🛡️ Grit Firewall

VPS 37.27.120.81 · SSH attack monitor · collinlabs.space
Overview
Login Attempts
Attackers by IP
🛑 RCE Attackers
🔐 System
Analytics
Total attempts
Failed
Successful
Unique attacker IPs
Last seen (KST)

Attack trend

Top attacker IPs

Top targeted usernames

Login attempts — click any row for details

#Time (KST)ResultIPSessionsCountry CityISPHost (rDNS)UserMethodPort

All attacker IPs — ranked by session count · click any row for full profile

#IP addressCountryTotalFailed SuccessFlagsISP / networkLast seen (UTC)

⚠ Application-layer compromise — attacker gets ROOT via the Next.js frontend, not SSH

A single unauthenticated POST with a Next-Action header + prototype-pollution body (__proto__:then / constructor:constructor) reaches the JS Function constructor and runs code inside the Node process. Because pm2 runs the app as root, that is instant root-level RCE — no SSH, no password, no escalation. Full write-up: 5.Audit/05-nextjs-rce-compromise.md.
RCE artifacts recorded
Still active
Critical severity
Removed / mitigated
Last observed (KST)

RCE attack chain & indicators — click any row for full detail

#StatusSeverityKill-chainIndicator TechniqueTargetTime (KST · to the second)
source: MongoDB security_db.rce_attacks · seeded from live forensics 2026-07-05

🔒 System — password required

Enter the password to open the System area (captured credentials + live sessions).

By country

Top ISPs / networks

Attempts per day (last 30 days) — UTC+9

collinlabs.space · store: MongoDB security_db.ssh_logins · auto-refresh 10s