# http://www.gotroot.com/mod_security+rules
# Gotroot.com ModSecurity rules
# Blacklist of rootkit sites, owned machines and other bad players for modsec 2.x
# NOTICE: THESE RULES ARE OBSOLETE AND ARE NO LONGER SUPPORTED
# Visit http://www.gotroot.com to download supported rules
#
# Download from: http://www.gotroot.com/downloads/ftp/mod_security/2.0/blacklist2.conf
#
# Created by Michael Shinn of the Prometheus Group (http://www.prometheus-group.com)
# Copyright 2005 and 2006 by Michael Shinn and the Prometheus Group, all rights reserved.
# Redistribution is strictly prohibited in any form, including whole or in part.
#
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS
# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
# THE POSSIBILITY OF SUCH DAMAGE.
# NOTICE: THESE RULES ARE OBSOLETE AND ARE NO LONGER SUPPORTED
# Visit http://www.gotroot.com to download supported rules
# http://www.gotroot.com/mod_security+rules
# Comment Spam Rules for modsec 2.x
# NOTICE: THESE RULES ARE OBSOLETE AND ARE NO LONGER SUPPORTED
# Visit http://www.gotroot.com to download supported rules
#
# Download from: http://www.gotroot.com/downloads/ftp/mod_security/2.0/blacklist.conf
#
# Created by Michael Shinn of the Prometheus Group (http://www.prometheus-group.com)
# Copyright 2005 and 2006 by Michael Shinn and the Prometheus Group, all rights reserved.
# Redistribution is strictly prohibited in any form, including whole or in part.
#
#Version: N-20061022-01
#
#
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS
# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
# THE POSSIBILITY OF SUCH DAMAGE.
#generic PHP forum posting exclusion
SecRuleRemoveById 300013
SecRuleRemoveById 300015
SecRuleRemoveById 300016
#PhpMyadmin
SecRuleRemoveById 300016
SecRuleRemoveById 300016
#/xde/managecontent.php
SecRuleRemoveById 300016
SecRuleRemoveById 300016
#PhpBB posting
SecRuleRemoveById 300013
#postnuke admin
SecRuleRemoveById 300016
#Postnuke uploads
SecRuleRemoveById 300013
#Tikiwiki forum
SecRuleRemoveById 300013
#Squirrel mail and Horde postings
SecRuleRemoveById 300013
SecRuleRemoveById 300015
SecRuleRemoveById 300016
#Provided by Todd Holforty
SecRuleRemoveById 300013
SecRuleRemoveById 300015
SecRuleRemoveById 300016
#Phorum posting
SecRuleRemoveById 300013
#Tikiwiki edit
SecRuleRemoveById 300013
SecRuleRemoveById 300013
SecRuleRemoveById 300016
###########################################
#Double pipe exclusion rules
###########################################
SecRuleRemoveById 300014
###########################################
#Front page exclusions
###########################################
SecRuleInheritance Off
SecRuleRemoveById 300016
SecRuleRemoveById 300016
###########################################
#Mambo/Joomla exclusions
###########################################
SecRuleRemoveById 380000
SecRuleRemoveById 300013
SecRuleRemoveById 300013
SecRuleRemoveById 300016
SecRuleRemoveById 380000
SecRuleRemoveById 360001
#Added 27AUG2006
#Courtesy of Tom Donovan
#ColdFusion RDS
SecRuleRemoveById 360001
#servlet/webacc
SecRuleRemoveById 300013
#WordPRess
SecRuleRemoveById 300015
#/profile.php
SecRuleRemoveById 300015
#Open-Exchange
SecRuleRemoveById 300015
#owl intranet
SecRuleRemoveById 300015
#http://www.gotroot.com
#see website for more information
SecRule REQUEST_URI "!(/compose\.php\?)" chain
SecRule ARGS|REQUEST_BODY|REQUEST_URI "Subject\:" chain
SecRule ARGS:Bcc ".*\@"
SecRule REQUEST_URI "!(/compose\.php\?)" chain
SecRule ARGS|REQUEST_BODY|REQUEST_URI "Subject\:" chain
SecRule ARGS|REQUEST_BODY|REQUEST_URI "\s*bcc\:"
SecRule REQUEST_URI "!(/compose\.php\?)" chain
SecRule ARGS|REQUEST_BODY|REQUEST_URI "\s*bcc\:\s*[a-z0-9._%-]+@[A-Z0-9.-]+\.[a-z]{2,}"
SecRule REQUEST_URI "!(/compose\.php\?)" chain
SecRule ARGS "\n[[:space:]]*(to|b?cc)[[:space:]]*:.*@"
SecRule REQUEST_URI "!(/compose\.php\?)" chain
SecRule ARGS "\s*bcc\:\s*[a-z0-9._%-]+\@.*\.[a-z]{2,}"
SecRule HTTP_x-aaaaaaaaa|HTTP_XAAAAAAAAA ".+$"
SecRule HTTP_x-aaaaaaaaaaa|HTTP_XAAAAAAAAAAA ".+$"
SecRule HTTP_x-aaaaaaaaaaaa|HTTP_X_AAAAAAAAAAAA ".+$"
#SecRule HTTP_XXXXXXXXXXXXXXX ".+$"
#unknown pattern in testing, logging only, please send
#any patterns RELATED TO SPAM OR ATTACKS you log with with these rules
#please do not send false positives for this rule set, just turn it off
#SecRule HTTP_aaaaaaaaa|HTTP_AAAAAAAAA ".+$" "log,pass"
#SecRule HTTP_aaaaaaaaaaa|HTTP_AAAAAAAAAAA ".+$" "log,pass"
#SecRule HTTP_aaaaaaaaaaaa|HTTP_AAAAAAAAAAAA ".+$" "log,pass"
#SecRule HTTP_aaaaaaaaaaaaaaa|HTTP_AAAAAAAAAAAAAAA ".+$" "log,pass"
SecRule HTTP_Referer|ARGS "(blow)+[\w\-_.]*(jobs?)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(gay)+[\w\-_.]*(beastiality)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(beastilality)+[\w\-_.]*(stories)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(free)+[\w\-_.]*(beastiality)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(horse|animal|dog)+[\w\-_.]*(porn|cocks|dick|sex|penis|blowj.*)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(buy)+[\w\-_.]*online[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(diet|penis)+[\w\-_.]*(pills|enlargement)[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(enlarg|enhanc).*(male|penis|natural).*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(enlarg|enhanc).*(male|penis|natural)\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(online)+[\w\-_.]*pharmacy"
SecRule HTTP_Referer|ARGS "(i|la)-sonneries?[\w\-_.]*\.[a-z]{2,}"
SecRule REQUEST_URI "!(/sugarcrm/index\.php)" chain
SecRule HTTP_Referer|ARGS "(silagra|morphine|ritalin|levitra|lolita|carisoprodol|phentermine|amitriptyline|diethylpropion|viagra|lisinopril|vig-?rx|zyban|valtex|xenical|adipex|meridia)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(ephedrine|neurontin|glucosamine|testosterone|cialis|lipitor|effexor|propecia|celebrex|gluclosamine|lexapro|ephedra|levitra)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(magazine)+[\w\-_.]*(finder|netfirms)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(male|penis)enlarg*\.(biz|com|net|org|us|info)"
SecRule HTTP_Referer|ARGS "(male|penis).*(enlarg|enhanc|natural|pill|surgery|traction)"
SecRule HTTP_Referer|ARGS "(mike)+[\w\-_.]*apartment[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(milf)+[\w\-_.]*(hunter|moms|fucking|lessons)[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(natural|penis|male).*(enlarg.*|enhanc.*)"
SecRule HTTP_Referer|ARGS "(natural|penis|male)+[\w\-_.]*(enlarg.*|enhanc.*)"
SecRule HTTP_Referer|ARGS "(online)+[\w\-_.]*(prescription|casino|roulette|slot)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "[\w\-_.]*(casino|roulette)\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "[\w\-_.]*(casino|roulette).*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(slot)+[\w\-_.]*machines\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(prozac|zoloft|xanax|valium|hydrocodone|vicodin|paxil|vioxx)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(ragazze)-?\w+\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(texas)+[\w\-_.]*holdem"
SecRule HTTP_Referer|ARGS "(phentermine)+[\w\-_.]*online"
SecRule HTTP_Referer|ARGS "(texas)+[\w\-_.]*hold[\w\-_.].*em"
SecRule HTTP_Referer|ARGS "texas[\w\-_.]hold[\w\-_.]em"
SecRule HTTP_Referer|ARGS "pacific+[\w\-_.]*poke.*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "poker+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "[\w\-_.]*poker\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "[\w\-_.]*poker.*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "poker.*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(random|free|internet)+[\w\-_.]*slots\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(wellbutrin|tenuate|tramadol|pheromones|phendimetrazine|ionamin|ortho.?tricyclen|retin.?a\b)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "ultram\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(celexa|valtrex|zyrtec|\bhgh\b|ambien\b|flonase|allegra|didrex|renova|bontril|nexium)+[\w\-_.]*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "([\w\-_.]+\.)?(l(so|os)tr)\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(lose[\w\-_.]*weight|weight[\w\-_.]*loss).*\.[a-z]{2,}"
SecRule HTTP_Referer|ARGS "(prices|pills|buy|diet*|medic(ine|ation|al)|dru.*)\.pharma.*\.[a-z]{2,}"
# http://www.gotroot.com/mod_security+rules
# Gotroot.com ModSecurity rules
# Just In Time Patches for Vulnerable Applications Rules for modsec 2.x
# NOTICE: THESE RULES ARE OBSOLETE AND ARE NO LONGER SUPPORTED
# Visit http://www.gotroot.com to download supported rules
#
# Version: N-20061022-01
#
# Download from: http://www.gotroot.com/downloads/ftp/mod_security/jitp.conf
#
# Created by Michael Shinn of the Prometheus Group (http://www.prometheus-group.com)
# Copyright 2005 and 2006 by Michael Shinn and the Prometheus Group, all rights reserved.
# Redistribution is strictly prohibited in any form, including whole or in part.
#
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS
# AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
# IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
# ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
# LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
# THE POSSIBILITY OF SUCH DAMAGE.
#
#--------------------------------
# notes
#--------------------------------
# Rules work with modsecurity 2.x and above only
#--------------------------------
#start rules
#--------------------------------
# WEB-CGI formmail
SecRule REQUEST_URI "/(formmail|mailform)(\x0a|\.pl\x0a)"
#pals-cgi arbitrary file access attempt
SecRule REQUEST_URI "/pals-cgi.*documentName="
# WEB-CGI phf arbitrary command execution attempt
SecRule REQUEST_URI "/phf" chain
SecRule REQUEST_URI "\x0a/"
# WEB-CGI phf access
SecRule REQUEST_URI "/phf\?"
# WEB-CGI htsearch arbitrary file read attempt
SecRule REQUEST_URI "/htsearch\?exclude=\`"
# WEB-CGI csSearch.cgi arbitrary command execution attempt
SecRule REQUEST_URI "/csSearch\.cgi\?" chain
SecRule REQUEST_URI "\`"
## WEB-CGI FormHandler.cgi directory traversal attempt attempt
SecRule REQUEST_URI "/FormHandler\.cgi" chain
SecRule REQUEST_URI "/\.\./"
# WEB-CGI FormHandler.cgi external site redirection attempt
SecRule REQUEST_URI "/FormHandler\.cgi" chain
SecRule REQUEST_URI "redirect=http"
# WEB-PHP squirrel mail spell-check arbitrary command attempt
SecRule REQUEST_URI "/squirrelspell/modules/check_me\.mod\.php" chain
SecRule REQUEST_URI "SQSPELL_APP\["
# WEB-PHP squirrel mail theme arbitrary command attempt
SecRule REQUEST_URI "/left_main\.php" chain
SecRule REQUEST_URI "cmdd="
# WEB-PHP directory.php arbitrary command attempt
SecRule REQUEST_URI "/directory\.php\?" chain
SecRule REQUEST_URI "\;"
# WEB-PHP PHPLIB remote commanSelective REQUEST_URI|REQUEST_BODYd attempt
SecRule REQUEST_URI|REQUEST_BODY "_PHPLIB\[libdir\]"
# WEB-PHP PHPLIB remote command attempt
SecRule REQUEST_URI "/db_mysql\.inc"
# Exploit phpBB Highlighting Code Execution Attempt
SecRule REQUEST_URI|REQUEST_BODY "(\;|\&)highlight=\'\.system\("
# Exploit phpBB Highlighting SQL Injection
SecRule REQUEST_URI|REQUEST_BODY "&highlight=\'\.mysql_query\("
# Exploit phpBB Highlighting Code Execution - Santy.A Worm
SecRule REQUEST_URI|REQUEST_BODY "&highlight=\'\.fwrite\(fopen\("
# Exploit phpBB Highlight Exploit Attempt
SecRule REQUEST_URI|REQUEST_BODY "&highlight=\x2527\x252Esystem\("
# WEB-CGI dcforum.cgi directory traversal attempt
SecRule REQUEST_URI "/dcforum\.cgi" chain
SecRule REQUEST_URI "forum=\.\./\.\."
# WEB-CGI dcboard.cgi invalid user addition attempt
SecRule REQUEST_URI "/dcboard\.cgi.*\|admin"
# WEB-CGI alchemy http server PRN arbitrary command execution attempt
SecRule REQUEST_URI|REQUEST_BODY "/PRN/\.\./\.\./"
# WEB-CGI alchemy http server NUL arbitrary command execution attempt
SecRule REQUEST_URI|REQUEST_BODY "/NUL/\.\./\.\./"
# WEB-CGI AltaVista Intranet Search directory traversal attempt
SecRule REQUEST_URI "/query\?mss=\.\."
# WEB-CGI hello.bat arbitrary command execution attempt
SecRule REQUEST_URI "/hello\.bat" chain
SecRule REQUEST_URI "\&"
# WEB-CGI Home Free search.cgi directory traversal attempt
SecRule REQUEST_URI "/search\.cgi" chain
SecRule REQUEST_URI "letter=\.\./\.\."
