# Apache ModSecurity rules for SHELLS
SecRuleEngine On
SecRule REQUEST_URI "
Symlink_Sa\ \[0\-9\.\]\+" "id:1203,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^\ ::\ b374k\ m1n1\ \[0\-9\.\]\+\ ::" "id:1221,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^\.\*\?\ \-\ WSO\ \[0\-9\.\]\+" "id:1199,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^\ \*n\[\ \]\+n\[\ \]\+lostDC\ \-" "id:1210,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^nnInput\ command\ :
n