Expected Log Samples

Deny All WAF

Shellcode

"<5>1 2020-01-07T09:17:08.732356+01:00 Management - - - - {"logAlertUid":"bb45b96adbb6a6216981645d5","@timestamp":"1578385028731","timestamp":"1578385028731","_type_":"Controller_Business_Log_SecurityLog","request":{"body":"","cookies":[],"headers":[{"key":"Host","value":"admin.logpointnp.np"},{"key":"User-Agent","value":"check_ssl_cert/1.76.0"},{"key":"Connection","value":"close"}],"hostname":"admin.logpoint.np","ipDst":"10.20.69.101","ipSrc":"10.2.1.31","method":"HEAD","path":"/","portDst":443,"protocol":"HTTP/1.1","query":"","requestUid":"XhQ@hL3oLmW@9nUuvpOS@AAM0"},"context":{"tags":"","applianceName":"Management","applianceUid":"fefaab9235ab42dbb5c4","backendHost":"10.100.1.1","backendPort":443,"reverseProxyName":"LOG123","reverseProxyUid":"aaaaaad1cba28f9564840e0f774","tunnelName":"CD84-V-zyx","tunnelUid":"661985yyyyyde9402cb00bc72af","workflowName":"WAF xxx-V-PORTACRM","workflowUid":"xxxxx3b35b4c60a766801d0"},"events":[{"eventUid":"74c816c3e280a53df9c203ba05","tokens":{"date":1578385028732003,"eventType":"security","engineUid":"custom","engineName":"Custom","attackFamily":"No Attack Family","riskLevel":50,"riskLevelOWASP":0.0,"cwe":"-","severity":5,"resolveType":"No Resolve","part":"No Part","customMessage":"URL non autorisee","reason":"Custom: URL non autorisee"}}]}"
"<5>1 2020-01-06T23:33:23.889229+01:00 Management - - - - {"logAlertUid":"3820d6a0997f4444b5b6a3369b7053a3","@timestamp":"1578350003887","timestamp":"1578350003887","_type_":"Controller_Business_Log_SecurityLog","request":{"body":"","cookies":[{"key":"PHPSESSID","value":"PHPSESSID=5g2r3dg3ka59f6vrvujb2mds53"}],"headers":[{"key":"Accept-Encoding","value":"gzip,deflate"},{"key":"From","value":"robot@seokicks.de"},{"key":"Connection","value":"Close"},{"key":"Referer","value":"https://maps.vaucluse.fr/"},{"key":"Accept","value":"text/html,text/plain"},{"key":"Host","value":"maps.vaucluse.fr"},{"key":"User-Agent","value":"Mozilla/5.0 (compatible; SEOkicks; +https://www.seokicks.de/robot.html)"}],"hostname":"maps.vaucluse.fr","ipDst":"10.100.19.46","ipSrc":"95.216.96.244","method":"GET","path":"/admin.php/auth/login/","portDst":443,"protocol":"HTTP/1.1","query":"auth_url_return=%2Findex.php%2Fview%2F","requestUid":"XhO1s0rlt2PSIyBTRXMJ7AAAAWs"},"context":{"tags":"","applianceName""

Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support