Files
patterns/waf_patterns/apache/rfi.conf

7 lines
473 B
Plaintext
Raw Normal View History

# Apache ModSecurity rules for RFI
SecRuleEngine On
2025-01-15 00:26:17 +00:00
SecRule REQUEST_URI "!@endsWith\ \.%\{request_headers\.host\}" "id:1029,phase:1,deny,status:403,log,msg:'rfi attack detected'"
2025-01-14 00:25:28 +00:00
SecRule REQUEST_URI "!@endsWith\ \.%\{request_headers\.host\}" "id:1030,phase:1,deny,status:403,log,msg:'rfi attack detected'"
2025-01-15 00:26:17 +00:00
SecRule REQUEST_URI "\^\(\?i:file\|ftps\?\|https\?\)://\(\?:d\{1,3\}\.d\{1,3\}\.d\{1,3\}\.d\{1,3\}\)" "id:1028,phase:1,deny,status:403,log,msg:'rfi attack detected'"