#campus attempt
SecRule REQUEST_URI "/campus\?\|0A\|"
# WEB-CGI pfdispaly.cgi arbitrary command execution attempt
SecRule REQUEST_URI "/pfdispaly\.cgi\?\'"
# WEB-CGI talkback.cgi directory traversal attempt
SecRule REQUEST_URI "/talkbalk\.cgi" chain
SecRule REQUEST_URI "article=\.\./\.\./"
# WEB-CGI technote main.cgi file directory traversal attempt
SecRule REQUEST_URI "/technote/main\.cgi" chain
SecRule REQUEST_URI "\.\./\.\./"
# WEB-CGI technote print.cgi directory traversal attempt
SecRule REQUEST_URI "/technote/print\.cgi.*\x00"
# WEB-CGI eXtropia webstore directory traversal
SecRule REQUEST_URI "/web_store\.cgi" chain
SecRule REQUEST_URI "page=\.\./"
# WEB-CGI shopping cart directory traversal
SecRule REQUEST_URI "/shop\.cgi" chain
SecRule REQUEST_URI "page=\.\./"
# WEB-CGI Allaire Pro Web Shell attempt
SecRule REQUEST_URI "/authenticate\.cgi\?PASSWORD" chain
SecRule REQUEST_URI "config\.ini"
# WEB-CGI Armada Style Master Index directory traversal
SecRule REQUEST_URI "/search\.cgi\?keys" chain
SecRule REQUEST_URI "catigory=\.\./"
# WEB-CGI cached_feed.cgi moreover shopping cart directory traversal
SecRule REQUEST_URI "/cached_feed\.cgi" chain
SecRule REQUEST_URI "\.\./"
# WEB-CGI Talentsoft Web+ exploit attempt
SecRule REQUEST_URI "/webplus\.cgi\?Script=/webplus/webping/webping\.wml"
# WEB-CGI txt2html.cgi directory traversal attempt
SecRule REQUEST_URI "/txt2html\.cgi" chain
SecRule REQUEST_URI "/\.\./\.\./\.\./\.\./"
# WEB-CGI store.cgi directory traversal attempt
SecRule REQUEST_URI "/store\.cgi" chain
SecRule REQUEST_URI "\.\./"
# WEB-CGI mrtg.cgi directory traversal attempt
SecRule REQUEST_URI "/mrtg\.cgi" chain
SecRule REQUEST_URI "cfg=/\.\./"
# WEB-CGI CCBill whereami.cgi arbitrary command execution attempt
SecRule REQUEST_URI "/whereami\.cgi\?g="
# WEB-CGI WhatsUpGold instancename overflow attempt
SecRule REQUEST_URI "/_maincfgret\.cgi"
#Demarc SQL injection attempt
SecRule REQUEST_URI "/dm/demarc.*s_key=.*\'"
# WEB-MISC apache directory disclosure attempt
SecRule REQUEST_URI|REQUEST_BODY "////////"
# WEB-MISC htgrep attempt
SecRule REQUEST_URI "/htgrep" chain
SecRule REQUEST_URI "hdr=/"
#musicat empower attempt
SecRule REQUEST_URI "/empower\?DB="
# WEB-PHP DNSTools administrator authentication bypass attempt
SecRule REQUEST_URI "/dnstools\.php" chain
SecRule REQUEST_URI "user_dnstools_administrator=true"
# WEB-PHP DNSTools authentication bypass attempt
SecRule REQUEST_URI "/dnstools\.php" chain
SecRule REQUEST_URI "user_logged_in=true"
#General phpbb_root_path vulnerabilities
SecRule ARGS:phpbb_root_path "((ht|f)tps?\:/|\.\./)" "id:390070,rev:1,severity:2,msg:'JITP: Generic phpbb_root_path exploit'"
# WEB-PHP phpbb quick-reply.php arbitrary command attempt
SecRule REQUEST_URI "/quick-reply\.php" chain
SecRule REQUEST_URI "phpbb_root_path="
# WEB-PHP Blahz-DNS dostuff.php modify user attempt
SecRule REQUEST_URI "/dostuff\.php\?action=modify_user"
# WEB-PHP PHP-Wiki cross site scripting attempt
SecRule REQUEST_URI "/modules\.php\?*name=Wiki*\<*(script|about|applet|activex|chrome)*\>"
# WEB-MISC *%0a.pl access
SecRule REQUEST_URI "/*\x0a\.pl"
# WEB-PHP strings overflow
SecRule REQUEST_URI|REQUEST_BODY "\?STRENGUR"
# WEB-PHP shoutbox.php directory traversal attempt
SecRule REQUEST_URI "/shoutbox\.php" chain
SecRule REQUEST_URI "\.\./"
# WEB-PHP b2 cafelog gm-2-b2.php remote file include attempt
SecRule REQUEST_URI "/gm-2-b2\.php" chain
SecRule REQUEST_URI "b2inc=(http|https|ftp)\:/"
# WEB-PHP BLNews objects.inc.php4 remote file include attempt
SecRule REQUEST_URI "/objects\.inc\.php*" chain
SecRule REQUEST_URI "Server\[path\]=(http|https|ftp)\:/"
# WEB-PHP ttCMS header.php remote file include attempt
SecRule REQUEST_URI "/admin/templates/header\.php" chain
SecRule REQUEST_URI "admin_root=(http|https|ftp)\:/"
# WEB-PHP autohtml.php directory traversal attempt
SecRule REQUEST_URI "/autohtml\.php" chain
SecRule REQUEST_URI "\.\./\.\./"
# WEB-PHP ttforum remote file include attempt
SecRule REQUEST_URI "forum/index\.php" chain
SecRule REQUEST_URI "template="
# WEB-PHP pmachine remote file include attempt
SecRule REQUEST_URI "lib\.inc\.php" chain
SecRule REQUEST_URI "pm_path=(http|https|ftp)\:/"
SecRule REQUEST_URI "lib\.inc\.php.*pm_path.*(http|https|ftp)\:/"
#rolis guestbook remote file include attempt
SecRule REQUEST_URI "/insert\.inc\.php*path="
# IdeaBox cord.php file include
SecRule REQUEST_URI "/index\.php*ideaDir*cord\.php"
#IdeaBox notification.php file include
SecRule REQUEST_URI "/index\.php*gorumDir*notification\.php"
# WEB-PHP DCP-Portal remote file include attempt
SecRule REQUEST_URI "/library/lib\.php" chain
SecRule REQUEST_URI "root="
# WEB-PHP IdeaBox cord.php file include
SecRule REQUEST_URI "/index\.php" chain
SecRule REQUEST_URI "cord\.php"
# WEB-PHP IdeaBox notification.php file include
SecRule REQUEST_URI "/index\.php" chain
SecRule REQUEST_URI "notification\.php"
# WEB-PHP Invision Board emailer.php file include
SecRule REQUEST_URI "/ad_member\.php" chain
SecRule REQUEST_URI "emailer\.php"
# WEB-PHP WebChat db_mysql.php file include
SecRule REQUEST_URI "/defines\.php" chain
SecRule REQUEST_URI "db_mysql\.php"
# WEB-PHP WebChat english.php file include
SecRule REQUEST_URI "/defines\.php" chain
SecRule REQUEST_URI "english\.php"
# WEB-PHP Typo3 translations.php file include
SecRule REQUEST_URI "/translations\.php" chain
SecRule REQUEST_URI "ONLY=\x2e"
# WEB-PHP news.php file include
SecRule REQUEST_URI "/news\.php" chain
SecRule REQUEST_URI "template"
# WEB-PHP YaBB SE packages.php file include
SecRule REQUEST_URI "/packages\.php" chain
SecRule REQUEST_URI "packer\.php"
# WEB-PHP newsPHP Language file include attempt
SecRule REQUEST_URI "/nphpd\.php" chain
SecRule REQUEST_URI "LangFile"
#myphpPagetool pt_config.inc file include
SecRule REQUEST_URI "/doc/admin*ptinclude*pt_config\.inc"
#Invision Board ipchat.php file include
SecRule REQUEST_URI "/ipchat\.php*root_path*conf_global\.php"
# WEB-PHP PhpGedView PGV authentication_index.php base directory manipulation attempt
SecRule REQUEST_URI "/authentication_index\.php" chain
SecRule REQUEST_URI "PGV_BASE_DIRECTORY=(http|https|ftp)\:/"
# WEB-PHP PhpGedView PGV functions.php base directory manipulation attempt
SecRule REQUEST_URI "/functions\.php" chain
SecRule REQUEST_URI "PGV_BASE_DIRECTORY"
# WEB-PHP TUTOS path disclosure attempt
SecRule REQUEST_URI "/note_overview\.php" chain
SecRule REQUEST_URI "id="
# WEB-PHP PhpGedView PGV base directory manipulation
SecRule REQUEST_URI "_conf\.php" chain
SecRule REQUEST_URI "PGV_BASE_DIRECTORY"
#PHPBB worm sigs
SecRule ARGS:highlight "(\x27|%27|\x2527|%2527)"
#Mailto domain search possible MyDoom.M,O
SecRule REQUEST_URI "/search\?hl=en&ie=UTF-8&oe=UTF-8&q=mailto\+" chain
SecRule REQUEST_URI "Host\: www\.google\.com"
#WEB-PHP EasyDynamicPages exploit
SecRule REQUEST_URI "edp_relative_path="
#Calendar XSS
SecRule REQUEST_URI "/(calendar|setup).php\?phpc_root_path=((http|https|ftp)\:/|<[[:space:]]*(script|about|applet|activex|chrome)*>.*(script|about|applet|activex|chrome)[[:space:]]*>)"
#phpMyAdmin Export.PHP File Disclosure Vulnerability
SecRule SCRIPT_FILENAME "export\.php$" chain
SecRule ARGS:what "\.\."
