# Apache ModSecurity rules for XSS
SecRuleEngine On
SecRule REQUEST_URI "\(\?i\)\]\*\[xbe>\]\|<\[\^xbe\]\*xbe" "id:1179,phase:1,deny,status:403,log,msg:'xss attack detected'"
SecRule REQUEST_URI "!@validateByteRange\ 20,\ 45\-47,\ 48\-57,\ 65\-90,\ 95,\ 97\-122" "id:1164,phase:1,deny,status:403,log,msg:'xss attack detected'"
SecRule REQUEST_URI "@detectXSS" "id:1182,phase:1,deny,status:403,log,msg:'xss attack detected'"
SecRule REQUEST_URI "\(\?i: