kim98035 Posted July 30, 2014 Share Posted July 30, 2014 (edited) I am now developing a website by prestashop and the domain is www.winemehk.com. Recently, I have encountered a problem that after clicking the website for several times, the website and cpanel blocked my IP. After changing to another IP, they blocked my IP again. Can anyone tell me how can I fixed this problem?Below please kindly find the log for your reference.Many thanks.Date Time IP GET Host Message Action2014-07-28 21:46:40 183.179.139.229 /admin5078/index.php?controller=AdminLogin&token=cb7497729f44392f33078a9746ec772f&redirect=AdminLanguages HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:41 183.179.139.229 /themes/default-bootstrap/css/modules/blockcart/blockcart.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 5012014-07-28 21:46:41 183.179.139.229 /themes/default-bootstrap/css/modules/blockcontact/blockcontact.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 5012014-07-28 21:46:42 183.179.139.229 /themes/default-bootstrap/css/global.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:42 183.179.139.229 /themes/default-bootstrap/css/autoload/highdpi.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:42 183.179.139.229 /themes/default-bootstrap/css/autoload/uniform.default.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:42 183.179.139.229 /themes/default-bootstrap/css/autoload/responsive-tables.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:42 183.179.139.229 /themes/default-bootstrap/css/modules/blockcategories/blockcategories.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:43 183.179.139.229 /modules/themeconfigurator/css/hooks.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 5012014-07-28 21:46:43 183.179.139.229 /themes/default-bootstrap/css/product_list.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:44 183.179.139.229 /themes/default-bootstrap/css/modules/blocksearch/blocksearch.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:44 183.179.139.229 /themes/default-bootstrap/css/modules/blockuserinfo/blockuserinfo.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:44 183.179.139.229 /themes/default-bootstrap/css/modules/blockviewed/blockviewed.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:44 183.179.139.229 /themes/default-bootstrap/css/modules/blocktags/blocktags.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:45 183.179.139.229 /themes/default-bootstrap/css/modules/blockwishlist/blockwishlist.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:45 183.179.139.229 /themes/default-bootstrap/js/global.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 5012014-07-28 21:46:45 183.179.139.229 /modules/paypal/css/paypal.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:45 183.179.139.229 /themes/default-bootstrap/css/modules/blocktopmenu/css/blocktopmenu.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:46 183.179.139.229 /themes/default-bootstrap/css/modules/blocktopmenu/css/superfish-modified.css HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:46 183.179.139.229 /js/jquery/plugins/jquery.easing.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:46 183.179.139.229 /themes/default-bootstrap/js/autoload/15-jquery.total-storage.min.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:46 183.179.139.229 /themes/default-bootstrap/js/autoload/10-bootstrap.min.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:47 183.179.139.229 /themes/default-bootstrap/js/autoload/15-jquery.uniform-modified.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:48 183.179.139.229 /themes/default-bootstrap/js/products-comparison.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:48 183.179.139.229 /js/jquery/plugins/jquery.serialScroll.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:48 183.179.139.229 /themes/default-bootstrap/js/modules/blockcart/ajax-cart.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:48 183.179.139.229 /js/jquery/plugins/bxslider/jquery.bxslider.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:48 183.179.139.229 /themes/default-bootstrap/js/tools/treeManagement.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 4042014-07-28 21:46:48 183.179.139.229 /themes/default-bootstrap/js/modules/blocksearch/blocksearch.js HTTP/1.1 www.winemehk.com Access denied with code 501 (phase 2). Pattern match "(?:b(? ?:n(?:et(?:bW+?blocalgroup|.exe)|(?:map|c).exe)|t(?:racer(?:oute|t)|elnet.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp).exe|echobW*?by+)b|c(?:md(? ?:32)?.exeb|bW*?/c)|d(?:bW*?[/]|W*?..)|hmod.{0,40}? ..." at REQUEST_COOKIES:2a0f1a0291a189ec406f99a4c735e244. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "111"] [id "959006"] [msg "System Command Injection"] [data "cd/"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] 404 Edited July 30, 2014 by kim98035 (see edit history) Link to comment Share on other sites More sharing options...
csschopper.com Posted July 30, 2014 Share Posted July 30, 2014 Hi, Please talk to your host provides, They can resolve this issue easily. Thanks Alok Link to comment Share on other sites More sharing options...
kim98035 Posted July 30, 2014 Author Share Posted July 30, 2014 Hi Alok, They can't solve my problem and just throw this log to me. I don't know what to do at this stage. Best Regards, Kim Link to comment Share on other sites More sharing options...
El Patron Posted July 30, 2014 Share Posted July 30, 2014 I found loads of topics concerning cpanel, PrestaShop forum is not the best place to be looking, here is fix that may or may not work for you http://forums.cpanel.net/f185/my-site-blocked-my-ip-where-do-i-look-fix-210311.html Link to comment Share on other sites More sharing options...
kim98035 Posted July 31, 2014 Author Share Posted July 31, 2014 Dear El Patron, Seems that I can't fix the problem by this post. The main problem is that the hosting asked me to pass the log to IT, but I don't have any IT support. When I asked cpanel cs, they told us to ask my hosting for help. Now I have no solution... Link to comment Share on other sites More sharing options...
El Patron Posted July 31, 2014 Share Posted July 31, 2014 Dear El Patron, Seems that I can't fix the problem by this post. The main problem is that the hosting asked me to pass the log to IT, but I don't have any IT support. When I asked cpanel cs, they told us to ask my hosting for help. Now I have no solution... the outside ps forum solutions really were for advanced users I think so don't feel badly if you don't have solution from those posts I would also be hard pressed to resolve with advice given. so chin up. did you contact your hosting provider? they are the only one I think now that can help you. remember, hosting is a commodity, if you have issues with hosting, run don't walk to better solution, yes? Link to comment Share on other sites More sharing options...
El Patron Posted July 31, 2014 Share Posted July 31, 2014 oh, I see where you did contact hosting provider, they referred you to IT, how comforting that is really their job as they provide framework and probably charge you for cpanel. Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now