mirror of
https://github.com/fabriziosalmi/patterns.git
synced 2025-12-17 17:55:48 +00:00
7 lines
473 B
Plaintext
7 lines
473 B
Plaintext
# Apache ModSecurity rules for RFI
|
|
SecRuleEngine On
|
|
|
|
SecRule REQUEST_URI "!@endsWith\ \.%\{request_headers\.host\}" "id:1137,phase:1,deny,status:403,log,msg:'rfi attack detected'"
|
|
SecRule REQUEST_URI "\^\(\?i:file\|ftps\?\|https\?\)://\(\?:d\{1,3\}\.d\{1,3\}\.d\{1,3\}\.d\{1,3\}\)" "id:1136,phase:1,deny,status:403,log,msg:'rfi attack detected'"
|
|
SecRule REQUEST_URI "!@endsWith\ \.%\{request_headers\.host\}" "id:1138,phase:1,deny,status:403,log,msg:'rfi attack detected'"
|