This commit is contained in:
vasco
2026-06-02 22:49:55 +01:00
parent 1f6bb854c3
commit 361f34c19f

View File

@@ -9,11 +9,11 @@ SecAuditLog /var/log/modsecurity/audit.log
# sql injection # sql injection
SecRule REQUEST_URI|ARGS "['\";]|--" \ SecRule REQUEST_URI|ARGS "['\";]|--" \
"id:950001,phase:2,deny,status:403,msg:'SQL Injection Attack Detected',log" "id:950001,phase:1,deny,status:403,msg:'SQL Injection Attack Detected',log"
# xss / html injection # xss / html injection
SecRule REQUEST_URI|ARGS "<.*>" \ SecRule REQUEST_URI ARGS "<.*>" \
"id:950003,phase:2,deny,status:403,msg:'XSS/HTML Injection Detected',log" "id:950003,phase:1,deny,status:403,msg:'XSS/HTML Injection Detected',log"
# command injection # command injection
SecRule ARGS "(\"role\".*:.*\"admin\")|exec|cat|more|ls|dir|/etc/passwd" \ SecRule ARGS "(\"role\".*:.*\"admin\")|exec|cat|more|ls|dir|/etc/passwd" \