S

Security & Traffic Report

This is a live report of real traffic against this site, generated from our own nginx access logs. Every request is classified as legitimate traffic or a specific attack type using the same rule-based techniques covered in our Web Application Firewall and HTTP User Agents articles โ€” published here as a live demonstration of what that traffic actually looks like.

Window: last 30 days ยท Last scan: 2026-07-26 03:01 UTC ยท Source IPs for attack activity are masked (last octet zeroed) before storage โ€” see Methodology below.

Requests Analysed

44,057

Flagged as Attacks

20,027

45.5% of all requests

Legitimate Traffic

24,030

Unique Visitors

11,746

daily-unique, summed across window

Daily Traffic โ€” Legitimate vs Attacks

Legitimate Attacks

Attack Types

Reconnaissance / Scanning 10,121
Sensitive Path Probing 9,030
Known Attack Tool 614
Path Traversal 111
Local/Remote File Inclusion 59
SQL Injection 47
Command Injection 42
Cross-Site Scripting 3

Client Types (User-Agent)

Browser 25,374
Other 7,421
Empty / Missing UA 6,088
Scripting / API Client 2,318
Search Engine Bot 1,521
AI Crawler 680
Known Attack Tool 614
Social Link-Preview Bot 26
Headless Browser 15

Most Targeted Paths

/wp-admin/install.php?step=1 1777 hits
/ 282 hits
/.env 169 hits
//xmlrpc.php?rsd 63 hits
/.git/config 54 hits
/wp-login.php 31 hits
/.env.local 26 hits
/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input 19 hits
/?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input 18 hits
/cgi-bin/luci/;stok=/locale 18 hits

Recent Attack Activity

Time (UTC) Type Target
07-26 02:49 Known Attack Tool GET /
07-26 02:40 Sensitive Path Probing GET /cgi-bin/login.cgi
07-26 02:31 Known Attack Tool GET /manager/text/list
07-26 01:57 Sensitive Path Probing GET //xmlrpc.php?rsd
07-26 01:45 Known Attack Tool GET /
07-26 01:43 Sensitive Path Probing GET /wp-admin/install.php?step=1
07-26 01:26 Sensitive Path Probing GET /wp-admin/install.php?step=1
07-26 01:26 Sensitive Path Probing GET /wp-admin/install.php?step=1
07-26 01:26 Sensitive Path Probing GET /wp-admin/install.php?step=1
07-26 00:44 Path Traversal GET /index.php?lang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?echo(md5(\x22hi\x22));?>+/tmp/index1.php
07-26 00:44 Path Traversal GET /index.php?lang=../../../../../../../../tmp/index1
07-26 00:43 Sensitive Path Probing GET /workspace/drupal/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /V2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /lib/phpunit/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /phpunit/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /lib/phpunit/phpunit/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /lib/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /vendor/phpunit/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /vendor/phpunit/phpunit/LICENSE/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /phpunit/phpunit/Util/PHP/eval-stdin.php
07-26 00:43 Local/Remote File Inclusion POST /test.hello?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input
07-26 00:43 Sensitive Path Probing GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php
07-26 00:43 Sensitive Path Probing GET /vendor/phpunit/src/Util/PHP/eval-stdin.php
07-26 00:43 Local/Remote File Inclusion POST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input

Methodology & Privacy

Traffic is classified using rule-based pattern matching against request paths, query strings, and User-Agent strings โ€” the same techniques described in our Web Application Firewall and HTTP User Agents articles. It is not a substitute for a dedicated WAF and will have false positives and false negatives like any signature-based system.

No raw log lines and no full IP addresses are ever stored. Only aggregated daily counts are kept long-term; individual attack events shown above have their source IP masked (last octet zeroed for IPv4) before being written to the database, and legitimate traffic is never shown at the individual-request level at all.

This report is generated periodically from our own nginx access logs by an automated scanner โ€” see About for more on this site.