Congratulations,
Dumbass

> cat /var/log/your-failures.log_

A very special round of applause for 57.141.20.25 for their valiant — and entirely unsuccessful — attempt to compromise our systems. We truly couldn't have done it without you. Well, actually we could. We did. You failed.

We Might Not Know Where You Live, But...

Did you think you were anonymous? That's adorable. Here's what we know about you:

IP Address 57.141.20.25
Country United States
Region New York
City New York
ISP / Org Unknown
Timezone Unknown
Coordinates 40.7126, -74.0066

Your Digital Fingerprint

Nice browser you've got there. It'd be a shame if someone… logged it.

meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 Edg/146.0.0.0 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))

Your Hall of Shame

Every single one of your pathetic attempts, lovingly preserved for posterity. Spoiler alert: they all failed.

Attack Breakdown

1
General Fuzzing / Forced Browsing
7
SQL Injection
76
LDAP Injection
84
Total Failed Attempts

Detailed Activity Log

# Timestamp Attack Type Method Target URI Detail
1 2026-03-15T04:53:12Z General Fuzzing / Forced Browsing GET /uploads/crest-pentest-logo.avif Forced browsing attempt: /uploads/crest-pentest-logo.avif
2 2026-06-13T15:07:11Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
3 2026-06-13T18:30:12Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
4 2026-06-13T18:42:40Z SQL Injection GET /wp-content/uploads/2020/03/NGINX-Plus_product-page-hero.png sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
5 2026-06-13T19:21:03Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
6 2026-06-14T07:55:48Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
7 2026-06-15T14:34:49Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
8 2026-06-17T04:56:45Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
9 2026-08-06T06:10:47Z LDAP Injection GET /blog/anatomy-of-a-breach-mod-laptop-theft ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
10 2026-08-06T06:12:14Z LDAP Injection GET /blog/how-often-do-regulators-expect-penetration-testing-to-be-performed ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
11 2026-08-06T11:08:20Z LDAP Injection GET /blog/anatomy-of-a-breach-watering-hole-silicon-valley ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
12 2026-08-06T13:33:35Z LDAP Injection GET /blog/apt1-the-persistent-data-hoarder ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
13 2026-08-06T16:25:01Z LDAP Injection GET /blog/anatomy-of-a-breach-british-airways-magecart ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
14 2026-08-06T20:05:50Z LDAP Injection GET /blog/cloud-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
15 2026-08-06T21:29:55Z LDAP Injection GET /blog/can-penetration-testing-help-with-cyber-essentials-plus-certification ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
16 2026-08-07T07:11:16Z LDAP Injection GET /blog/what-tools-do-professional-penetration-testers-typically-use ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
17 2026-08-07T22:54:51Z LDAP Injection GET /blog/anatomy-of-a-breach-mod-laptop-theft ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
18 2026-08-08T06:56:22Z LDAP Injection GET /blog/78-percent-uk-manufacturers-cyber-incidents-2026 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
19 2026-08-09T00:47:38Z LDAP Injection GET /blog/pentesting-ai-engines-and-guardrails ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
20 2026-08-09T14:27:11Z LDAP Injection GET /blog/what-are-the-typical-root-causes-behind-recurring-critical-vulnerabilities ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
21 2026-08-09T16:41:17Z LDAP Injection GET /news_sitemap.xml ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
22 2026-08-09T18:15:37Z LDAP Injection GET /blog/capgemini-data-breach-20gb-of-sensitive-information-stolen ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
23 2026-08-09T18:33:58Z LDAP Injection GET /case-studies ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
24 2026-08-09T23:15:36Z LDAP Injection GET /blog/anatomy-of-a-breach-hackney-council ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
25 2026-08-10T04:10:40Z LDAP Injection GET /blog/anatomy-of-a-breach-2011-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
26 2026-08-10T11:35:39Z LDAP Injection GET /blog/no-critical-findings-does-not-mean-secure ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
27 2026-08-10T21:12:31Z LDAP Injection GET /blog/anatomy-of-a-breach-western-digital ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
28 2026-08-10T21:51:33Z LDAP Injection GET /blog/anatomy-of-a-breach-uber ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
29 2026-08-11T19:08:57Z LDAP Injection GET /blog/uk-government-breaches-six-month-update ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
30 2026-08-12T04:00:29Z LDAP Injection GET /blog/anatomy-of-a-breach-home-depot ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
31 2026-08-12T06:26:26Z LDAP Injection GET /blog/anatomy-of-a-breach-belvoir-park-hospital ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
32 2026-08-12T08:00:45Z LDAP Injection GET /blog/anatomy-of-a-breach-zoom-security ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
33 2026-08-12T13:17:28Z LDAP Injection GET /blog/anatomy-of-a-breach-t-mobile-uk-insider ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
34 2026-08-12T16:24:47Z LDAP Injection GET /blog/what-makes-a-penetration-test-valuable-to-security-operations-teams ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
35 2026-08-12T20:42:00Z LDAP Injection GET /blog/anatomy-of-a-breach-dropbox-source-code ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
36 2026-08-12T23:54:00Z LDAP Injection GET /blog/anatomy-of-a-breach-operation-tovar ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
37 2026-08-13T19:09:18Z LDAP Injection GET /blog/anatomy-of-a-breach-steam-valve ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
38 2026-08-13T21:02:08Z LDAP Injection GET /blog/sector-under-the-microscope-legal ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
39 2026-08-14T03:00:25Z LDAP Injection GET /blog/anatomy-of-a-breach-t-mobile-us-2018 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
40 2026-08-14T04:03:17Z LDAP Injection GET /blog/anatomy-of-a-breach-2013-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
41 2026-08-14T09:31:18Z LDAP Injection GET /sitemap-index.xml ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
