<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Possible hack attempts from *.opera-mini.net ?]]></title><description><![CDATA[<p dir="auto">I have this filling up my Apache logfile 24/7 and it always comes from *.opera-mini.net hosts. Is this really a hack attempt or a false positive?</p>
<p dir="auto">ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://www.mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">www.mysite.com</a>"] [uri "/"] [unique_id "U6xFmUKT6CAAAGJHYwgAAAKP"]</p>
]]></description><link>https://forums.opera.com/topic/3634/possible-hack-attempts-from-opera-mini-net</link><generator>RSS for Node</generator><lastBuildDate>Thu, 12 Mar 2026 14:56:57 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/3634.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 26 Jun 2014 18:15:21 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Possible hack attempts from *.opera-mini.net ? on Tue, 22 Jul 2014 14:46:53 GMT]]></title><description><![CDATA[<p dir="auto">Can you send me the logs at gregd [at] opera [dot] com</p>
]]></description><link>https://forums.opera.com/post/45773</link><guid isPermaLink="true">https://forums.opera.com/post/45773</guid><dc:creator><![CDATA[gregdistefano]]></dc:creator><pubDate>Tue, 22 Jul 2014 14:46:53 GMT</pubDate></item><item><title><![CDATA[Reply to Possible hack attempts from *.opera-mini.net ? on Thu, 26 Jun 2014 18:16:50 GMT]]></title><description><![CDATA[<p dir="auto">It's like every couple minutes same thing flooding my logs:</p>
<p dir="auto">[Thu Jun 26 20:21:06 2014] [error] [client 82.145.217.121] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://www.mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">www.mysite.com</a>"] [uri "/"] [unique_id "U6xWgkKT6CAAAGyng08AAAGR"]<br />
[Thu Jun 26 20:21:07 2014] [error] [client 82.145.217.121] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://www.mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">www.mysite.com</a>"] [uri "/"] [unique_id "U6xWg0KT6CAAAG51IU0AAAEC"]<br />
[Thu Jun 26 20:21:08 2014] [error] [client 82.145.217.121] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://www.mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">www.mysite.com</a>"] [uri "/"] [unique_id "U6xWhEKT6CAAAG51IU4AAAEV"]<br />
[Thu Jun 26 20:21:08 2014] [error] [client 82.145.217.121] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://www.mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">www.mysite.com</a>"] [uri "/"] [unique_id "U6xWhEKT6CAAAG76d1gAAADE"]<br />
[Thu Jun 26 20:29:28 2014] [error] [client 112.215.36.144] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://www.mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">www.mysite.com</a>"] [uri "/"] [unique_id "U6xYeEKT6CAAAHCIzMcAAAJN"]<br />
[Thu Jun 26 20:29:28 2014] [error] [client 112.215.36.144] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://www.mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">www.mysite.com</a>"] [uri "/"] [unique_id "U6xYeEKT6CAAAGzkGO4AAAIU"]<br />
[Thu Jun 26 20:34:26 2014] [error] [client 82.145.216.156] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">mysite.com</a>"] [uri "/offer/images/rot4s.png"] [unique_id "U6xZokKT6CAAAHFEIC4AAACI"]<br />
[Thu Jun 26 20:34:27 2014] [error] [client 82.145.216.156] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">mysite.com</a>"] [uri "/offer/images/rot4s.png"] [unique_id "U6xZo0KT6CAAAGfAMPcAAABV"]<br />
[Thu Jun 26 20:34:27 2014] [error] [client 82.145.216.156] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">mysite.com</a>"] [uri "/offer/images/rot4s.png"] [unique_id "U6xZo0KT6CAAAG-WZ34AAAAW"]<br />
[Thu Jun 26 20:34:27 2014] [error] [client 82.145.216.156] ModSecurity: Access denied with connection close (phase 2). Pattern match "(?:\\b(?:(?:n(?:et(?:\\b\\W+?\\blocalgroup|\\.exe)|(?:map|c)\\.exe)|t(?:racer(?:oute|t)|elnet\\.exe|clsh8?|ftp)|(?:w(?:guest|sh)|rcmd|ftp)\\.exe|echo\\b\\W*?\\by+)\\b|c(?:md(?:(?:32)?\\.exe\\b|\\b\\W*?\\/c)|d(?:\\b\\W*?[\\\\/]|\\W*?\\.\\.)|hmod.{0,40}? ..." at REQUEST_HEADERS:User-Agent. [file "/usr/local/apache/conf/modsec2.user.conf"] [line "143"] [id "1234123446"] [msg "System Command Injection"] [data "; id"] [severity "CRITICAL"] [tag "WEB_ATTACK/COMMAND_INJECTION"] [hostname "<a href="http://mysite.com" target="_blank" rel="noopener noreferrer nofollow ugc">mysite.com</a>"] [uri "/offer/images/rot4s.png"] [unique_id "U6xZo0KT6CAAAG-WZ4AAAAAF"]</p>
]]></description><link>https://forums.opera.com/post/43573</link><guid isPermaLink="true">https://forums.opera.com/post/43573</guid><dc:creator><![CDATA[ivanlevente]]></dc:creator><pubDate>Thu, 26 Jun 2014 18:16:50 GMT</pubDate></item></channel></rss>