Congratulations,
Dumbass

> cat /var/log/your-failures.log_

A very special round of applause for 57.141.20.21 for their valiant — and entirely unsuccessful — attempt to compromise our systems. We truly couldn't have done it without you. Well, actually we could. We did. You failed.

We Might Not Know Where You Live, But...

Did you think you were anonymous? That's adorable. Here's what we know about you:

IP Address 57.141.20.21
Country United States
Region New York
City New York
ISP / Org Unknown
Timezone Unknown
Coordinates 40.7126, -74.0066

Your Digital Fingerprint

Nice browser you've got there. It'd be a shame if someone… logged it.

meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))

Your Hall of Shame

Every single one of your pathetic attempts, lovingly preserved for posterity. Spoiler alert: they all failed.

Attack Breakdown

4
SQL Injection
41
LDAP Injection
45
Total Failed Attempts

Detailed Activity Log

# Timestamp Attack Type Method Target URI Detail
1 2026-06-13T19:36:12Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
2 2026-06-14T13:15:12Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
3 2026-06-16T02:45:50Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
4 2026-06-16T04:25:29Z SQL Injection GET /wp-content/uploads/2020/03/NGINX-Plus_product-page-hero.png sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
5 2026-08-06T01:37:22Z LDAP Injection GET /blog/cyber-essentials-demystified-ce-vs-ce-plus ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
6 2026-08-06T16:48:47Z LDAP Injection GET /blog/anatomy-of-a-breach-credential-stuffing-epidemic ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
7 2026-08-07T07:11:08Z LDAP Injection GET /terms-of-service ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
8 2026-08-08T03:39:46Z LDAP Injection GET /blog/metasploit-deep-dive-exploitation-framework ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
9 2026-08-08T03:59:22Z LDAP Injection GET /blog/anatomy-of-a-breach-global-payments ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
10 2026-08-09T00:52:13Z LDAP Injection GET /blog/sector-under-the-microscope-local-government ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
11 2026-08-09T13:45:27Z LDAP Injection GET /blog/smart-slider-wordpress-supply-chain-attack-april-2026 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
12 2026-08-09T19:09:39Z LDAP Injection GET /blog/business-guide-to-penetration-testing-understanding-your-report ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
13 2026-08-09T22:18:04Z LDAP Injection GET /blog/anatomy-of-a-breach-powerschool ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
14 2026-08-10T02:25:35Z LDAP Injection GET /blog/anatomy-of-a-breach-uk-retail-siege ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
15 2026-08-10T18:25:33Z LDAP Injection GET /blog/what-happens-before-a-penetration-test ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
16 2026-08-11T00:26:08Z LDAP Injection GET /blog/cloud-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
17 2026-08-11T01:47:36Z LDAP Injection GET /blog/what-credentials-should-a-penetration-testing-company-hold ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
18 2026-08-11T02:18:07Z LDAP Injection GET /blog/what-are-the-early-warning-signs-that-your-organisation-is-ready-for-a-red-team-simulation ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
19 2026-08-11T10:04:48Z LDAP Injection GET /blog/anatomy-of-a-breach-change-healthcare ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
20 2026-08-11T21:00:19Z LDAP Injection GET /blog/anatomy-of-a-breach-hse-jbs-ransomware ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
21 2026-08-11T21:52:41Z LDAP Injection GET /blog/anatomy-of-a-breach-2010-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
22 2026-08-12T03:42:55Z LDAP Injection GET /blog/how-are-wireless-networks-typically-compromised-during-an-engagement ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
23 2026-08-12T04:26:42Z LDAP Injection GET /blog/apt41 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
24 2026-08-12T04:44:48Z LDAP Injection GET /blog/how-do-testers-safely-exploit-vulnerabilities-without-disrupting-live-business-systems ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
25 2026-08-12T05:00:52Z LDAP Injection GET /blog/how-do-we-define-the-scope-of-a-penetration-test-properly ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
26 2026-08-12T07:34:52Z LDAP Injection GET /blog/custom-payloads-encoding-evasion-metasploit ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
27 2026-08-12T08:33:13Z LDAP Injection GET /blog/anatomy-of-a-breach-gonzalez-sentenced ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
28 2026-08-12T15:28:11Z LDAP Injection GET /blog/anatomy-of-a-breach-eternalblue-released ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
29 2026-08-12T18:44:56Z LDAP Injection GET /blog/apt12-the-prcs-cyber-operative ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
30 2026-08-13T01:17:05Z LDAP Injection GET /blog/business-guide-to-penetration-testing-what-is-it ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
31 2026-08-13T02:19:19Z LDAP Injection GET /blog/openvas-deep-dive-vulnerability-scanning ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
32 2026-08-13T08:25:21Z LDAP Injection GET /blog/what-does-a-high-quality-executive-summary-in-a-penetration-test-report-look-like ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
33 2026-08-13T19:03:45Z LDAP Injection GET /wp-content/uploads/2020/03/shutterstock_71441182-scaled.jpg ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
34 2026-08-14T01:46:28Z LDAP Injection GET /blog/anatomy-of-a-breach-livingsocial ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
35 2026-08-14T06:09:43Z LDAP Injection GET /blog/anatomy-of-a-breach-wannacry ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
36 2026-08-14T14:32:50Z LDAP Injection GET /blog/chaining-low-risk-findings ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
37 2026-08-14T23:55:58Z LDAP Injection GET /blog/how-do-penetration-testers-evaluate-third-party-and-supply-chain-exposure ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
38 2026-08-15T07:20:45Z LDAP Injection GET /blog/anatomy-of-a-breach-national-public-data ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
39 2026-08-15T07:30:17Z LDAP Injection GET /blog/anatomy-of-a-breach-equifax ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
40 2026-08-15T10:39:28Z LDAP Injection GET /blog/can-penetration-testing-identify-insider-threats ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
41 2026-08-15T14:59:02Z LDAP Injection GET /blog/anatomy-of-a-breach-spamhaus-ddos ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
42 2026-08-15T17:41:06Z LDAP Injection GET /blog/snowden-nsa-leak-deep-dive ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
43 2026-08-15T21:45:42Z LDAP Injection GET /blog/what-differentiates-a-high-assurance-testing-firm-from-a-commodity-provider ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
44 2026-08-16T03:51:11Z LDAP Injection GET /blog/anatomy-of-a-breach-tfl ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
45 2026-08-16T07:59:50Z LDAP Injection GET /blog/what-makes-a-web-application-penetration-test-genuinely-thorough ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i

In Summary

You came. You saw. You got absolutely owned by a hedgehog.

Every request you made was detected, logged, and laughed at. Our WAF didn't even break a sweat. Maybe next time try something more challenging — like reading a book on operational security.

Pro tip: If you're going to hack a cybersecurity company, maybe don't use the same IP address for every single request. Just a thought.