42 2026-08-14T10:46:44Z LDAP Injection GET /blog/78-percent-uk-manufacturers-cyber-incidents-2026 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
43 2026-08-14T13:17:07Z LDAP Injection GET /blog/anatomy-of-a-breach-sony-psn ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
44 2026-08-14T23:38:29Z LDAP Injection GET /blog/pentesting-ai-engines-and-guardrails ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
45 2026-08-15T00:35:45Z LDAP Injection GET /blog/netcat-deep-dive-the-swiss-army-knife-of-networking ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
46 2026-08-15T04:50:31Z LDAP Injection GET /blog/anatomy-of-a-breach-mariposa-botnet ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
47 2026-08-15T07:16:42Z LDAP Injection GET /blog/anatomy-of-a-breach-medibank ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
48 2026-08-15T14:56:13Z LDAP Injection GET /sitemap.html ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
49 2026-08-15T17:18:01Z LDAP Injection GET /blog/salt-typhoon ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
50 2026-08-15T23:55:11Z LDAP Injection GET /blog/what-are-the-biggest-misconceptions-boards-have-about-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
51 2026-08-16T15:45:48Z LDAP Injection GET /blog/modelling-real-world-threat-scenarios ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
52 2026-08-16T20:11:07Z LDAP Injection GET /blog/penetration-testing-elevates-cyber-essentials-plus ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
53 2026-08-17T05:34:09Z LDAP Injection GET /blog/how-are-wireless-networks-typically-compromised-during-an-engagement ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
54 2026-08-17T06:26:35Z LDAP Injection GET /blog/what-is-the-real-impact-of-outdated-ssltls-configurations ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
55 2026-08-17T07:18:50Z LDAP Injection GET /blog/sector-under-the-microscope-aerial-uav-security ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
56 2026-08-18T01:22:53Z LDAP Injection GET /blog/anatomy-of-a-breach-snapchat ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
57 2026-08-18T01:36:39Z LDAP Injection GET /blog/anatomy-of-a-breach-moonpig ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
58 2026-08-18T02:06:16Z LDAP Injection GET /blog/anatomy-of-a-breach-cryptolocker ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
59 2026-08-18T02:13:37Z LDAP Injection GET /blog/anatomy-of-a-breach-blackbaud ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
60 2026-08-18T03:51:42Z LDAP Injection GET /blog/crest-approved-penetration-testing-company ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
61 2026-08-18T07:42:54Z LDAP Injection GET /blog/apt42 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
62 2026-08-18T08:20:38Z LDAP Injection GET /blog/anatomy-of-a-breach-t-mobile-us-2021 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
63 2026-08-18T17:23:09Z LDAP Injection GET /blog/anatomy-of-a-breach-uk-electoral-commission ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
64 2026-08-18T17:33:39Z LDAP Injection GET /blog/anatomy-of-a-breach-3cx-supply-chain ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
65 2026-08-18T20:49:38Z LDAP Injection GET /blog/executive-summaries-fund-or-fail-remediation ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
66 2026-08-19T00:48:23Z LDAP Injection GET /blog/penetration-testing-checklist-for-business-owners ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
67 2026-08-19T05:24:24Z LDAP Injection GET /blog/dora-requirements-penetration-testing-deep-dive ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
68 2026-08-19T05:45:11Z LDAP Injection GET /blog/ashley-madison-breach-deep-dive ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
69 2026-08-19T09:37:24Z LDAP Injection GET /blog/anatomy-of-a-breach-garmin-wastedlocker ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
70 2026-08-19T10:35:07Z LDAP Injection GET /blog/what-are-the-ethical-boundaries-of-professional-hacking ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
71 2026-08-19T21:17:37Z LDAP Injection GET /cyber-essentials ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
72 2026-08-19T23:36:55Z LDAP Injection GET /blog/uk-government-breaches-2026-update ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
73 2026-08-20T00:03:26Z LDAP Injection GET /blog/from-the-hacker-desk-superyacht-keylock ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
74 2026-08-20T01:08:18Z LDAP Injection GET /blog/anatomy-of-a-breach-cambridge-analytica ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
75 2026-08-20T01:39:43Z LDAP Injection GET /wireless-spectrum-security ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
76 2026-08-20T12:32:21Z LDAP Injection GET /blog/anatomy-of-a-breach-facebook-plaintext-passwords ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
77 2026-08-20T12:56:28Z LDAP Injection GET /blog/cyber-essentials-demystified-action-plan ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
78 2026-08-20T15:52:05Z LDAP Injection GET /blog/apt10 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
79 2026-08-20T16:12:28Z LDAP Injection GET /blog/anatomy-of-a-breach-mega-breach-dumps ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
80 2026-08-21T18:23:15Z LDAP Injection GET /blog/anatomy-of-a-breach-marks-spencer ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
81 2026-08-22T08:02:19Z LDAP Injection GET /blog/sector-under-the-microscope-construction ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
82 2026-08-22T18:53:22Z LDAP Injection GET /blog/what-are-the-biggest-misconceptions-boards-have-about-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
83 2026-08-22T19:25:51Z LDAP Injection GET /blog/apt10 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
84 2026-08-22T21:26:44Z LDAP Injection GET /blog/pen-test-reports-prioritise-security-investment ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i

In Summary

You came. You saw. You got absolutely owned by a hedgehog.

Every request you made was detected, logged, and laughed at. Our WAF didn't even break a sweat. Maybe next time try something more challenging — like reading a book on operational security.

Pro tip: If you're going to hack a cybersecurity company, maybe don't use the same IP address for every single request. Just a thought.