Congratulations,
Dumbass

> cat /var/log/your-failures.log_

A very special round of applause for 57.141.20.9 for their valiant — and entirely unsuccessful — attempt to compromise our systems. We truly couldn't have done it without you. Well, actually we could. We did. You failed.

We Might Not Know Where You Live, But...

Did you think you were anonymous? That's adorable. Here's what we know about you:

IP Address 57.141.20.9
Country United States
Region New York
City New York
ISP / Org Unknown
Timezone Unknown
Coordinates 40.7126, -74.0066

Your Digital Fingerprint

Nice browser you've got there. It'd be a shame if someone… logged it.

meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler))

Your Hall of Shame

Every single one of your pathetic attempts, lovingly preserved for posterity. Spoiler alert: they all failed.

Attack Breakdown

4
SQL Injection
65
LDAP Injection
69
Total Failed Attempts

Detailed Activity Log

# Timestamp Attack Type Method Target URI Detail
1 2026-06-13T09:43:33Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
2 2026-06-13T12:30:47Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
3 2026-06-15T12:52:11Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
4 2026-06-15T21:06:07Z SQL Injection GET /blog/null sqli [HEADER][HTTP_ACCEPT] matched /\/\*[\s\S]*?\*\//
5 2026-08-06T01:47:11Z LDAP Injection GET /blog/cyber-essentials-demystified-danzell-changes ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
6 2026-08-06T06:07:58Z LDAP Injection GET /blog/anatomy-of-a-breach-tesco-bank ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
7 2026-08-06T06:53:40Z LDAP Injection GET /blog/anatomy-of-a-breach-cloudbleed ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
8 2026-08-06T11:29:19Z LDAP Injection GET /blog/anatomy-of-a-breach-icbc-lockbit ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
9 2026-08-06T12:42:21Z LDAP Injection GET /blog/from-the-hacker-desk-misconfigured-api-endpoints ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
10 2026-08-06T20:16:58Z LDAP Injection GET /blog/uk-government-breaches-pattern-of-failure ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
11 2026-08-06T23:00:52Z LDAP Injection GET /blog/questions-before-commissioning-penetration-test ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
12 2026-08-07T03:54:56Z LDAP Injection GET /blog/what-exploitation-means-in-a-pen-test ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
13 2026-08-07T04:36:57Z LDAP Injection GET /blog/anatomy-of-a-breach-panama-papers ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
14 2026-08-07T04:52:13Z LDAP Injection GET /blog/anatomy-of-a-breach-labour-party-ddos ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
15 2026-08-07T09:08:27Z LDAP Injection GET /blog/penetration-testing-challenge-assumptions-not-confirm-comfort ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
16 2026-08-07T10:46:12Z LDAP Injection GET /blog/wifi-penetration-testing-of-companies ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
17 2026-08-07T11:48:17Z LDAP Injection GET /blog/from-the-hacker-desk-vlan-not-segmented ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
18 2026-08-07T14:51:20Z LDAP Injection GET /blog/can-penetration-testing-be-done-remotely ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
19 2026-08-07T15:54:57Z LDAP Injection GET /blog/understanding-pass-the-hash-attack-how-hackers-exploit-password-vulnerabilities ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
20 2026-08-08T01:23:23Z LDAP Injection GET /blog/anatomy-of-a-breach-equifax ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
21 2026-08-08T16:43:58Z LDAP Injection GET /blog/anatomy-of-a-breach-vtech ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
22 2026-08-08T22:45:51Z LDAP Injection GET /blog/what-is-the-real-impact-of-outdated-ssltls-configurations ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
23 2026-08-09T00:54:45Z LDAP Injection GET /blog/can-a-penetration-test-demonstrate-resilience-against-ransomware ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
24 2026-08-09T02:37:11Z LDAP Injection GET /wireless-spectrum-security ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
25 2026-08-09T07:21:49Z LDAP Injection GET /blog/chaining-low-risk-findings ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
26 2026-08-09T22:11:32Z LDAP Injection GET /blog/anatomy-of-a-breach-marriott-starwood ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
27 2026-08-09T22:44:38Z LDAP Injection GET /blog/chrome-zero-day-cve-2026-3909-3910-patch-now ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
28 2026-08-10T13:02:18Z LDAP Injection GET /blog/anatomy-of-a-breach-british-airways-magecart ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
29 2026-08-10T13:13:59Z LDAP Injection GET /blog/anatomy-of-a-breach-clearview-ai ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
30 2026-08-10T22:47:07Z LDAP Injection GET /blog/anatomy-of-a-breach-2014-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
31 2026-08-11T04:08:36Z LDAP Injection GET /blog/anatomy-of-a-breach-ticketmaster-dixons ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
32 2026-08-11T07:14:53Z LDAP Injection GET /blog/testing-saas-and-shared-responsibility ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
33 2026-08-11T09:54:46Z LDAP Injection GET /blog/what-are-the-most-common-misconfigurations-discovered-during-internal-network-tests ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
