Congratulations,
Dumbass

> cat /var/log/your-failures.log_

A very special round of applause for 57.141.20.4 for their valiant — and entirely unsuccessful — attempt to compromise our systems. We truly couldn't have done it without you. Well, actually we could. We did. You failed.

We Might Not Know Where You Live, But...

Did you think you were anonymous? That's adorable. Here's what we know about you:

IP Address 57.141.20.4
Country United States
Region New York
City New York
ISP / Org Unknown
Timezone Unknown
Coordinates 40.7126, -74.0066

Your Digital Fingerprint

Nice browser you've got there. It'd be a shame if someone… logged it.

meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))

Your Hall of Shame

Every single one of your pathetic attempts, lovingly preserved for posterity. Spoiler alert: they all failed.

Attack Breakdown

10
SQL Injection
61
LDAP Injection
71
Total Failed Attempts

Detailed Activity Log

# Timestamp Attack Type Method Target URI Detail
1 2026-06-12T13:08:38Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
2 2026-06-13T21:21:53Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
3 2026-06-13T21:22:51Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
4 2026-06-14T02:03:30Z SQL Injection GET /wp-content/uploads/2020/03/NGINX-Plus_product-page-hero.png sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
5 2026-06-14T05:55:12Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
6 2026-06-14T08:48:16Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
7 2026-06-15T22:22:31Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
8 2026-06-16T23:18:28Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
9 2026-06-17T03:04:34Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
10 2026-06-25T05:34:50Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
11 2026-08-05T21:01:58Z LDAP Injection GET /blog/wifi-penetration-testing-of-companies ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
12 2026-08-06T03:59:33Z LDAP Injection GET /blog/what-is-the-difference-between-black-box-grey-box-and-white-box-testing-and-which-should-i-choose ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
13 2026-08-06T10:31:51Z LDAP Injection GET /blog/cyber-essentials-demystified-five-controls-overview ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
14 2026-08-06T23:59:22Z LDAP Injection GET /index.php/blog/key-concepts-of-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
15 2026-08-07T16:38:46Z LDAP Injection GET /blog/what-are-the-risks-of-relying-solely-on-automated-testing-tools ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
16 2026-08-07T22:10:37Z LDAP Injection GET /blog/anatomy-of-a-breach-twitch ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
17 2026-08-07T23:06:00Z LDAP Injection GET /blog/vulnerability-list-vs-narrative-report ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
18 2026-08-08T02:09:33Z LDAP Injection GET /blog/will-the-testers-require-administrative-credentials ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
19 2026-08-08T02:15:01Z LDAP Injection GET /blog/snowden-nsa-leak-deep-dive ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
20 2026-08-08T04:11:58Z LDAP Injection GET /blog/what-does-a-crest-aligned-penetration-testing-methodology-actually-involve ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
21 2026-08-08T05:18:44Z LDAP Injection GET /blog/anatomy-of-a-breach-uk-ico-enforcement-2012 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
22 2026-08-08T09:19:12Z LDAP Injection GET /blog/what-credentials-should-a-penetration-testing-company-hold ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
23 2026-08-08T09:26:12Z LDAP Injection GET /blog/how-does-physical-penetration-testing-differ-from-digital-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
24 2026-08-08T13:14:43Z LDAP Injection GET /blog/penetration-testing-for-small-business-uk ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
25 2026-08-08T18:58:07Z LDAP Injection GET /blog/what-are-the-risks-of-relying-solely-on-automated-testing-tools ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
26 2026-08-09T03:58:55Z LDAP Injection GET /blog/anatomy-of-a-breach-2016-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
27 2026-08-09T04:34:38Z LDAP Injection GET /blog/anatomy-of-a-breach-microsoft-midnight-blizzard ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
28 2026-08-09T18:33:43Z LDAP Injection GET /blog/anatomy-of-a-breach-2024-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
29 2026-08-09T18:37:41Z LDAP Injection GET /blog/sector-under-the-microscope-professional-services ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
30 2026-08-10T17:55:50Z LDAP Injection GET /blog/how-do-i-justify-penetration-testing-expenditure-to-the-board ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
31 2026-08-10T22:36:50Z LDAP Injection GET /blog/can-penetration-testing-uncover-weaknesses-in-remote-working-and-vpn-architectures ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
32 2026-08-11T05:58:12Z LDAP Injection GET /blog/anatomy-of-a-breach-zoom-security ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
33 2026-08-11T09:26:52Z LDAP Injection GET /blog/anatomy-of-a-breach-2009-year-in-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
34 2026-08-11T18:46:28Z LDAP Injection GET /blog/how-do-penetration-testing-results-integrate-with-a-siem-or-soc ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
35 2026-08-12T12:31:26Z LDAP Injection GET /blog/anatomy-of-a-breach-adobe ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