#nmap version request
SecRule REQUEST_URI|REQUEST_BODY "^(HELP|default|\||TNMP|DmdT|\:)$"
#More PHPBB worms
SecRule REQUEST_URI "/viewtopic\.php\?" chain
SecRule ARGS "(chr|fwrite|fopen|system|echr|passthru|popen|proc_open|shell_exec|exec|proc_nice|proc_terminate|proc_get_status|proc_close|pfsockopen|leak|apache_child_terminate|posix_kill|posix_mkfifo|posix_setpgid|posix_setsid|posix_setuid|phpinfo)\(([0-9a-fA-Fx]{1,3})\)"
# TIKIWIKI
SecRule REQUEST_URI "/tiki-map.phtml\?mapfile=\.\./\.\./"
# WEB-MISC BitKeeper arbitrary command attempt
SecRule REQUEST_URI "/diffs/" chain
SecRule REQUEST_URI "\'"
#awstats probe
SecRule REQUEST_URI|REQUEST_BODY "/awstats\.pl HTTP\/(0\.9|1\.0|1\.1)$" "id:390000,rev:1,severity:2,msg:'JITP: Awstats.pl probe'"
#/forum/viewtopic.php?x=http://
SecRule REQUEST_URI "/forum/viewtopic\.php\?x=(http|https|ftp)\:/"
# WEB-MISC Crystal Reports crystalImageHandler.aspx directory traversal attempt
SecRule REQUEST_URI "/crystalimagehandler\.aspx" chain
SecRule REQUEST_URI "dynamicimage=\.\./"
#mailman 2.x path recursion attack
SecRule REQUEST_URI|REQUEST_BODY "mailman/private/.*\.\.\./\.\.\.\.///"
SecRule REQUEST_URI|REQUEST_BODY "/mailman/.*\.\.\./"
#ftp.pl attempt
SecRule REQUEST_URI "/ftp\.pl\?dir=\.\./\.\."
#Tomcat server snoop access
SecRule REQUEST_URI "/jsp/snp/.*\.snp"
# WEB-CGI HyperSeek hsx.cgi directory traversal attempt
SecRule REQUEST_URI "/hsx\.cgi.*\x00"
# WEB-CGI SWSoft ASPSeek Overflow attempt
SecRule REQUEST_URI "/s\.cgi" chain
SecRule REQUEST_URI "tmpl="
# WEB-CGI /wwwboard/passwd.txt access
SecRule REQUEST_URI "/wwwboard/passwd\.txt"
# WEB-CGI webplus directory traversal
SecRule REQUEST_URI "/webplus\?script" chain
SecRule REQUEST_URI "\.\./"
# WEB-CGI websendmail access
SecRule REQUEST_URI "/websendmail"
# WEB-CGI anaconda directory transversal attempt
SecRule REQUEST_URI "/(apexec|anacondaclip)\.pl" chain
SecRule REQUEST_URI "template=\.\./"
# WEB-CGI imagemap.exe overflow attempt
SecRule REQUEST_URI "/imagemap\.exe\?"
# WEB-CGI htmlscript attempt
SecRule REQUEST_URI "/htmlscript\?\.\./\.\."
# WEB-CGI nph-test-cgi access
SecRule REQUEST_URI "/nph-test-cgi"
# WEB-CGI rwwwshell.pl access
SecRule REQUEST_URI "/rwwwshell\.pl"
# WEB-CGI view-source directory traversal
SecRule REQUEST_URI "/view-source" chain
SecRule REQUEST_URI "\.\./"
# WEB-CGI calendar_admin.pl arbitrary command execution attempt
SecRule REQUEST_URI "/calendar_admin.pl\?config=\|7C\|"
# WEB-CGI bb-hist.sh attempt
SecRule REQUEST_URI "/bb-hist\.sh\?HISTFILE=\.\./\.\."
# WEB-CGI bb-hostscv.sh attempt
SecRule REQUEST_URI "/bb-hostsvc\.sh\?HOSTSVC\?\.\./\.\."
# WEB-CGI wayboard attempt
SecRule REQUEST_URI "/way-board/way-board\.cgi" chain
SecRule REQUEST_URI "\.\./\.\."
# WEB-CGI commerce.cgi arbitrary file access attempt
SecRule REQUEST_URI "/commerce\.cgi" chain
SecRule REQUEST_URI "/\.\./"
# WEB-CGI Amaya templates sendtemp.pl directory traversal attempt
SecRule REQUEST_URI "/sendtemp\.pl" chain
SecRule REQUEST_URI "templ="
# WEB-CGI webspirs.cgi directory traversal attempt
SecRule REQUEST_URI "/webspirs\.cgi" chain
SecRule REQUEST_URI "\.\./\.\./"
# WEB-CGI auktion.cgi directory traversal attempt
SecRule REQUEST_URI "/auktion\.cgi" chain
SecRule REQUEST_URI "menue=\.\./\.\./"
# WEB-CGI cgiforum.pl attempt
SecRule REQUEST_URI "/cgiforum\.pl\?thesection=\.\./\.\."
# WEB-CGI directorypro.cgi attempt
SecRule REQUEST_URI "/directorypro\.cgi" chain
SecRule REQUEST_URI "\.\./\.\."
