# Apache ModSecurity rules for SHELLS
SecRuleEngine On
SecRule REQUEST_URI "\^\ \*n\[\ \]\+
n\[\ \]\+lostDC\ \-" "id:1307,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@contains\ punkholicshell" "id:1314,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI ">SmEvK_PaThAn\ Shell\ v\[0\-9\]\+\ coded\ by\ \.\*\?\ \-\ WSO\ \[0\-9\.\]\+" "id:1296,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "SimAttacker\ \-\ \(\?:Version\|Vrsion\)\ :\ \[0\-9\.\]\+\ \-" "id:1304,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^n\.\*\?\ \~\ Shell\ Inn