# Apache ModSecurity rules for SHELLS SecRuleEngine On SecRule REQUEST_URI "NGHshell\ \[0\-9\.\]\+\ by\ Cr4shn\$" "id:1330,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ nnnng00nshell\ v\[0\-9\.\]\+" "id:1340,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "<title>Mini\ Shell\.\*Developed\ By\ LameHacker" "id:1325,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "CasuS\ \[0\-9\.\]\+\ by\ MafiABoY" "id:1328,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\.\*\?\ \-\ WSO\ \[0\-9\.\]\+" "id:1323,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "Symlink_Sa\ \[0\-9\.\]\+" "id:1327,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^n\.\*\?\ \~\ Shell\ Inn