# WEB-CGI Web Shopper shopper.cgi attempt
SecRule REQUEST_URI "/shopper\.cgi" chain
SecRule REQUEST_URI "newpage=\.\./"
# WEB-CGI cal_make.pl directory traversal attempt
SecRule REQUEST_URI "/cal_make\.pl" chain
SecRule REQUEST_URI "p0=\.\./\.\./"
# WEB-CGI ttawebtop.cgi arbitrary file attempt
SecRule REQUEST_URI "/ttawebtop\.cgi" chain
SecRule REQUEST_URI "pg=\.\./"
# WEB-CGI ustorekeeper.pl directory traversal attempt
SecRule REQUEST_URI "/ustorekeeper\.pl" chain
SecRule REQUEST_URI "file=\.\./\.\./"
# WEB-CGI htsearch arbitrary configuration file attempt
SecRule REQUEST_URI "/htsearch\?\-c"
# WEB-CGI alibaba.pl arbitrary command execution attempt
SecRule REQUEST_URI "/alibaba\.pl(\|7C\||\x7C)"
# WEB-CGI AltaVista Intranet Search directory traversal attempt
SecRule REQUEST_URI "/query\?mss=\.\."
# WEB-CGI test.bat arbitrary command execution attempt
SecRule REQUEST_URI "/test.bat(\|7C\||\x7C)"
# WEB-CGI input.bat arbitrary command execution attempt
SecRule REQUEST_URI "/input.bat(\|7C\||\x7C)"
# WEB-CGI envout.bat arbitrary command execution attempt
SecRule REQUEST_URI "/envout.bat(\|7C\||\x7C)"
# WEB-CGI hello.bat arbitrary command execution attempt
SecRule REQUEST_URI "/hello\.bat" chain
SecRule REQUEST_URI "\&"
# WEB-CGI csSearch.cgi arbitrary command execution attempt
SecRule REQUEST_URI "/csSearch\.cgi" chain
SecRule REQUEST_URI "\`"
# WEB-CGI eshop.pl arbitrary commane execution attempt
SecRule REQUEST_URI "/eshop\.pl\?seite=(\|3B\|\x3B)"
# WEB-CGI loadpage.cgi directory traversal attempt
SecRule REQUEST_URI "/loadpage\.cgi" chain
SecRule REQUEST_URI "file=\.\./"
#faqmanager.cgi arbitrary file access attempt
SecRule REQUEST_URI "/faqmanager\.cgi\?toc=*/"
SecRule REQUEST_URI "/faqmanager\.cgi\?(cd|\;|perl|python|rpm|yum|apt-get|emerge|lynx|links|mkdir|elinks|cmd|pwd|wget|lwp-(download|request|mirror|rget)|id|uname|cvs|svn|(s|r)(cp|sh)|rexec|smbclient|t?ftp|ncftp|curl|telnet|gcc|cc|g\+\+|\./)"
# WEB-CGI Home Free search.cgi directory traversal attempt
SecRule REQUEST_URI "/search\.cgi" chain
SecRule REQUEST_URI "letter=\.\./\.\."
# WEB-CGI pfdispaly.cgi arbitrary command execution attempt
SecRule REQUEST_URI "/pfdispaly\.cgi\?'"
# WEB-CGI pagelog.cgi directory traversal attempt
SecRule REQUEST_URI "/pagelog\.cgi" chain
SecRule REQUEST_URI "name=\.\./"
# WEB-CGI talkback.cgi directory traversal attempt
SecRule REQUEST_URI "/talkbalk\.cgi" chain
SecRule REQUEST_URI "article=\.\./\.\./"
# WEB-CGI emumail.cgi NULL attempt
SecRule REQUEST_URI "/emumail\.cgi.*\x00"
# WEB-CGI technote main.cgi file directory traversal attempt
SecRule REQUEST_URI "/technote/main\.cgi" chain
SecRule REQUEST_URI "\.\./\.\./"
# WEB-CGI technote print.cgi directory traversal attempt
SecRule REQUEST_URI "/technote/print\.cgi.*\x00"
# WEB-CGI Allaire Pro Web Shell attempt
SecRule REQUEST_URI "/authenticate.cgi\?PASSWORD" chain
SecRule REQUEST_URI "config\.ini"
# WEB-CGI Armada Style Master Index directory traversal
SecRule REQUEST_URI "/search\.cgi\?keys" chain
SecRule REQUEST_URI "catigory=\.\./"
# WEB-CGI cached_feed.cgi moreover shopping cart directory traversal
SecRule REQUEST_URI "/cached_feed\.cgi" chain
SecRule REQUEST_URI "\.\./"
# WEB-CGI Talentsoft Web+ exploit attempt
SecRule REQUEST_URI "/webplus.cgi\?Script=/webplus/webping/webping\.wml"
# WEB-CGI bizdbsearch attempt
SecRule REQUEST_URI "/bizdb1-search\.cgi" chain
SecRule REQUEST_URI "mail"
# WEB-CGI sojourn.cgi File attempt
SecRule REQUEST_URI "/sojourn\.cgi\?cat=.*\x00"
# WEB-CGI SGI InfoSearch fname attempt
SecRule REQUEST_URI "/infosrch\.cgi\?" chain
SecRule REQUEST_URI "fname="
# WEB-CGI store.cgi directory traversal attempt
SecRule REQUEST_URI "/store\.cgi" chain
SecRule REQUEST_URI "\.\./"
# WEB-CGI SIX webboard generate.cgi attempt
SecRule REQUEST_URI "/generate\.cgi" chain
SecRule REQUEST_URI "content=\.\./"
# WEB-CGI story.pl arbitrary file read attempt
SecRule REQUEST_URI "/story\.pl" chain
SecRule REQUEST_URI "next=\.\./"
# WEB-CGI mrtg.cgi directory traversal attempt
SecRule REQUEST_URI "/mrtg\.cgi" chain
SecRule REQUEST_URI "cfg=/\.\./"
#alienform.cgi directory traversal attempt
SecRule REQUEST_URI "/alienform\.cgi.*\.\|7C\|\./\.\|7C\|\."
SecRule REQUEST_URI "/af\.cgi.*\.\|7C\|\./\.\|7C\|\."