34 2026-08-11T12:29:07Z LDAP Injection GET /blog/cyber-essentials-demystified-firewalls ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
35 2026-08-11T15:58:54Z LDAP Injection GET /blog/anatomy-of-a-breach-wikileaks-manning ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
36 2026-08-11T19:07:08Z LDAP Injection GET /blog/annual-penetration-testing-requirements-uk-gdpr ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
37 2026-08-11T20:15:35Z LDAP Injection GET /blog/anatomy-of-a-breach-baltimore-ransomware ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
38 2026-08-11T21:18:46Z LDAP Injection GET /blog/anatomy-of-a-breach-cloudbleed ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
39 2026-08-12T02:40:42Z LDAP Injection GET /blog/anatomy-of-a-breach-jp-morgan-chase ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
40 2026-08-12T06:02:45Z LDAP Injection GET /news-sitemap.xml ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
41 2026-08-12T09:13:52Z LDAP Injection GET /blog/anatomy-of-a-breach-operation-aurora ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
42 2026-08-12T11:32:25Z LDAP Injection GET /blog/anatomy-of-a-breach-sap-netweaver ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
43 2026-08-12T13:32:05Z LDAP Injection GET /blog/from-the-hacker-desk-lift-reconnaissance-platform ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
44 2026-08-12T16:56:02Z LDAP Injection GET /blog/anatomy-of-a-breach-att-ipad-email ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
45 2026-08-12T20:06:32Z LDAP Injection GET /blog/anatomy-of-a-breach-uk-ico-enforcement-2012 ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
46 2026-08-13T18:49:49Z LDAP Injection GET /blog/anatomy-of-a-breach-moonpig ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
47 2026-08-13T22:36:01Z LDAP Injection GET /blog/anatomy-of-a-breach-rbs-worldpay ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
48 2026-08-15T04:24:17Z LDAP Injection GET /blog/muddywater ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
49 2026-08-15T08:58:20Z LDAP Injection GET /blog/anatomy-of-a-breach-manchester-united ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
50 2026-08-15T13:39:16Z LDAP Injection GET /blog/cyber-essentials-demystified-danzell-changes ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
51 2026-08-15T19:13:43Z LDAP Injection GET /blog/anatomy-of-a-breach-carphone-warehouse ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
52 2026-08-15T19:26:03Z LDAP Injection GET /blog/anatomy-of-a-breach-premera-blue-cross ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
53 2026-08-15T20:01:45Z LDAP Injection GET /blog/the-digital-parasite-why-attackers-stopped-breaking-things-and-started-moving-in ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
54 2026-08-15T21:39:38Z LDAP Injection GET /blog/why-automated-tools-are-not-enough ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
55 2026-08-16T00:42:53Z LDAP Injection GET /blog/anatomy-of-a-breach-2014-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
56 2026-08-16T07:16:57Z LDAP Injection GET /blog/penetration-testing-risk-management-governance ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
57 2026-08-16T16:42:57Z LDAP Injection GET /blog/anatomy-of-a-breach-red-cross-icrc ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
58 2026-08-17T05:26:21Z LDAP Injection GET /blog/anatomy-of-a-breach-garmin-wastedlocker ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
59 2026-08-17T17:26:49Z LDAP Injection GET /blog/anatomy-of-a-breach-synnovis-nhs-london ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
60 2026-08-17T18:32:06Z LDAP Injection GET /blog/from-the-hacker-desk-wifi-car-park ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
61 2026-08-18T08:45:11Z LDAP Injection GET /blog/anatomy-of-a-breach-adobe ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
62 2026-08-18T20:58:35Z LDAP Injection GET /blog/anatomy-of-a-breach-medibank ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
63 2026-08-19T04:21:56Z LDAP Injection GET /blog/cyber-security-resilience-bill-what-uk-businesses-need-to-know ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
64 2026-08-20T09:16:00Z LDAP Injection GET /blog/sector-under-the-microscope-financial-services ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
65 2026-08-20T12:49:32Z LDAP Injection GET /blog/what-evidence-will-i-receive-for-audit-or-compliance-purposes ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
66 2026-08-20T13:25:15Z LDAP Injection GET /blog/anatomy-of-a-breach-marriott-starwood ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
67 2026-08-20T17:07:12Z LDAP Injection GET /blog/sector-under-the-microscope-local-government ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
68 2026-08-20T22:31:39Z LDAP Injection GET /blog/why-do-many-penetration-test-reports-fail-to-drive-meaningful-remediation ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i
69 2026-08-21T16:20:40Z LDAP Injection GET /blog/anatomy-of-a-breach-2013-year-review ldap_injection [HEADER][HTTP_USER_AGENT] matched /[)(|*\\]\s*[)(|*\\]/i

In Summary

You came. You saw. You got absolutely owned by a hedgehog.

Every request you made was detected, logged, and laughed at. Our WAF didn't even break a sweat. Maybe next time try something more challenging — like reading a book on operational security.

Pro tip: If you're going to hack a cybersecurity company, maybe don't use the same IP address for every single request. Just a thought.