# Nginx WAF rules for SHELLS location / { set $attack_detected 0; if ($request_uri ~* "@lt 1") { set $attack_detected 1; } if ($request_uri ~* "@lt 1") { set $attack_detected 1; } if ($request_uri ~* "@pmFromFile web-shells-php.data") { set $attack_detected 1; } if ($request_uri ~* "@rx (r57 Shell Version [0-9.]+|r57 shell)") { set $attack_detected 1; } if ($request_uri ~* "@rx ^.*? - WSO [0-9.]+") { set $attack_detected 1; } if ($request_uri ~* "@rx B4TM4N SH3LL.*") { set $attack_detected 1; } if ($request_uri ~* "@rx Mini Shell.*Developed By LameHacker") { set $attack_detected 1; } if ($request_uri ~* "@rx .:: .* ~ Ashiyane V [0-9.]+ ::.") { set $attack_detected 1; } if ($request_uri ~* "@rx Symlink_Sa [0-9.]+") { set $attack_detected 1; } if ($request_uri ~* "@rx CasuS [0-9.]+ by MafiABoY") { set $attack_detected 1; } if ($request_uri ~* "@rx ^rnrnGRP WebShell [0-9.]+") { set $attack_detected 1; } if ($request_uri ~* "@rx <small>NGHshell [0-9.]+ by Cr4sh</body></html>n$") { set $attack_detected 1; } if ($request_uri ~* "@rx <title>SimAttacker - (?:Version|Vrsion) : [0-9.]+ -") { set $attack_detected 1; } if ($request_uri ~* "@rx ^<!DOCTYPE html>n<html>n<!-- By Artyum .*<title>Web Shell") { set $attack_detected 1; } if ($request_uri ~* "@rx lama's'hell v. [0-9.]+") { set $attack_detected 1; } if ($request_uri ~* "@rx ^ *n[ ]+n[ ]+lostDC -") { set $attack_detected 1; } if ($request_uri ~* "@rx ^<title>PHP Web Shellrnrnrn ") { set $attack_detected 1; } if ($request_uri ~* "@rx ^nn
Input command :
n
") { set $attack_detected 1; } if ($request_uri ~* "@rx ^nnRu24PostWebShell -") { set $attack_detected 1; } if ($request_uri ~* "@rx <title>s72 Shell v[0-9.]+ Codinf by Cr@zy_King") { set $attack_detected 1; } if ($request_uri ~* "@rx ^rnrnrnPhpSpy Ver [0-9]+") { set $attack_detected 1; } if ($request_uri ~* "@rx ^ nnnng00nshell v[0-9.]+") { set $attack_detected 1; } if ($request_uri ~* "@contains <title>punkholicshell") { set $attack_detected 1; } if ($request_uri ~* "@rx ^n n azrail [0-9.]+ by C-W-M") { set $attack_detected 1; } if ($request_uri ~* "@rx >SmEvK_PaThAn Shell v[0-9]+ coded by n.*? ~ Shell Inn