# WEB-CGI CCBill whereami.cgi arbitrary command execution attempt
SecRule REQUEST_URI "/whereami\.cgi\?g="
# WEB-CGI MDaemon form2raw.cgi overflow attempt
SecRule REQUEST_URI "/form2raw\.cgi"
# WEB-CGI WhatsUpGold instancename overflow attempt
SecRule REQUEST_URI "/_maincfgret\.cgi"
#honeypot
SecRule REQUEST_URI|REQUEST_BODY "clamav-partial "
SecRule REQUEST_URI|REQUEST_BODY "vi\.recover "
# WEB-COLDFUSION cfcache.map access
SecRule REQUEST_URI "/cfcache\.map"
# WEB-COLDFUSION exampleapp application.cfm
SecRule REQUEST_URI "/cfdocs/exampleapp/email/application\.cfm"
# WEB-COLDFUSION application.cfm access
SecRule REQUEST_URI "/cfdocs/exampleapp/publish/admin/application\.cfm"
# WEB-COLDFUSION getfile.cfm access
SecRule REQUEST_URI "/cfdocs/exampleapp/email/getfile\.cfm"
# WEB-COLDFUSION addcontent.cfm access
SecRule REQUEST_URI "/cfdocs/exampleapp/publish/admin/addcontent\.cfm"
# WEB-COLDFUSION administrator access
SecRule REQUEST_URI "/cfide/administrator/index\.cfm"
# WEB-COLDFUSION fileexists.cfm access
SecRule REQUEST_URI "/cfdocs/snippets/fileexists\.cfm"
# WEB-COLDFUSION exprcalc access
SecRule REQUEST_URI "/cfdocs/expeval/exprcalc\.cfm"
# WEB-COLDFUSION parks access
SecRule REQUEST_URI "/cfdocs/examples/parks/detail\.cfm"
# WEB-COLDFUSION cfappman access
SecRule REQUEST_URI "/cfappman/index\.cfm"
# WEB-COLDFUSION beaninfo access
SecRule REQUEST_URI "/cfdocs/examples/cvbeans/beaninfo\.cfm"
# WEB-COLDFUSION evaluate.cfm access
SecRule REQUEST_URI "/cfdocs/snippets/evaluate\.cfm"
# WEB-COLDFUSION expeval access
SecRule REQUEST_URI "/cfdocs/expeval/"
# WEB-COLDFUSION displayfile access
SecRule REQUEST_URI "/cfdocs/expeval/displayopenedfile\.cfm"
# WEB-COLDFUSION mainframeset access
SecRule REQUEST_URI "/cfdocs/examples/mainframeset\.cfm"
# WEB-COLDFUSION exampleapp access
SecRule REQUEST_URI "/cfdocs/exampleapp/"
# WEB-COLDFUSION snippets attempt
SecRule REQUEST_URI "/cfdocs/snippets/"
# WEB-COLDFUSION cfmlsyntaxcheck.cfm access
SecRule REQUEST_URI "/cfdocs/cfmlsyntaxcheck\.cfm"
# WEB-COLDFUSION application.cfm access
SecRule REQUEST_URI "/application\.cfm"
# WEB-COLDFUSION onrequestend.cfm access
SecRule REQUEST_URI "/onrequestend\.cfm"
# WEB-COLDFUSION startstop DOS access
SecRule REQUEST_URI "/cfide/administrator/startstop\.html"
# WEB-COLDFUSION gettempdirectory.cfm access
SecRule REQUEST_URI "/cfdocs/snippets/gettempdirectory\.cfm"
# WEB-COLDFUSION sendmail.cfm access
SecRule REQUEST_URI "/sendmail\.cfm"
# WEB-COLDFUSION ?Mode=debug attempt
#SecRule REQUEST_URI "Mode=debug"
# WEB-MISC Tomcat view source attempt
SecRule REQUEST_URI|REQUEST_BODY "\x252ejsp"
# WEB-MISC unify eWave ServletExec upload
SecRule REQUEST_URI|REQUEST_BODY "/servlet/com\.unify\.servletexec\.UploadServlet"
# WEB-MISC Talentsoft Web+ Source Code view access
SecRule REQUEST_URI "/webplus\.exe\?script=test\.wml"
# WEB-MISC ftp.pl attempt
SecRule REQUEST_URI "/ftp\.pl\?dir=\.\./\.\."
# WEB-MISC apache source.asp file access
SecRule REQUEST_URI "/site/eg/source\.asp"
# WEB-MISC Tomcat server exploit access
SecRule REQUEST_URI "/contextAdmin/contextAdmin\.html"
# WEB-MISC Ecommerce import.txt access
SecRule REQUEST_URI "/orders/import\.txt"
# WEB-MISC Domino catalog.nsf access
SecRule REQUEST_URI "/catalog\.nsf"
# WEB-MISC Domino domcfg.nsf access
SecRule REQUEST_URI "/domcfg\.nsf"
# WEB-MISC Domino domlog.nsf access
SecRule REQUEST_URI "/domlog\.nsf"
# WEB-MISC Domino log.nsf access
SecRule REQUEST_URI "/log\.nsf"
# WEB-MISC Domino names.nsf access
SecRule REQUEST_URI "/names\.nsf"
# WEB-MISC Domino mab.nsf access
SecRule REQUEST_URI "/mab\.nsf"
# WEB-MISC Domino cersvr.nsf access
SecRule REQUEST_URI "/cersvr\.nsf"
# WEB-MISC Domino setup.nsf access
SecRule REQUEST_URI "/setup\.nsf"
# WEB-MISC Domino statrep.nsf access
SecRule REQUEST_URI "/statrep\.nsf"
# WEB-MISC Domino webadmin.nsf access
SecRule REQUEST_URI "/webadmin\.nsf"
# WEB-MISC Domino events4.nsf access
SecRule REQUEST_URI "/events4\.nsf"
# WEB-MISC Domino ntsync4.nsf access
SecRule REQUEST_URI "/ntsync4\.nsf"
# WEB-MISC Domino collect4.nsf access
SecRule REQUEST_URI "/collect4\.nsf"
# WEB-MISC Domino mailw46.nsf access
SecRule REQUEST_URI "/mailw46\.nsf"
# WEB-MISC Domino bookmark.nsf access
SecRule REQUEST_URI "/bookmark\.nsf"
# WEB-MISC Domino agentrunner.nsf access
SecRule REQUEST_URI "/agentrunner\.nsf"
# WEB-MISC Domino mail.box access
#SecRule REQUEST_URI "/mail.box"
# WEB-MISC Ecommerce checks.txt access
SecRule REQUEST_URI "/orders/checks\.txt"
# WEB-MISC mall log order access
SecRule REQUEST_URI "/mall_log_files/order\.log"
# WEB-MISC ROADS search.pl attempt
SecRule REQUEST_URI "/ROADS/cgi-bin/search\.pl" chain
SecRule REQUEST_URI "form="
# WEB-MISC SWEditServlet directory traversal attempt
SecRule REQUEST_URI "/SWEditServlet" chain
SecRule REQUEST_URI "template=\.\./\.\./\.\./"
# WEB-MISC RBS ISP /newuser directory traversal attempt
SecRule REQUEST_URI "/newuser\?Image=\.\./\.\."
