# Nginx WAF rules for SHELLS location / { set $attack_detected 0; if ($request_uri ~* "^PHP Web Shellrnrnrn ") { set $attack_detected 1; } if ($request_uri ~* "^nn