# Apache ModSecurity rules for SHELLS SecRuleEngine On SecRule REQUEST_URI "@contains\ webadmin\.php" "id:1338,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^rnrnGRP\ WebShell\ \[0\-9\.\]\+" "id:1321,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>n\ \ \ \ \ \ <head>n\ \ \ \ \ \ \ \ \ \ \ \ \ <title>azrail\ \[0\-9\.\]\+\ by\ C\-W\-M" "id:1334,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "@contains\ punkholicshell" "id:1333,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ nnnng00nshell\ v\[0\-9\.\]\+" "id:1332,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI ">SmEvK_PaThAn\ Shell\ v\[0\-9\]\+\ coded\ by\ <a\ href=" "id:1335,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<!DOCTYPE\ html>n<html>n<!\-\-\ By\ Artyum\ \.\*<title>Web\ Shell" "id:1324,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\(r57\ Shell\ Version\ \[0\-9\.\]\+\|r57\ shell\)" "id:1314,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ ::\ b374k\ m1n1\ \[0\-9\.\]\+\ ::" "id:1337,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\.::\ \.\*\ \~\ Ashiyane\ V\ \[0\-9\.\]\+\ ::\." "id:1318,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "lama's'hell\ v\.\ \[0\-9\.\]\+" "id:1325,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "B4TM4N\ SH3LL\.\*" "id:1316,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ \*n\[\ \]\+n\[\ \]\+lostDC\ \-" "id:1326,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<title>PHP\ Web\ Shellrnrnrn\ \ \ \ " "id:1327,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^nnRu24PostWebShell\ \-" "id:1329,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "<title>SimAttacker\ \-\ \(\?:Version\|Vrsion\)\ :\ \[0\-9\.\]\+\ \-" "id:1323,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>rn<head>rn<meta\ http\-equiv="Content\-Type"\ content="text/html;\ charset=gb2312">rn<title>PhpSpy\ Ver\ \[0\-9\]\+" "id:1331,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^nnInput\ command\ :n" "id:1328,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^n\.\*\?\ \~\ Shell\ Inn