Posted on 28/10/2019 11:15:59
Hi Nicolai,
The solution is https://gbtwente.nl/ (DW 9.5.1).
The ipban log is as follows where the 141.101 range seems to be cloudflare (for example https://db-ip.com/all/141.101.105):
2019-10-24 21:46:59.7555|INFO|IpBanner|Banned ip: 141.101.105.239; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:00.0142|INFO|IpBanner|Banned ip: 172.69.55.153; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:00.2329|INFO|IpBanner|Banned ip: 141.101.77.157; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:00.4547|INFO|IpBanner|Banned ip: 172.69.55.99; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:00.9418|INFO|IpBanner|Banned ip: 141.101.76.189; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:01.1570|INFO|IpBanner|Banned ip: 141.101.105.35; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:01.3602|INFO|IpBanner|Banned ip: 141.101.77.145; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:01.5714|INFO|IpBanner|Banned ip: 141.101.104.150; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:02.3055|INFO|IpBanner|Banned ip: 162.158.111.132; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:03.6782|INFO|IpBanner|Banned ip: 141.101.104.136; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:03.9776|INFO|IpBanner|Banned ip: 172.69.55.81; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:15.3619|INFO|IpBanner|Banned ip: 141.101.76.33; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:16.2169|INFO|IpBanner|Banned ip: 141.101.104.170; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:20.0721|INFO|IpBanner|Banned ip: 141.101.104.198; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:20.6660|INFO|IpBanner|Banned ip: 141.101.104.64; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
2019-10-24 21:47:37.6362|INFO|IpBanner|Banned ip: 141.101.105.23; REASON: Injection ban: Match on 404;http://www.gbtwente.nl:443/admin/public/404.aspx?404;https://GBTwente:80/index.php?page ((?:\%27|\'|\%3B|\;|\%3D|%23|\-\-|UNION( +ALL){0,1})(?:[\W\s]+|$)*(?:union|select|update|delete|drop|insert|shutdown|exec|declare|cast|set|truncate|create|alter|grant|use|deny|waitfor|benchmark|having)(?:[\W\s]+|$))
Greets Hans