Congratulations,
Dumbass

> cat /var/log/your-failures.log_

A very special round of applause for 57.141.20.20 for their valiant — and entirely unsuccessful — attempt to compromise our systems. We truly couldn't have done it without you. Well, actually we could. We did. You failed.

We Might Not Know Where You Live, But...

Did you think you were anonymous? That's adorable. Here's what we know about you:

IP Address 57.141.20.20
Country United States
Region New York
City New York
ISP / Org Unknown
Timezone Unknown
Coordinates 40.7126, -74.0066

Your Digital Fingerprint

Nice browser you've got there. It'd be a shame if someone… logged it.

meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:147.0) Gecko/20100101 Firefox/147.0 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))

Your Hall of Shame

Every single one of your pathetic attempts, lovingly preserved for posterity. Spoiler alert: they all failed.

Attack Breakdown

3
SQL Injection
67
LDAP Injection
70
Total Failed Attempts

Detailed Activity Log

# Timestamp Attack Type Method Target URI Detail
1 2026-02-15T13:54:49Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
2 2026-06-14T15:55:11Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
3 2026-06-15T12:10:46Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
4 2026-08-06T07:56:14Z LDAP Injection GET /blog/from-the-hacker-desk-smart-building-management-system ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
5 2026-08-06T21:29:18Z LDAP Injection GET /blog/anatomy-of-a-breach-talktalk ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
6 2026-08-07T11:15:38Z LDAP Injection GET /blog/how-can-businesses-ensure-their-remediation-actions-are-effective-after-a-test ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
7 2026-08-07T16:34:37Z LDAP Injection GET /blog/anatomy-of-a-breach-2015-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
8 2026-08-07T17:14:18Z LDAP Injection GET /wireless-spectrum-security ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
9 2026-08-07T18:38:21Z LDAP Injection GET /blog/anatomy-of-a-breach-premera-blue-cross ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
10 2026-08-08T01:43:03Z LDAP Injection GET /blog/what-is-the-value-of-retesting-and-when-should-it-be-conducted ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
11 2026-08-08T08:50:00Z LDAP Injection GET /sitemap-index.xml ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
12 2026-08-08T11:53:53Z LDAP Injection GET /blog/anatomy-of-a-breach-labour-party-ddos ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
13 2026-08-08T22:24:29Z LDAP Injection GET /blog/anatomy-of-a-breach-costa-rica-conti ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
14 2026-08-08T23:12:02Z LDAP Injection GET /terms-of-service ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
15 2026-08-09T08:05:04Z LDAP Injection GET /blog/cyber-essentials-demystified-firewalls ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
16 2026-08-09T08:30:41Z LDAP Injection GET /blog/anatomy-of-a-breach-cambridge-analytica ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
17 2026-08-09T14:08:53Z LDAP Injection GET /blog/what-a-good-penetration-test-report-looks-like ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
18 2026-08-09T19:12:12Z LDAP Injection GET /blog/cyber-essentials-demystified-action-plan ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
19 2026-08-10T05:26:46Z LDAP Injection GET /blog/anatomy-of-a-breach-olympic-destroyer ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
20 2026-08-10T11:27:23Z LDAP Injection GET /blog/companies-house-webfiling-flaw-directors-exposed ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
21 2026-08-10T14:46:38Z LDAP Injection GET /blog/what-does-a-crest-aligned-penetration-testing-methodology-actually-involve ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
22 2026-08-10T18:46:56Z LDAP Injection GET /blog/why-automated-tools-are-not-enough ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
23 2026-08-11T03:04:09Z LDAP Injection GET /blog/how-much-does-a-penetration-test-cost-for-a-medium-sized-uk-business ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
24 2026-08-11T05:46:28Z LDAP Injection GET /blog/chaining-low-risk-findings ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
25 2026-08-11T06:59:49Z LDAP Injection GET /blog/pen-test-reports-regulatory-legal-insurance ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
26 2026-08-11T12:52:14Z LDAP Injection GET /blog/how-do-testers-assess-authentication-and-session-management-weaknesses ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
27 2026-08-11T16:13:57Z LDAP Injection GET /blog/anatomy-of-a-breach-match-group-eurail ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
28 2026-08-12T07:58:13Z LDAP Injection GET /blog/what-information-does-a-penetration-testing-provider-need-before-starting ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
29 2026-08-12T11:51:27Z LDAP Injection GET /blog/anatomy-of-a-breach-mega-breach-dumps ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
30 2026-08-12T23:26:36Z LDAP Injection GET /blog/modelling-real-world-threat-scenarios ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
31 2026-08-13T05:15:40Z LDAP Injection GET /blog/cyber-essentials-demystified-firewalls ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
32 2026-08-13T08:44:03Z LDAP Injection GET /blog/anatomy-of-a-breach-2017-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
33 2026-08-14T01:36:30Z LDAP Injection GET /blog/anatomy-of-a-breach-mega-breach-dumps ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
34 2026-08-15T13:19:19Z LDAP Injection GET /blog/what-does-exploitation-proof-of-concept-actually-mean-in-a-report ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
