# Apache ModSecurity rules for SHELLS SecRuleEngine On SecRule REQUEST_URI "\^nnRu24PostWebShell\ \-" "id:1284,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ <html>nn<head>nn<title>g00nshell\ v\[0\-9\.\]\+" "id:1287,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>rn<head>rn<title>GRP\ WebShell\ \[0\-9\.\]\+" "id:1276,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>n\ \ \ \ \ \ <head>n\ \ \ \ \ \ \ \ \ \ \ \ \ <title>azrail\ \[0\-9\.\]\+\ by\ C\-W\-M" "id:1289,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "CasuS\ \[0\-9\.\]\+\ by\ MafiABoY" "id:1275,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^rnrnrnPhpSpy\ Ver\ \[0\-9\]\+" "id:1286,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^nnWeb\ Shell" "id:1279,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^nnInput\ command\ :n" "id:1283,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ \*n\[\ \]\+n\[\ \]\+lostDC\ \-" "id:1281,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>n<title>\.\*\?\ \~\ Shell\ Inn