Security & Traffic Report
This is a live report of real traffic against this site, generated from our own nginx access logs. Every request is classified as legitimate traffic or a specific attack type using the same rule-based techniques covered in our Web Application Firewall and HTTP User Agents articles โ published here as a live demonstration of what that traffic actually looks like.
Window: last 30 days ยท Last scan: 2026-09-09 12:01 UTC ยท Source IPs for attack activity are masked (last octet zeroed) before storage โ see Methodology below.
Requests Analysed
143,515
Flagged as Attacks
94,618
65.9% of all requests
Legitimate Traffic
48,897
Unique Visitors
16,895
daily-unique, summed across window
Daily Traffic โ Legitimate vs Attacks
Attack Types
Client Types (User-Agent)
Most Targeted Paths
| /wp-admin/install.php?step=1 | 82 hits |
| / | 53 hits |
| /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input | 26 hits |
| /.env | 25 hits |
| /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input | 20 hits |
| /index.php?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input | 15 hits |
| /test.hello?%25ADd+allow_url_include%3D1+%25ADd+auto_prepend_file%3Dphp://input | 15 hits |
| /static../.aws/credentials | 14 hits |
| /index.php?lang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?echo(md5(\x22hi\x22));?>+/tmp/index1.php | 12 hits |
| /index.php?lang=../../../../../../../../tmp/index1 | 12 hits |
Recent Attack Activity
| Time (UTC) | Type | Target |
|---|---|---|
| 09-09 11:43 | Known Attack Tool | GET / |
| 09-09 11:38 | Sensitive Path Probing | GET /.env |
| 09-09 11:38 | Sensitive Path Probing | GET /actuator |
| 09-09 11:38 | Sensitive Path Probing | GET /actuator/logfile |
| 09-09 11:38 | Sensitive Path Probing | GET /actuator/heapdump |
| 09-09 11:38 | Sensitive Path Probing | GET /actuator/env |
| 09-09 11:38 | Sensitive Path Probing | GET /actuator/configprops |
| 09-09 11:36 | Sensitive Path Probing | GET /.git/packed-refs?_=ileVm4Mb |
| 09-09 11:36 | Sensitive Path Probing | GET /.git/COMMIT_EDITMSG?_=fWD0ZU4y |
| 09-09 11:36 | Sensitive Path Probing | GET /.git/HEAD?_=cRJmzJ0j |
| 09-09 11:36 | Sensitive Path Probing | GET /.git/config?_=aCXaPG8d |
| 09-09 11:36 | Sensitive Path Probing | GET /.git/HEAD?_=pX1QyrI0 |
| 09-09 11:15 | Sensitive Path Probing | GET /wp-admin/install.php?step=1 |
| 09-09 11:06 | Sensitive Path Probing | GET /wp-admin/install.php?step=1 |
| 09-09 11:06 | Sensitive Path Probing | GET /wp-admin/install.php?step=1 |
| 09-09 11:06 | Sensitive Path Probing | GET /wp-admin/install.php?step=1 |
| 09-09 10:32 | Sensitive Path Probing | GET /wp-admin/phpinfo.php |
| 09-09 10:32 | Sensitive Path Probing | GET /administrator/phpinfo.php |
| 09-09 10:32 | Sensitive Path Probing | GET /development/.env |
| 09-09 10:32 | Sensitive Path Probing | GET /production/.env |
| 09-09 10:32 | Sensitive Path Probing | GET /config/app/.env |
| 09-09 10:32 | Sensitive Path Probing | GET /beta/.env |
| 09-09 10:32 | Sensitive Path Probing | GET /uat/.env |
| 09-09 10:32 | Sensitive Path Probing | GET /stage/.env |
| 09-09 10:32 | Sensitive Path Probing | GET /job/.env |
| 09-09 10:32 | Sensitive Path Probing | GET /test/.env |
| 09-09 10:32 | Sensitive Path Probing | GET /qa/.env |
| 09-09 10:32 | Sensitive Path Probing | GET /preview/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /rabbitmq/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /kafka/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /queue/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /worker/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /postgres/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /mongodb/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /redis/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /elasticsearch/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /travis/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /buildkite/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /mysql/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /gitlab/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /github/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /actions/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /circleci/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /.git/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /ci/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /cd/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /jenkins/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /kubernetes/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /terraform/.env |
| 09-09 10:31 | Sensitive Path Probing | GET /ansible/.env |
Methodology & Privacy
Traffic is classified using rule-based pattern matching against request paths, query strings, and User-Agent strings โ the same techniques described in our Web Application Firewall and HTTP User Agents articles. It is not a substitute for a dedicated WAF and will have false positives and false negatives like any signature-based system.
No raw log lines and no full IP addresses are ever stored. Only aggregated daily counts are kept long-term; individual attack events shown above have their source IP masked (last octet zeroed for IPv4) before being written to the database, and legitimate traffic is never shown at the individual-request level at all.
This report is generated periodically from our own nginx access logs by an automated scanner โ see About for more on this site.