# Apache ModSecurity rules for SHELLS
SecRuleEngine On
SecRule REQUEST_URI "@lt 1" "id:1231,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@lt 1" "id:1232,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@pmFromFile web-shells-php.data" "id:1233,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx (
r57 Shell Version [0-9.]+|r57 shell)" "id:1234,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx ^.*? - WSO [0-9.]+" "id:1235,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx B4TM4N SH3LL.*" "id:1236,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx Mini Shell.*Developed By LameHacker" "id:1237,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx .:: .* ~ Ashiyane V [0-9.]+ ::." "id:1238,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx Symlink_Sa [0-9.]+" "id:1239,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx CasuS [0-9.]+ by MafiABoY" "id:1240,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx ^rnrnGRP WebShell [0-9.]+" "id:1241,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx NGHshell [0-9.]+ by Cr4shn$" "id:1242,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx SimAttacker - (?:Version|Vrsion) : [0-9.]+ -" "id:1243,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx ^nn" "id:1247,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@rx ^nnInput command :
n