kys18
This commit is contained in:
@@ -16,9 +16,9 @@ SecRule ARGS "(?i)\b(select|insert|update|delete|drop|union|grant|alter|truncate
|
|||||||
"id:950002,phase:2,deny,status:403,msg:'SQL Injection: Keyword',log,t:urlDecode,t:lowercase"
|
"id:950002,phase:2,deny,status:403,msg:'SQL Injection: Keyword',log,t:urlDecode,t:lowercase"
|
||||||
|
|
||||||
# sql3 (teste)
|
# sql3 (teste)
|
||||||
SecRule ARGS|ARGS_NAMES|REQUEST_COOKIES|REQUEST_COOKIES_NAMES|REQUEST_HEADERS|XML:/*|JSON:/* \
|
# SecRule ARGS|ARGS_NAMES|REQUEST_COOKIES|REQUEST_COOKIES_NAMES|REQUEST_HEADERS|XML\
|
||||||
"(?i)(select\s|insert\s|update\s|delete\s|drop\s|union\s|--|#|/\*|\*/|'|\"|%27|%22|<script>|<|>|%3C|%3E|exec\s|system\s|/etc/passwd|\.\./|%00)" \
|
# "(?i)(select\s|insert\s|update\s|delete\s|drop\s|union\s|--|#|/\*|\*/|'|\")"\
|
||||||
"id:950100,phase:2,deny,status:403,msg:'SQL',log,t:urlDecode,t:lowercase"
|
# "id:950100,phase:2,deny,status:403,msg:'SQL',log,t:urlDecode,t:lowercase"
|
||||||
|
|
||||||
# xss / html injection
|
# xss / html injection
|
||||||
SecRule REQUEST_URI|ARGS "(<.*>)|(%3C.*%3E)" \
|
SecRule REQUEST_URI|ARGS "(<.*>)|(%3C.*%3E)" \
|
||||||
|
|||||||
Reference in New Issue
Block a user