# Apache ModSecurity rules for SHELLS SecRuleEngine On SecRule REQUEST_URI "SimAttacker\ \-\ \(\?:Version\|Vrsion\)\ :\ \[0\-9\.\]\+\ \-" "id:1312,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "B4TM4N\ SH3LL\.\*" "id:1305,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\(r57\ Shell\ Version\ \[0\-9\.\]\+\|r57\ shell\)" "id:1303,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^\ nnnng00nshell\ v\[0\-9\.\]\+" "id:1321,phase:1,deny,status:403,log,msg:'shells attack detected'" SecRule REQUEST_URI "\^<html>n<title>\.\*\?\ \~\ Shell\ Inn