# Apache ModSecurity rules for SHELLS
SecRuleEngine On
SecRule REQUEST_URI "B4TM4N\ SH3LL\.\*" "id:1293,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "
\.::\ \.\*\ \~\ Ashiyane\ V\ \[0\-9\.\]\+\ ::\." "id:1295,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "lama's'hell\ v\.\ \[0\-9\.\]\+" "id:1302,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI ">SmEvK_PaThAn\ Shell\ v\[0\-9\]\+\ coded\ by\ s72\ Shell\ v\[0\-9\.\]\+\ Codinf\ by\ Cr@zy_King" "id:1307,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "@contains\ webadmin\.php
" "id:1315,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^\ ::\ b374k\ m1n1\ \[0\-9\.\]\+\ ::" "id:1314,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "Mini\ Shell\.\*Developed\ By\ LameHacker" "id:1294,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^\ \*n\[\ \]\+n\[\ \]\+lostDC\ \-" "id:1303,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^\.\*\?\ \-\ WSO\ \[0\-9\.\]\+" "id:1292,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^PHP\ Web\ Shellrnrnrn\ \ \ \ " "id:1304,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^nnRu24PostWebShell\ \-" "id:1306,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^rnrnrnPhpSpy\ Ver\ \[0\-9\]\+" "id:1308,phase:1,deny,status:403,log,msg:'shells attack detected'"
SecRule REQUEST_URI "\^n\.\*\?\ \~\ Shell\ Inn