# WEB-MISC PCCS mysql database admin tool access
SecRule REQUEST_URI "pccsmysqladm/incs/dbconnect\.inc"
# WEB-MISC ans.pl attempt
SecRule REQUEST_URI "/ans.pl\?p=\.\./\.\./"
# WEB-MISC Demarc SQL injection attempt
SecRule REQUEST_URI "/dm/demarc" chain
SecRule REQUEST_URI "\'"
# WEB-MISC philboard_admin.asp authentication bypass attempt
SecRule REQUEST_URI "/philboard_admin\.asp" chain
SecRule REQUEST_URI "philboard_admin=True"
# WEB-PHP Phorum /support/common.php access
SecRule REQUEST_URI "/support/common\.php"
# WEB-PHP rolis guestbook remote file include attempt
SecRule REQUEST_URI "/insert\.inc\.php" chain
SecRule REQUEST_URI "path="
# book.cgi arbitrary command execution attempt
SecRule REQUEST_URI "/book\.cgi.*current=\|7C\|"
# WEB-PHP gallery remote file include attempt
SecRule REQUEST_URI "/setup/" chain
SecRule REQUEST_URI "GALLERY_BASEDIR=(http|https|ftp)\:/"
#Needinit remote file include attempt
SecRule REQUEST_URI "/needinit\.php\?" chain
SecRule REQUEST_URI "GALLERY_BASEDIR=(http|https|ftp)\:/"
# WEB-PHP IdeaBox cord.php file include
SecRule REQUEST_URI "/index\.php" chain
SecRule REQUEST_URI "cord\.php"
# WEB-PHP Invision Board ipchat.php file include
SecRule REQUEST_URI "/ipchat\.php" chain
SecRule REQUEST_URI "conf_global\.php"
# WEB-PHP myphpPagetool pt_config.inc file include
SecRule REQUEST_URI "/doc/admin" chain
SecRule REQUEST_URI "pt_config\.inc"
# WEB-PHP YaBB SE packages.php file include
SecRule REQUEST_URI "/packages\.php" chain
SecRule REQUEST_URI "packer\.php"
# WEB-PHP PhpGedView PGV authentication_index.php base directory manipulation attempt
SecRule REQUEST_URI "/authentication_index\.php" chain
SecRule REQUEST_URI "PGV_BASE_DIRECTORY"
# WEB-PHP PhpGedView PGV functions.php base directory manipulation attempt
SecRule REQUEST_URI "/functions\.php" chain
SecRule REQUEST_URI "PGV_BASE_DIRECTORY"
# WEB-PHP PhpGedView PGV config_gedcom.php base directory manipulation attempt
SecRule REQUEST_URI "/config_gedcom\.php" chain
SecRule REQUEST_URI "PGV_BASE_DIRECTORY"
# WEB-PHP PhpGedView PGV base directory manipulation
SecRule REQUEST_URI "_conf\.php" chain
SecRule REQUEST_URI "PGV_BASE_DIRECTORY"
# WEB-PHP WAnewsletter newsletter.php file include attempt
SecRule REQUEST_URI "newsletter\.php" chain
SecRule REQUEST_URI "start\.php"
# WEB-PHP Opt-X header.php remote file include attempt
SecRule REQUEST_URI "/header\.php" chain
SecRule REQUEST_URI "systempath="
#webdav searcg attack
SecRule REQUEST_URI "/_vti_bin/_vti_aut/fp30reg\.dll"
#/auth.php?path=http://[attacker]/
SecRule REQUEST_URI "/auth.php\?path=(http|https|ftp)\:/"
SecRule REQUEST_URI "/dforum/nav\.php3\?page=<[[:space:]]*(script|about|applet|activex|chrome)+.*(script|about|applet|activex|chrome)[[:space:]]*>"
#phpMyAdmin path vln
SecRule REQUEST_URI "/phpMyAdmin/css/phpmyadmin\.css\.php\?GLOBALS\[cfg\]\[ThemePath\]=(/|.*\.\./)"
#PHPBB full path disclosure
SecRule REQUEST_URI "phpBB/db/oracle\.php"
SecRule REQUEST_URI "forum/db/oracle\.php"
SecRule REQUEST_URI "forums/db/oracle\.php"
#PHP Form Mail Script File Incusion vuln
SecRule REQUEST_URI "/inc/formmail\.inc\.php\?script_root=(http|https|ftp)\:/"
#Download Center Lite File Incusion vuln
SecRule REQUEST_URI "/inc/download_center_lite\.inc\.php\?script_root=(http|https|ftp)\:/"
#/modules/mod_mainmenu.php?mosConfig_absolute_path=http://
SecRule REQUEST_URI "/modules/mod_mainmenu\.php\?mosConfig_absolute_path=(http|https|ftp)\:/"
#phpWebLog command execution
SecRule REQUEST_URI "/init\.inc\.php\?G_PATH=(http|https|ftp)\:/"
SecRule REQUEST_URI "/backend/addons/links/index\.php\?PATH=(http|https|ftp)\:/"
#mcNews command execution
SecRule REQUEST_URI "/mcNews/admin/header\.php\?skinfile=(http|https|ftp)\:/"
#phpbb
SecRule REQUEST_URI "admin/admin_styles\.php\?mode=addnew\&install_to=\.\./\.\./"
#votebox
SecRule REQUEST_URI "/votebox\.php\?VoteBoxPath=(http|https|ftp)\:/"
#phpAdsNew path disclosure
SecRule REQUEST_URI "/libraries/lib-xmlrpcs.inc\.php"
SecRule REQUEST_URI "/maintenance/maintenance-activation\.php"
SecRule REQUEST_URI "/maintenance/maintenance-cleantables\.php"
SecRule REQUEST_URI "/maintenance/maintenance-autotargeting\.php"
SecRule REQUEST_URI "/maintenance/maintenance-reports\.php"
SecRule REQUEST_URI "/misc/backwards\x20compatibility/phpads\.php"
SecRule REQUEST_URI "/misc/backwards\x20compatibility/remotehtmlview\.php"
SecRule REQUEST_URI "/misc/backwards\x20compatibility/click\.php"
SecRule REQUEST_URI "/adframe\.php\?refresh=securityreason\.com\'\>"
#include cgi command exec
SecRule REQUEST_URI "/includer\.cgi\?=\|"
#citrusDB
#adjust these to your system, you might need to upload
SecRule REQUEST_URI "tools/index\.php\?load=\.\./\.\./"
SecRule REQUEST_URI "citrusdb/tools/index\.php\?load=importcc\&submit=on"
SecRule REQUEST_URI "/citrusdb/tools/uploadcc\.php"
#awstats vulns
SecRule REQUEST_URI "/awstats\.pl\?(configdir|update|pluginmode|cgi)=(\||echo|\:system\()"
SecRule REQUEST_URI "/awstats\.pl\?(debug=1|pluginmode=rawlog\&loadplugin=rawlog|update=1\&logfile=\|)"
SecRule REQUEST_URI "/awstats\.pl\?[^\r\n]*logfile=\|"
SecRule REQUEST_URI "/awstats\.pl\?configdir="
SecRule REQUEST_URI "awstats\.pl\?" chain
SecRule ARGS "(debug|configdir|perl|chmod|exec|print|cgi)"
#yabb
SecRule REQUEST_URI "/YaBB\.pl\?action=usersrecentposts\;username=\|(http|https|ftp)\:/)"
SecRule REQUEST_URI|REQUEST_BODY "/privmsg\.php" chain
SecRule REQUEST_URI|REQUEST_BODY "\|(http|https|ftp)\:/)"
# Remote File Inclusion Vulnerability in phpWebLog
SecRule REQUEST_URI "/include/init\.inc\.php\?G_PATH=(http|https|ftp)\:/"
SecRule REQUEST_URI "addons/links/index\.php\?PATH=(http|https|ftp)\:/"
#Multiple Vulnerabilities in ProjectBB
SecRule REQUEST_URI "/divers\.php\?action=liste\&liste=\&desc=\&pages=(\<(javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
SecRule REQUEST_URI "/divers\.php\?action=liste\&liste=(\<(javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
SecRule REQUEST_URI "/Zip/divers\.php\?action =liste&liste=email&desc=.*\'"
#WebChat english.php or db_mysql.php file include
SecRule REQUEST_URI "/defines\.php*WEBCHATPATH*(db_mysql\.php|english\.php)"
#Cross-Site Scripting Vulnerability in D-Forum
SecRule REQUEST_URI "/nav\.php3\?page=(\<(javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
#Multiple Vulnerabilities in auraCMS
SecRule REQUEST_URI "/index\.php\?query=(\<(javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/).*\&pilih=search"
SecRule REQUEST_URI "/hits\.php\?hits=(\<(javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
SecRule REQUEST_URI "/counter\.php\?theCount=(\<(javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
#vBulletin Remote Command Execution Attempt
SecRule REQUEST_URI "/forumdisplay\.php?[^\r\n]*comma=[^\r\n\x26]*system\x28.*\x29/Ui"
SecRule REQUEST_URI "/forumdisplay\.php\?" chain
SecRule REQUEST_URI|REQUEST_BODY "\.system\(.+\)\."
