New signatures for Google Hacks and Search engine recons, probes and attacks
By: Michael Shinn on: Fri 02 of Dec., 2005 22:26 EST ( Reads)|
I've added a new ruleset to the collection, "recons.conf" that contains the start of a ruleset to detect and block attacks that originate from, so called, "Google Hacks" - or the art of detecting vulnerable software by simply searching for it with Google. These rules only work with modsecurity 1.9.x and up, as I'm also starting the process of adding ids, revs, severity and msg variables to the rules, so if you are using modsecurity 1.8.x, these rules will not work for you - and may not even load. |