36 2026-08-13T04:11:55Z LDAP Injection GET /blog/anatomy-of-a-breach-icbc-lockbit ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
37 2026-08-13T04:51:06Z LDAP Injection GET /blog/anatomy-of-a-breach-wikileaks-manning ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
38 2026-08-13T06:15:53Z LDAP Injection GET /blog/anatomy-of-a-breach-atlanta-samsam ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
39 2026-08-13T17:21:42Z LDAP Injection GET /blog/anatomy-of-a-breach-talktalk ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
40 2026-08-13T21:56:51Z LDAP Injection GET /blog/anatomy-of-a-breach-2009-year-in-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
41 2026-08-14T08:23:30Z LDAP Injection GET /blog/business-guide-to-penetration-testing-when-to-test ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
42 2026-08-15T00:30:51Z LDAP Injection GET /blog/the-human-element-of-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
43 2026-08-15T06:17:29Z LDAP Injection GET /blog/penetration-testing-incident-preparedness-breach-pathways ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
44 2026-08-15T11:24:07Z LDAP Injection GET /blog/how-do-testers-simulate-insider-threat-scenarios ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
45 2026-08-15T12:13:08Z LDAP Injection GET /penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
46 2026-08-15T15:36:35Z LDAP Injection GET /blog/business-guide-to-penetration-testing-scoping ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
47 2026-08-15T19:51:59Z LDAP Injection GET /blog/anatomy-of-a-breach-clearview-ai ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
48 2026-08-16T07:36:05Z LDAP Injection GET /blog/is-it-better-to-use-the-same-provider-each-year-or-rotate-suppliers ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
49 2026-08-16T18:22:54Z LDAP Injection GET /blog/how-do-we-ensure-minimal-reputational-risk-during-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
50 2026-08-17T05:45:46Z LDAP Injection GET /blog/anatomy-of-a-breach-hollywood-presbyterian-ransomware ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
51 2026-08-17T16:20:06Z LDAP Injection GET /blog/anatomy-of-a-breach-tjx-tk-maxx ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
52 2026-08-17T19:22:57Z LDAP Injection GET /blog/how-to-choose-a-penetration-testing-provider ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
53 2026-08-17T19:58:56Z LDAP Injection GET /blog/anatomy-of-a-breach-t-mobile-us-2018 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
54 2026-08-17T20:43:31Z LDAP Injection GET /blog/can-penetration-testing-help-with-cyber-essentials-plus-certification ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
55 2026-08-17T22:54:34Z LDAP Injection GET /blog/what-are-the-biggest-misconceptions-boards-have-about-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
56 2026-08-18T02:26:37Z LDAP Injection GET /blog/internal-vs-external-penetration-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
57 2026-08-18T06:36:52Z LDAP Injection GET /blog/cyber-essentials-demystified-action-plan ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
58 2026-08-19T01:02:52Z LDAP Injection GET /blog/anatomy-of-a-breach-new-york-times-china ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
59 2026-08-19T03:58:36Z LDAP Injection GET /blog/anatomy-of-a-breach-snowden-nsa ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
60 2026-08-19T04:24:57Z LDAP Injection GET /blog/anatomy-of-a-breach-nhs-advanced-lastpass ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
61 2026-08-19T08:35:25Z LDAP Injection GET /blog/anatomy-of-a-breach-marriott-starwood ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
62 2026-08-19T09:45:40Z LDAP Injection GET /blog/do-i-need-board-approval-before-commissioning-a-penetration-test ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
63 2026-08-19T13:47:05Z LDAP Injection GET /blog/custom-payloads-encoding-evasion-metasploit ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
64 2026-08-19T16:06:34Z LDAP Injection GET /blog/how-do-testers-safely-exploit-vulnerabilities-without-disrupting-live-business-systems ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
65 2026-08-20T01:55:29Z LDAP Injection GET /blog/what-does-a-high-quality-executive-summary-in-a-penetration-test-report-look-like ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
66 2026-08-20T05:42:03Z LDAP Injection GET /blog/anatomy-of-a-breach-jp-morgan-chase ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
67 2026-08-20T16:32:00Z LDAP Injection GET /blog/how-do-testers-approach-active-directory-security-in-complex-enterprise-environments ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
68 2026-08-20T19:43:32Z LDAP Injection GET /blog/compliance-vs-threat-led-testing ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
69 2026-08-21T13:22:34Z LDAP Injection GET /blog/anatomy-of-a-breach-2017-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
70 2026-08-21T15:36:37Z LDAP Injection GET /blog/modelling-real-world-threat-scenarios ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
71 2026-08-21T21:26:02Z LDAP Injection GET /blog/testing-saas-and-shared-responsibility ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i

In Summary

You came. You saw. You got absolutely owned by a hedgehog.

Every request you made was detected, logged, and laughed at. Our WAF didn't even break a sweat. Maybe next time try something more challenging — like reading a book on operational security.

Pro tip: If you're going to hack a cybersecurity company, maybe don't use the same IP address for every single request. Just a thought.