# Apache ModSecurity rules for SHELLS
SecRuleEngine On
SecRule REQUEST_URI "\^rn
rnGRP\ WebShell\ \[0\-9\.\]\+" "id:1298,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "lama's'hell\ v\.\ \[0\-9\.\]\+" "id:1302,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^\ nnnng00nshell\ v\[0\-9\.\]\+" "id:1309,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\.::\ \.\*\ \~\ Ashiyane\ V\ \[0\-9\.\]\+\ ::\." "id:1295,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^n\ \ \ \ \ \ n\ \ \ \ \ \ \ \ \ \ \ \ \ azrail\ \[0\-9\.\]\+\ by\ C\-W\-M" "id:1311,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "Mini\ Shell\.\*Developed\ By\ LameHacker" "id:1294,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "CasuS\ \[0\-9\.\]\+\ by\ MafiABoY" "id:1297,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^nnInput\ command\ :
n\.\*" "id:1293,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI ">SmEvK_PaThAn\ Shell\ v\[0\-9\]\+\ coded\ by\ NGHshell\ \[0\-9\.\]\+\ by\ Cr4shn\$" "id:1299,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^\.\*\?\ \-\ WSO\ \[0\-9\.\]\+" "id:1292,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "SimAttacker\ \-\ \(\?:Version\|Vrsion\)\ :\ \[0\-9\.\]\+\ \-" "id:1300,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "Symlink_Sa\ \[0\-9\.\]\+" "id:1296,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^rnrnrnPhpSpy\ Ver\ \[0\-9\]\+" "id:1308,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^n\.\*\?\ \~\ Shell\ Inn