# Nginx WAF rules for RFI # Automatically generated from OWASP rules. # Include this file in your server or location block. map $request_uri $waf_block_rfi { default 0; "~*^(?i:file|ftps?|https?)://(?:d{1,3}.d{1,3}.d{1,3}.d{1,3})" 1; "~*!@endsWith .%{request_headers.host}" 1; } if ($waf_block_rfi) { return 403; # Log the blocked request (optional) # access_log /var/log/nginx/waf_blocked.log; }