SecRule REQUEST_URI "/forumdisplay\.php\?*comma="
#PHPNuke general XSS attempt
#/modules.php?name=News&file=article&sid=1&optionbox=
SecRule REQUEST_URI "/modules\.php\?*name=*\<*(script|about|applet|activex|chrome)*\>"
SecRule REQUEST_URI "/modules\.php\?op=modload&name=News&file=article&sid=*\<*(script|about|applet|activex|chrome)*\>"
# PHPNuke SQL injection attempt
SecRule REQUEST_URI "/modules\.php\?*name=Search*instory="
SecRule REQUEST_URI "/modules\.php\?*name=(Search|Web_Links).*\'"
#EasyDynamicPages exploit
SecRule REQUEST_URI|REQUEST_BODY "edp_relative_path="
#Readfile.tcl Access
SecRule REQUEST_URI "/readfile\.tcl\?file="
#phpnuke sql insertion
SecRule REQUEST_URI "/modules\.php*name=Forums.*file=viewtopic*/forum=.*\'/"
#WAnewsletter newsletter.php file include attempt
SecRule REQUEST_URI "newsletter\.php*waroot*start\.php"
# Typo3 translations.php file include
SecRule REQUEST_URI "/translations\.php*ONLY"
#PHP-Nuke remote file include attempt
SecRule REQUEST_URI "/index\.php*file=*(http|https|ftp)\:/"
#PayPal Storefront remote file include attempt
SecRule REQUEST_URI "do=ext*/page=(http|https|ftp)\:/"
#PHPOpenChat
SecRule REQUEST_URI "/poc_loginform\.php\?phpbb_root_path=(http|https|ftp)\:/"
SecRule REQUEST_URI "/poc\.php\?phpbb_root_path=(http|https|ftp)\:/"
SecRule REQUEST_URI "/poc\.php\?poc_root_path=(http|https|ftp)\:/"
SecRule REQUEST_URI "/ENGLISH_poc\.php\?poc_root_path=(http|https|ftp)\:/"
SecRule REQUEST_URI "/poc\.php\?sourcedir=(http|https|ftp)\:/"
#ACS Blog Search.ASP Cross-Site Scripting Vulnerability
SecRule REQUEST_URI "/search\.asp\?search=.*iframe\+src.*((javascript|script|about|applet|activex|chrome)*\>|http|https|ftp)\:/"
#mcNews Remote command execution
SecRule REQUEST_URI "/admin/install\.php\?l=(http|https|ftp)\:/"
#mailman XSS
SecRule REQUEST_URI|REQUEST_BODY "/mailman/.*\?.*info=*<[[:space:]]*(script|about|applet|activex|chrome)*>.*(script|about|applet|activex|chrome)[[:space:]]*>"
#Macromedia SiteSpring XSS
SecRule REQUEST_URI|REQUEST_BODY "/error/500error\.jsp.*et=*<[[:space:]]*(script|about|applet|activex|chrome)*>.*(script|about|applet|activex|chrome)[[:space:]]*>"
#OWA phishing redirect
SecRule REQUEST_URI "/exchweb/bin/auth/owalogon\.asp\?url=(http|https)\:/"
#ads.cgi command execution attempt
SecRule REQUEST_URI "/ads\.cgi.*file=.*\.\./\.\./"
#webdist.cgi arbitrary command attemp
SecRule REQUEST_URI "/webdist\.cgi.*distloc=(\|3B\||\x3B)"
#enter_bug.cgi arbitrary command attempt
SecRule REQUEST_URI "/enter_bug\.cgi.*who.*(\|3B\||\x3B)"
#cross site scripting HTML Image tag set to javascript attempt
SecRule REQUEST_URI|REQUEST_BODY "img src=javascript"
#b2 arbitrary command execution attempt
SecRule REQUEST_URI "/b2-include/.*b2inc.*http(\|3A\|//|\x3A)"
#tomcat servlet mapping XSS
SecRule REQUEST_URI|REQUEST_BODY "/servlet/.*/org\.apache\."
#RUNCMS,Exoops,CIAMOS highlight file access hole
SecRule REQUEST_URI "/class/debug/highlight\.php\?file=(/|\.\./)"
#TRG/CzarNews News Script Include File Hole Lets Remote Users Execute Arbitrary Commands
SecRule REQUEST_URI "/install/(article|authorall|comment|display|displayall.)\.php\?dir=(http|https|ftp):/"
#zpanel XSS
SecRule REQUEST_URI "/zpanel\.php\?page=.*((javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
#zpanel SQL injection
SecRule REQUEST_URI "/zpanel\.php\?page=.*\'"
#Phorum HTTP Response Splitting Vulnerability
SecRule REQUEST_URI "/search\.php\?forum_id=.*\&search=.*\&body=.*Content-Length\:.*HTTP/1\.0.*Content-Type\:.*Content-Length\:"
#Subdreamer Light Global Variables SQL Injection Vulnerability
SecRule REQUEST_URI "/index\.php\?categoryid=.*\&.*_sectionid=.*\&.*_imageid=.*\'"
#PhotoPost Pro
SecRule REQUEST_URI "/showgallery\.php\?cat=[0-9].*\&page=(http|https|ftp)\:/"
SecRule REQUEST_URI "/showgallery\.php\?si=(http|https|ftp)\:/"
SecRule REQUEST_URI "/showgallery\.php\?ppuser=[0-9].*\&cat=(http|https|ftp)\:/"
SecRule REQUEST_URI "/showgallery\.php\?cat=[0-9].*\'"
SecRule REQUEST_URI "/showgallery\.php\?ppuser=[0-9].*\'.*\&cat="
#betaparticle blog Discloses Database to Remote Users
#and Lets Remote Users Upload/Delete Arbitrary Files
SecRule REQUEST_URI "/bp/database/dbBlogMX\.mdb"
SecRule REQUEST_URI "/Blog\.mdb"
#Kayako eSupport Remote Cross Site Scripting Vulnerability
SecRule REQUEST_URI "/eSupport/index.php\?_a=knowledgebase\&_j=questiondetails\&_i=[0-9].*((javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
SecRule REQUEST_URI "/eSupport/index.php\?_a=knowledgebase\&_j=questionprint\&_i=[0-9].*((javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
SecRule REQUEST_URI "/eSupport/index.php\?_a=troubleshooter\&_c=[0-9].*((javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
SecRule REQUEST_URI "/eSupport/index.php\?_a=knowledgebase\&_j=subcat\&_i=[0-9].*((javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
#phpSysInfo XSS vulns
SecRule REQUEST_URI "/index\.php\?sensor_program=.*((javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
SecRule REQUEST_URI "/includes/system_footer\.php\?text[template]=\"\>.*((javascript|script|about|applet|activex|chrome)*\>|(http|https|ftp)\:/)"
SecRule REQUEST_URI "/includes/system_footer\.php\?hide_picklist=.*\&VERSION=\|(http|https|ftp)\:/)"
#DigitalHive Remote Unathenticated Software Re-install and Cross-Site Scripting Vulnerabilities
SecRule REQUEST_URI "/base\.php\?page=forum/msg\.php-afs-1-\"/\>\