S

Security & Traffic Report

This is a live report of real traffic against this site, generated from our own nginx access logs. Every request is classified as legitimate traffic or a specific attack type using the same rule-based techniques covered in our Web Application Firewall and HTTP User Agents articles โ€” published here as a live demonstration of what that traffic actually looks like.

Window: last 30 days ยท Last scan: 2026-09-09 12:01 UTC ยท Source IPs for attack activity are masked (last octet zeroed) before storage โ€” see Methodology below.

Requests Analysed

143,515

Flagged as Attacks

94,618

65.9% of all requests

Legitimate Traffic

48,897

Unique Visitors

16,895

daily-unique, summed across window

Daily Traffic โ€” Legitimate vs Attacks

Legitimate Attacks

Attack Types

Reconnaissance / Scanning 61,882
Sensitive Path Probing 29,969
Path Traversal 1,285
Known Attack Tool 1,122
Local/Remote File Inclusion 239
Command Injection 109
SQL Injection 9
Cross-Site Scripting 3

Client Types (User-Agent)

Browser 59,027
Scripting / API Client 40,710
Empty / Missing UA 13,097
Search Engine Bot 11,223
Other 9,732
AI Crawler 5,810
Social Link-Preview Bot 2,758
Known Attack Tool 1,122
Headless Browser 36

Most Targeted Paths

/wp-admin/install.php?step=1 82 hits
/ 53 hits
/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input 26 hits
/.env 25 hits
/?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input 20 hits
/index.php?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input 15 hits
/test.hello?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input 15 hits
/static../.aws/credentials 14 hits
/index.php?lang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?echo(md5(\x22hi\x22));?>+/tmp/index1.php 12 hits
/index.php?lang=../../../../../../../../tmp/index1 12 hits

Recent Attack Activity

Time (UTC) Type Target
09-09 11:43 Known Attack Tool GET /
09-09 11:38 Sensitive Path Probing GET /.env
09-09 11:38 Sensitive Path Probing GET /actuator
09-09 11:38 Sensitive Path Probing GET /actuator/logfile
09-09 11:38 Sensitive Path Probing GET /actuator/heapdump
09-09 11:38 Sensitive Path Probing GET /actuator/env
09-09 11:38 Sensitive Path Probing GET /actuator/configprops
09-09 11:36 Sensitive Path Probing GET /.git/packed-refs?_=ileVm4Mb
09-09 11:36 Sensitive Path Probing GET /.git/COMMIT_EDITMSG?_=fWD0ZU4y
09-09 11:36 Sensitive Path Probing GET /.git/HEAD?_=cRJmzJ0j
09-09 11:36 Sensitive Path Probing GET /.git/config?_=aCXaPG8d
09-09 11:36 Sensitive Path Probing GET /.git/HEAD?_=pX1QyrI0
09-09 11:15 Sensitive Path Probing GET /wp-admin/install.php?step=1
09-09 11:06 Sensitive Path Probing GET /wp-admin/install.php?step=1
09-09 11:06 Sensitive Path Probing GET /wp-admin/install.php?step=1
09-09 11:06 Sensitive Path Probing GET /wp-admin/install.php?step=1
09-09 10:32 Sensitive Path Probing GET /wp-admin/phpinfo.php
09-09 10:32 Sensitive Path Probing GET /administrator/phpinfo.php
09-09 10:32 Sensitive Path Probing GET /development/.env
09-09 10:32 Sensitive Path Probing GET /production/.env
09-09 10:32 Sensitive Path Probing GET /config/app/.env
09-09 10:32 Sensitive Path Probing GET /beta/.env
09-09 10:32 Sensitive Path Probing GET /uat/.env
09-09 10:32 Sensitive Path Probing GET /stage/.env
09-09 10:32 Sensitive Path Probing GET /job/.env
09-09 10:32 Sensitive Path Probing GET /test/.env
09-09 10:32 Sensitive Path Probing GET /qa/.env
09-09 10:32 Sensitive Path Probing GET /preview/.env
09-09 10:31 Sensitive Path Probing GET /rabbitmq/.env
09-09 10:31 Sensitive Path Probing GET /kafka/.env
09-09 10:31 Sensitive Path Probing GET /queue/.env
09-09 10:31 Sensitive Path Probing GET /worker/.env
09-09 10:31 Sensitive Path Probing GET /postgres/.env
09-09 10:31 Sensitive Path Probing GET /mongodb/.env
09-09 10:31 Sensitive Path Probing GET /redis/.env
09-09 10:31 Sensitive Path Probing GET /elasticsearch/.env
09-09 10:31 Sensitive Path Probing GET /travis/.env
09-09 10:31 Sensitive Path Probing GET /buildkite/.env
09-09 10:31 Sensitive Path Probing GET /mysql/.env
09-09 10:31 Sensitive Path Probing GET /gitlab/.env
09-09 10:31 Sensitive Path Probing GET /github/.env
09-09 10:31 Sensitive Path Probing GET /actions/.env
09-09 10:31 Sensitive Path Probing GET /circleci/.env
09-09 10:31 Sensitive Path Probing GET /.git/.env
09-09 10:31 Sensitive Path Probing GET /ci/.env
09-09 10:31 Sensitive Path Probing GET /cd/.env
09-09 10:31 Sensitive Path Probing GET /jenkins/.env
09-09 10:31 Sensitive Path Probing GET /kubernetes/.env
09-09 10:31 Sensitive Path Probing GET /terraform/.env
09-09 10:31 Sensitive Path Probing GET /ansible/.env

Methodology & Privacy

Traffic is classified using rule-based pattern matching against request paths, query strings, and User-Agent strings โ€” the same techniques described in our Web Application Firewall and HTTP User Agents articles. It is not a substitute for a dedicated WAF and will have false positives and false negatives like any signature-based system.

No raw log lines and no full IP addresses are ever stored. Only aggregated daily counts are kept long-term; individual attack events shown above have their source IP masked (last octet zeroed for IPv4) before being written to the database, and legitimate traffic is never shown at the individual-request level at all.

This report is generated periodically from our own nginx access logs by an automated scanner โ€” see About for more on this site.