# Apache ModSecurity rules for SHELLS
SecRuleEngine On
SecRule REQUEST_URI "\^rn
rnGRP\ WebShell\ \[0\-9\.\]\+" "id:1321,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^\ \*n\[\ \]\+n\[\ \]\+lostDC\ \-" "id:1326,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^n\ \ \ \ \ \ n\ \ \ \ \ \ \ \ \ \ \ \ \ azrail\ \[0\-9\.\]\+\ by\ C\-W\-M" "id:1334,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\.::\ \.\*\ \~\ Ashiyane\ V\ \[0\-9\.\]\+\ ::\." "id:1318,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^nnInput\ command\ :
n