# Apache ModSecurity rules for SHELLS SecRuleEngine On SecRule REQUEST_URI "B4TM4N\ SH3LL\.\*" "id:1293,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\(r57\ Shell\ Version\ \[0\-9\.\]\+\|r57\ shell\)" "id:1291,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "NGHshell\ \[0\-9\.\]\+\ by\ Cr4shn\$" "id:1299,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^nnWeb\ Shell" "id:1301,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\.\*\?\ \-\ WSO\ \[0\-9\.\]\+" "id:1292,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^rnrnrnPhpSpy\ Ver\ \[0\-9\]\+" "id:1308,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ ::\ b374k\ m1n1\ \[0\-9\.\]\+\ ::" "id:1314,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^rnrnGRP\ WebShell\ \[0\-9\.\]\+" "id:1298,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>n<head>n<div\ align="left"><font\ size="1">Input\ command\ :</font></div>n<form\ name="cmd"\ method="POST"\ enctype="multipart/form\-data">" "id:1305,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "<title>lama's'hell\ v\.\ \[0\-9\.\]\+" "id:1302,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "@contains\ webadmin\.php" "id:1315,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^n\ \ \ \ \ \ n\ \ \ \ \ \ \ \ \ \ \ \ \ azrail\ \[0\-9\.\]\+\ by\ C\-W\-M" "id:1311,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\.::\ \.\*\ \~\ Ashiyane\ V\ \[0\-9\.\]\+\ ::\." "id:1295,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "s72\ Shell\ v\[0\-9\.\]\+\ Codinf\ by\ Cr@zy_King" "id:1307,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^PHP\ Web\ Shellrnrnrn\ \ \ \ " "id:1304,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "CasuS\ \[0\-9\.\]\+\ by\ MafiABoY" "id:1297,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^nnRu24PostWebShell\ \-" "id:1306,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ <html>nn<head>nn<title>g00nshell\ v\[0\-9\.\]\+" "id:1309,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "@contains\ <title>punkholicshell" "id:1310,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "Symlink_Sa\ \[0\-9\.\]\+" "id:1296,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^n\.\*\?\ \~\ Shell\ Inn