/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules
# Apache # (no slash; also guards against old.htaccess, old.htpasswd, etc.) .htaccess .htdigest .htpasswd # home level dotfiles (keep in sync with lfi-os-files.data) .aptitude/config .bash_config .bash_history .bash_logout .bash_profile .bashrc .cache/notify-osd.log .config/odesk/odesk team.conf .cshrc .drush/ .gitconfig .gnupg/ .hplip/hplip.conf .ksh_history .lesshst .lftp/ .lhistory .lldb-history .local/share/mc/ .my.cnf .mysql_history .nano_history .node_repl_history .nsr .pearrc .php_history .pki/ .profile .psql_history .python_history .rediscli_history .Rhistory .sh_history .sqlite_history .ssh/authorized_keys .ssh/config .ssh/id_dsa .ssh/id_dsa.pub .ssh/id_rsa .ssh/id_rsa.pub .ssh/identity .ssh/identity.pub .ssh/known_hosts .subversion/auth .subversion/config .subversion/servers .tconn/tconn.conf .tcshrc .vidalia/vidalia.conf .viminfo .vimrc .xauthority .zhistory .zshrc .zsh_history .nsconfig # Version control /.git/ /.gitignore /.hg/ /.hgignore /.svn/ # Wordpress wp-config.php wp-config.bak wp-config.old wp-config.temp wp-config.tmp wp-config.txt # Symfony /config/config.yml /config/config_dev.yml /config/config_prod.yml /config/config_test.yml /config/parameters.yml /config/routing.yml /config/security.yml /config/services.yml # Drupal /sites/default/default.settings.php /sites/default/settings.php /sites/default/settings.local.php # Magento /app/etc/local.xml # Sublime Text /sftp-config.json # ASP.NET /Web.config # Node /package.json /package-lock.json /gruntfile.js /npm-debug.log /ormconfig.json /tsconfig.json /webpack.config.js /yarn.lock # Composer /composer.json /composer.lock /packages.json # dotenv /.env # OSX /.DS_Store # WS FTP /.ws_ftp.ini # common, old network config file .netrc # New Top Level dotfiles .thunderbird/ .vmware/ .kube/ .java/ .anydesk/ .docker/ .npm/ .nvm/ .minikube/ .atom/ .aws/config .aws/credentials .cups/ .dbus/ .boto .gem/ .gnonme/ .gsutil/ # New Per-Project Files .idea nbproject/ bower.json .bowerrc .eslintrc .jshintrc .gitlab-ci.yml .travis.yml database.yml Dockerfile
.
Edit
..
Edit
REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example
Edit
REQUEST-901-INITIALIZATION.conf
Edit
REQUEST-903.9001-DRUPAL-EXCLUSION-RULES.conf
Edit
REQUEST-903.9002-WORDPRESS-EXCLUSION-RULES.conf
Edit
REQUEST-903.9003-NEXTCLOUD-EXCLUSION-RULES.conf
Edit
REQUEST-903.9004-DOKUWIKI-EXCLUSION-RULES.conf
Edit
REQUEST-903.9005-CPANEL-EXCLUSION-RULES.conf
Edit
REQUEST-903.9006-XENFORO-EXCLUSION-RULES.conf
Edit
REQUEST-905-COMMON-EXCEPTIONS.conf
Edit
REQUEST-910-IP-REPUTATION.conf
Edit
REQUEST-911-METHOD-ENFORCEMENT.conf
Edit
REQUEST-912-DOS-PROTECTION.conf
Edit
REQUEST-913-SCANNER-DETECTION.conf
Edit
REQUEST-920-PROTOCOL-ENFORCEMENT.conf
Edit
REQUEST-921-PROTOCOL-ATTACK.conf
Edit
REQUEST-922-MULTIPART-ATTACK.conf
Edit
REQUEST-930-APPLICATION-ATTACK-LFI.conf
Edit
REQUEST-931-APPLICATION-ATTACK-RFI.conf
Edit
REQUEST-932-APPLICATION-ATTACK-RCE.conf
Edit
REQUEST-933-APPLICATION-ATTACK-PHP.conf
Edit
REQUEST-934-APPLICATION-ATTACK-NODEJS.conf
Edit
REQUEST-941-APPLICATION-ATTACK-XSS.conf
Edit
REQUEST-942-APPLICATION-ATTACK-SQLI.conf
Edit
REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
Edit
REQUEST-944-APPLICATION-ATTACK-JAVA.conf
Edit
REQUEST-949-BLOCKING-EVALUATION.conf
Edit
RESPONSE-950-DATA-LEAKAGES.conf
Edit
RESPONSE-951-DATA-LEAKAGES-SQL.conf
Edit
RESPONSE-952-DATA-LEAKAGES-JAVA.conf
Edit
RESPONSE-953-DATA-LEAKAGES-PHP.conf
Edit
RESPONSE-954-DATA-LEAKAGES-IIS.conf
Edit
RESPONSE-959-BLOCKING-EVALUATION.conf
Edit
RESPONSE-980-CORRELATION.conf
Edit
RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example
Edit
crawlers-user-agents.data
Edit
iis-errors.data
Edit
java-classes.data
Edit
java-code-leakages.data
Edit
java-errors.data
Edit
lfi-os-files.data
Edit
php-config-directives.data
Edit
php-errors.data
Edit
php-function-names-933150.data
Edit
php-function-names-933151.data
Edit
php-variables.data
Edit
restricted-files.data
Edit
restricted-upload.data
Edit
scanners-headers.data
Edit
scanners-urls.data
Edit
scanners-user-agents.data
Edit
scripting-user-agents.data
Edit
sql-errors.data
Edit
unix-shell.data
Edit
windows-powershell-commands.data
Edit