# Apache ModSecurity rules for SHELLS SecRuleEngine On SecRule REQUEST_URI "\^nnInput\ command\ :n" "id:1115,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\.\*\?\ \-\ WSO\ \[0\-9\.\]\+" "id:1102,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^PHP\ Web\ Shellrnrnrn\ \ \ \ " "id:1114,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ ::\ b374k\ m1n1\ \[0\-9\.\]\+\ ::" "id:1124,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "Mini\ Shell\.\*Developed\ By\ LameHacker" "id:1104,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "lama's'hell\ v\.\ \[0\-9\.\]\+" "id:1112,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "Symlink_Sa\ \[0\-9\.\]\+" "id:1106,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "@contains\ webadmin\.php" "id:1125,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\.::\ \.\*\ \~\ Ashiyane\ V\ \[0\-9\.\]\+\ ::\." "id:1105,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^rnrnGRP\ WebShell\ \[0\-9\.\]\+" "id:1108,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<!DOCTYPE\ html>n<html>n<!\-\-\ By\ Artyum\ \.\*<title>Web\ Shell" "id:1111,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "CasuS\ \[0\-9\.\]\+\ by\ MafiABoY" "id:1107,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI ">SmEvK_PaThAn\ Shell\ v\[0\-9\]\+\ coded\ by\ \.\*" "id:1103,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^rnrnrnPhpSpy\ Ver\ \[0\-9\]\+" "id:1118,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "NGHshell\ \[0\-9\.\]\+\ by\ Cr4shn\$" "id:1109,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ nnnng00nshell\ v\[0\-9\.\]\+" "id:1119,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>n<head>n<title>Ru24PostWebShell\ \-" "id:1116,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "@contains\ <title>punkholicshell" "id:1120,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\(r57\ Shell\ Version\ \[0\-9\.\]\+\|r57\ shell\)" "id:1101,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "s72\ Shell\ v\[0\-9\.\]\+\ Codinf\ by\ Cr@zy_King" "id:1117,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^n\ \ \ \ \ \ n\ \ \ \ \ \ \ \ \ \ \ \ \ azrail\ \[0\-9\.\]\+\ by\ C\-W\-M" "id:1121,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ \*n\[\ \]\+n\[\ \]\+lostDC\ \-" "id:1113,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "<title>SimAttacker\ \-\ \(\?:Version\|Vrsion\)\ :\ \[0\-9\.\]\+\ \-" "id:1110,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>n<title>\.\*\?\ \~\ Shell\ Inn