Congratulations,
Dumbass

> cat /var/log/your-failures.log_

A very special round of applause for 114.119.148.189 for their valiant — and entirely unsuccessful — attempt to compromise our systems. We truly couldn't have done it without you. Well, actually we could. We did. You failed.

We Might Not Know Where You Live, But...

Did you think you were anonymous? That's adorable. Here's what we know about you:

IP Address 114.119.148.189
Country Singapore
Region Unknown
City Singapore
ISP / Org Unknown
Timezone Unknown
Coordinates 1.2872, 103.8507

Your Digital Fingerprint

Nice browser you've got there. It'd be a shame if someone… logged it.

Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot)
Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (HTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot)

Your Hall of Shame

Every single one of your pathetic attempts, lovingly preserved for posterity. Spoiler alert: they all failed.

Attack Breakdown

11
General Fuzzing / Forced Browsing
4
LDAP Injection
7
SQL Injection
22
Total Failed Attempts

Detailed Activity Log

# Timestamp Attack Type Method Target URI Detail
1 2026-03-06T07:26:18Z General Fuzzing / Forced Browsing GET /wp-admin/ Forced browsing attempt: /wp-admin
2 2026-04-03T02:44:06Z General Fuzzing / Forced Browsing GET /wp-admin/ Forced browsing attempt: /wp-admin
3 2026-04-03T03:56:53Z General Fuzzing / Forced Browsing GET /services/managed-wazuh general_fuzzing [HEADER][HTTP_REFERER] matched /(?:sqlmap|havij|pangolin|acunetix|nessus|nikto|netsparker|burpsuite|owasp[\s-]?zap)/i
4 2026-04-06T02:29:52Z LDAP Injection GET /insights/beyond-firewalls-how-a-pe*******on-test-enhances-web-application-security ldap_injection [URI][REQUEST_URI] matched /[)(|*\\]\s*[)(|*\\]/i
5 2026-04-10T05:53:15Z SQL Injection GET /soc-as-a-service/?source=about_page------------------------------------- sqli [GET][source] matched /--\s*$/m
6 2026-04-30T13:26:58Z SQL Injection GET /soc-as-a-service/?source=user_about----------------------ab8752247b75--------------- sqli [GET][source] matched /--\s*$/m
7 2026-05-02T15:46:13Z LDAP Injection GET /insights/beyond-firewalls-how-a-pe*******on-test-enhances-web-application-security ldap_injection [URI][REQUEST_URI] matched /[)(|*\\]\s*[)(|*\\]/i
8 2026-05-18T07:50:51Z General Fuzzing / Forced Browsing GET /uploads/credscan6.png Forced browsing attempt: /uploads/credscan6.png
9 2026-06-01T10:31:53Z General Fuzzing / Forced Browsing GET /wp-login.php Forced browsing attempt: /wp-login
10 2026-06-07T20:27:55Z LDAP Injection GET /insights/beyond-firewalls-how-a-pe*******on-test-enhances-web-application-security ldap_injection [URI][REQUEST_URI] matched /[)(|*\\]\s*[)(|*\\]/i
11 2026-06-14T11:48:47Z General Fuzzing / Forced Browsing GET /wp-admin/ Forced browsing attempt: /wp-admin
12 2026-06-26T09:45:08Z LDAP Injection GET /insights/beyond-firewalls-how-a-pe*******on-test-enhances-web-application-security ldap_injection [URI][REQUEST_URI] matched /[)(|*\\]\s*[)(|*\\]/i
13 2026-07-02T08:53:46Z SQL Injection GET /soc-as-a-service/?source=about_page------------------------------------- sqli [GET][source] matched /--\s*$/m
14 2026-07-08T07:04:34Z SQL Injection GET /cyber-essentials/?source=about_page------------------------------------- sqli [GET][source] matched /--\s*$/m
15 2026-07-21T05:52:45Z General Fuzzing / Forced Browsing GET /files/install-guides/XDR-Agent-Install-Guide.pdf Forced browsing attempt: /files/install-guides/xdr-agent-install-guide.pdf
16 2026-07-25T10:08:09Z General Fuzzing / Forced Browsing GET /wp-login.php Forced browsing attempt: /wp-login
17 2026-08-03T12:40:53Z SQL Injection GET /soc-as-a-service/?source=user_about----------------------ab8752247b75--------------- sqli [GET][source] matched /--\s*$/m
18 2026-08-07T00:27:57Z General Fuzzing / Forced Browsing GET /services/managed-wazuh general_fuzzing [HEADER][HTTP_REFERER] matched /(?:sqlmap|havij|pangolin|acunetix|nessus|nikto|netsparker|burpsuite|owasp[\s-]?zap)/i
19 2026-08-07T06:57:16Z SQL Injection GET /penetration-testing/?source=about_page------------------------------------- sqli [GET][source] matched /--\s*$/m
20 2026-08-12T05:28:56Z General Fuzzing / Forced Browsing GET /wp-login.php Forced browsing attempt: /wp-login
21 2026-08-17T17:13:26Z SQL Injection GET /penetration-testing/?source=about_page------------------------------------- sqli [GET][source] matched /--\s*$/m
22 2026-08-17T17:59:24Z General Fuzzing / Forced Browsing GET /services/managed-wazuh general_fuzzing [HEADER][HTTP_REFERER] matched /(?:sqlmap|havij|pangolin|acunetix|nessus|nikto|netsparker|burpsuite|owasp[\s-]?zap)/i

In Summary

You came. You saw. You got absolutely owned by a hedgehog.

Every request you made was detected, logged, and laughed at. Our WAF didn't even break a sweat. Maybe next time try something more challenging — like reading a book on operational security.

Pro tip: If you're going to hack a cybersecurity company, maybe don't use the same IP address for every single request. Just a thought.