# Apache ModSecurity rules for SHELLS SecRuleEngine On SecRule REQUEST_URI "NGHshell\ \[0\-9\.\]\+\ by\ Cr4shn\$" "id:1284,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "Mini\ Shell\.\*Developed\ By\ LameHacker" "id:1279,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^nnInput\ command\ :n" "id:1290,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "SimAttacker\ \-\ \(\?:Version\|Vrsion\)\ :\ \[0\-9\.\]\+\ \-" "id:1285,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ \*<html>n\[\ \]\+<head>n\[\ \]\+<title>lostDC\ \-" "id:1288,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>rn<head>rn<meta\ http\-equiv="Content\-Type"\ content="text/html;\ charset=gb2312">rn<title>PhpSpy\ Ver\ \[0\-9\]\+" "id:1293,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^rnrnGRP\ WebShell\ \[0\-9\.\]\+" "id:1283,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "<title>s72\ Shell\ v\[0\-9\.\]\+\ Codinf\ by\ Cr@zy_King" "id:1292,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "CasuS\ \[0\-9\.\]\+\ by\ MafiABoY" "id:1282,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^n\.\*\?\ \~\ Shell\ Inn