35 2026-08-15T14:53:55Z LDAP Injection GET /blog/anatomy-of-a-breach-labour-party-ddos ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
36 2026-08-15T15:11:07Z LDAP Injection GET /blog/penetration-testing-relevant-despite-automation-ai ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
37 2026-08-15T17:39:58Z LDAP Injection GET /sitemap-index.xml ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
38 2026-08-15T17:48:37Z LDAP Injection GET /blog/from-the-hacker-desk-cctv-intelligence-hub ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
39 2026-08-16T01:24:02Z LDAP Injection GET /blog/how-do-testers-adapt-methodology-when-targeting-operational-technology-or-iot-environments ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
40 2026-08-16T17:09:28Z LDAP Injection GET /blog/business-guide-to-penetration-testing-understanding-your-report ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
41 2026-08-16T21:31:02Z LDAP Injection GET /blog/difference-between-a-penetration-test-and-a-vulnerability-scan ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
42 2026-08-16T21:59:21Z LDAP Injection GET /case-studies ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
43 2026-08-17T06:07:48Z LDAP Injection GET /blog/what-is-the-difference-between-crest-check-and-cyber-scheme-certifications ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
44 2026-08-17T17:28:18Z LDAP Injection GET /blog/anatomy-of-a-breach-eu-commission-stryker ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
45 2026-08-18T11:54:58Z LDAP Injection GET /blog/how-does-penetration-testing-fit-into-a-broader-detect-defend-and-disrupt-cyber-strategy ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
46 2026-08-18T12:46:00Z LDAP Injection GET /blog/from-the-hacker-desk-superyacht-keylock ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
47 2026-08-18T13:14:46Z LDAP Injection GET /blog/do-we-need-cyber-insurance-before-commissioning-a-penetration-test ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
48 2026-08-18T17:28:17Z LDAP Injection GET /blog/measuring-real-value-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
49 2026-08-18T21:18:49Z LDAP Injection GET /blog/anatomy-of-a-breach-nortel-networks ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
50 2026-08-19T20:52:46Z LDAP Injection GET /blog/anatomy-of-a-breach-morrisons-insider ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
51 2026-08-19T22:06:31Z LDAP Injection GET /blog/anatomy-of-a-breach-dropbox-source-code ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
52 2026-08-20T01:27:08Z LDAP Injection GET /blog/anatomy-of-a-breach-twitch ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
53 2026-08-20T09:03:05Z LDAP Injection GET /blog/what-is-hipaa ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
54 2026-08-21T02:17:52Z LDAP Injection GET /blog/will-the-testers-require-administrative-credentials ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
55 2026-08-21T13:02:40Z LDAP Injection GET /blog/penetration-testing-vs-red-teaming-differences ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
56 2026-08-21T14:55:30Z LDAP Injection GET /cookie-policy ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
57 2026-08-21T19:48:00Z LDAP Injection GET /blog/anatomy-of-a-breach-south-carolina-dor ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
58 2026-08-21T21:42:04Z LDAP Injection GET /blog/anatomy-of-a-breach-2020-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
59 2026-08-22T05:47:06Z LDAP Injection GET /blog/should-penetration-testing-be-combined-with-a-vulnerability-management-programme ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
60 2026-08-22T06:22:37Z LDAP Injection GET /blog/how-do-phishing-simulations-differ-from-real-adversary-social-engineering-campaigns ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
61 2026-08-22T17:57:24Z LDAP Injection GET /blog/what-are-the-typical-root-causes-behind-recurring-critical-vulnerabilities ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
62 2026-08-22T21:56:30Z LDAP Injection GET /blog/what-is-hipaa ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
63 2026-08-22T22:46:00Z LDAP Injection GET /blog/testing-saas-and-shared-responsibility ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
64 2026-08-23T00:51:43Z LDAP Injection GET /blog/airspace-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
65 2026-08-23T05:51:05Z LDAP Injection GET /blog/crest-approved-penetration-testing-company ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
66 2026-08-23T07:09:56Z LDAP Injection GET /blog/anatomy-of-a-breach-microsoft-midnight-blizzard ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
67 2026-08-23T09:04:07Z LDAP Injection GET /blog/cyber-essentials-demystified-ce-vs-ce-plus ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
68 2026-08-23T14:50:15Z LDAP Injection GET /blog/anatomy-of-a-breach-marriott-starwood ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
69 2026-08-23T19:44:09Z LDAP Injection GET /blog/cambridge-analytica-breach-deep-dive ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
70 2026-08-23T21:21:07Z LDAP Injection GET /blog/anatomy-of-a-breach-costa-rica-conti ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i

In Summary

You came. You saw. You got absolutely owned by a hedgehog.

Every request you made was detected, logged, and laughed at. Our WAF didn't even break a sweat. Maybe next time try something more challenging — like reading a book on operational security.

Pro tip: If you're going to hack a cybersecurity company, maybe don't use the same IP address for every single request. Just a thought.