[Tue Nov 19 11:50:13.329949 2019] [:error] [pid 206583:tid 47276449986304] [client 35.243.115.20:57622] [client 35.243.115.20] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/RESPONSE-980-CORRELATION.conf"] [line "37"] [id "980130"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 5 - SQLI=0,XSS=5,RFI=0,LFI=0,RCE=0,PHPI=0,HTTP=0,SESS=0): XSS Attack Detected via libinjection"] [tag "event-correlation"] [hostname "www.sitedomain.com"] [uri "/index.php"] [unique_id "XdO61TVLl3ZTUBSeVvkGagAAAUw"]
[Tue Nov 19 11:51:07.093268 2019] [:error] [pid 206683:tid 47276456290048] [client 35.243.115.20:35058] [client 35.243.115.20] ModSecurity: Warning. detected XSS using libinjection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "37"] [id "941100"] [rev "2"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: <?xml version found within ARGS_NAMES:<?xml version: <?xml version"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "1"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "www.sitedomain.com"] [uri "/xmlrpc.php"] [unique_id "XdO7C@-@@N87oYyMoiLcoQAAAY8"]
Are these googlebout blocks? from modsecurity
[Tue Nov 19 11:51:07.093268 2019] [:error] [pid 206683:tid 47276456290048] [client 35.243.115.20:35058] [client 35.243.115.20] ModSecurity: Warning. detected XSS using libinjection. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-941-APPLICATION-ATTACK-XSS.conf"] [line "37"] [id "941100"] [rev "2"] [msg "XSS Attack Detected via libinjection"] [data "Matched Data: <?xml version found within ARGS_NAMES:<?xml version: <?xml version"] [severity "CRITICAL"] [ver "OWASP_CRS/3.0.0"] [maturity "1"] [accuracy "9"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-xss"] [tag "OWASP_CRS/WEB_ATTACK/XSS"] [tag "WASCTC/WASC-8"] [tag "WASCTC/WASC-22"] [tag "OWASP_TOP_10/A3"] [tag "OWASP_AppSensor/IE1"] [tag "CAPEC-242"] [hostname "www.sitedomain.com"] [uri "/xmlrpc.php"] [unique_id "XdO7C@-@@N87oYyMoiLcoQAAAY8"]
Are these googlebout blocks? from modsecurity