Security & Traffic Report
This is a live report of real traffic against this site, generated from our own nginx access logs. Every request is classified as legitimate traffic or a specific attack type using the same rule-based techniques covered in our Web Application Firewall and HTTP User Agents articles โ published here as a live demonstration of what that traffic actually looks like.
Window: last 30 days ยท Last scan: 2026-07-26 03:01 UTC ยท Source IPs for attack activity are masked (last octet zeroed) before storage โ see Methodology below.
Requests Analysed
44,057
Flagged as Attacks
20,027
45.5% of all requests
Legitimate Traffic
24,030
Unique Visitors
11,746
daily-unique, summed across window
Daily Traffic โ Legitimate vs Attacks
Attack Types
Client Types (User-Agent)
Most Targeted Paths
| /wp-admin/install.php?step=1 | 1777 hits |
| / | 282 hits |
| /.env | 169 hits |
| //xmlrpc.php?rsd | 63 hits |
| /.git/config | 54 hits |
| /wp-login.php | 31 hits |
| /.env.local | 26 hits |
| /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input | 19 hits |
| /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input | 18 hits |
| /cgi-bin/luci/;stok=/locale | 18 hits |
Recent Attack Activity
| Time (UTC) | Type | Target |
|---|---|---|
| 07-26 02:49 | Known Attack Tool | GET / |
| 07-26 02:40 | Sensitive Path Probing | GET /cgi-bin/login.cgi |
| 07-26 02:31 | Known Attack Tool | GET /manager/text/list |
| 07-26 01:57 | Sensitive Path Probing | GET //xmlrpc.php?rsd |
| 07-26 01:45 | Known Attack Tool | GET / |
| 07-26 01:43 | Sensitive Path Probing | GET /wp-admin/install.php?step=1 |
| 07-26 01:26 | Sensitive Path Probing | GET /wp-admin/install.php?step=1 |
| 07-26 01:26 | Sensitive Path Probing | GET /wp-admin/install.php?step=1 |
| 07-26 01:26 | Sensitive Path Probing | GET /wp-admin/install.php?step=1 |
| 07-26 00:44 | Path Traversal | GET /index.php?lang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?echo(md5(\x22hi\x22));?>+/tmp/index1.php |
| 07-26 00:44 | Path Traversal | GET /index.php?lang=../../../../../../../../tmp/index1 |
| 07-26 00:43 | Sensitive Path Probing | GET /workspace/drupal/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /V2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /lib/phpunit/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /phpunit/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /lib/phpunit/phpunit/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /lib/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /vendor/phpunit/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /vendor/phpunit/phpunit/LICENSE/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /phpunit/phpunit/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Local/Remote File Inclusion | POST /test.hello?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input |
| 07-26 00:43 | Sensitive Path Probing | GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Sensitive Path Probing | GET /vendor/phpunit/src/Util/PHP/eval-stdin.php |
| 07-26 00:43 | Local/Remote File Inclusion | POST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input |
Methodology & Privacy
Traffic is classified using rule-based pattern matching against request paths, query strings, and User-Agent strings โ the same techniques described in our Web Application Firewall and HTTP User Agents articles. It is not a substitute for a dedicated WAF and will have false positives and false negatives like any signature-based system.
No raw log lines and no full IP addresses are ever stored. Only aggregated daily counts are kept long-term; individual attack events shown above have their source IP masked (last octet zeroed for IPv4) before being written to the database, and legitimate traffic is never shown at the individual-request level at all.
This report is generated periodically from our own nginx access logs by an automated scanner โ see About for more on this site.