/etc/apache2/conf.d/modsec_vendor_configs/imunify360-full-apache
# ------------------------------------------------------ # Imunify360 ModSecurity Rules # Copyright (C) 2026 CloudLinux Inc All right reserved # The Imunify360 ModSecurity Rules is distributed under # IMUNIFY360 LICENSE AGREEMENT # ------------------------------------------------------ # Imunify360 ModSecurity Base Ruleset SecRule FILES_TMPNAMES "!@rx ^$" "id:33362,chain,pass,nolog,severity:5,t:none" SecRuleScript detectlua.lua "t:none,chain" SecRule FILES_TMPNAMES "!@rx ^$" "t:none" SecRule &TX:lua_present "@eq 0" "id:77350119,chain,phase:2,pass,nolog,severity:5,setvar:TX.py_scan_start=%{DURATION},tag:'service_im360',tag:'noshow'" SecRule FILES_TMPNAMES "!@rx ^$" "t:none" SecRule &TX:lua_present "@eq 0" "id:33363,nolog,auditLog,block,chain,severity:2,phase:2,t:none,msg:'IM360 WAF: Attempt to upload malware||Action:%{ARGS.action}||Scan duration:%{TX.py_scan_duration}||Sizes:%{FILES_SIZES}||Combined size:%{FILES_COMBINED_SIZE}||User:%{SCRIPT_USERNAME}||Filename:%{FILES}||Scanned:%{FILES_TMPNAMES}||SC:%{SCRIPT_FILENAME}||WPU:%{TX.wp_user}||RSV:8.02||T:APACHE||',tag:'service_im360'" SecRule FILES_TMPNAMES "@inspectFile /opt/alt/python35/share/imunify360/scripts/modsec_scan.py" "t:none,setvar:TX.py_scan_duration=%{DURATION},setvar:TX.py_scan_duration=-%{TX.py_scan_start}" SecRule &TX:lua_present "@eq 0" "id:77350120,chain,phase:2,pass,nolog,severity:5,setvar:TX.py_scan_time=%{DURATION},setvar:TX.py_scan_time=-%{TX.py_scan_start},tag:'service_im360',tag:'noshow'" SecRule FILES_TMPNAMES "!@rx ^$" "t:none" SecRule &TX:lua_present "@eq 1" "id:77350121,chain,phase:2,pass,nolog,severity:5,setvar:TX.lua_scan_start=%{DURATION},tag:'service_im360',tag:'noshow'" SecRule FILES_TMPNAMES "!@rx ^$" "t:none" SecRule &TX:lua_present "@eq 1" "id:33331,nolog,auditlog,block,chain,severity:2,phase:2,t:none,msg:'IM360 WAF: Attempt to upload malware||Action:%{ARGS.action}||Scan duration:%{TX.lua_scan_duration}||Sizes:%{FILES_SIZES}||Combined size:%{FILES_COMBINED_SIZE}||User:%{SCRIPT_USERNAME}||WPU:%{TX.wp_user}||Filename:%{FILES}||Scanned:%{FILES_TMPNAMES}||SC:%{SCRIPT_FILENAME}||RSV:8.02||T:APACHE||',tag:'service_im360'" SecRule FILES_TMPNAMES "@inspectFile inspectfile.lua" "t:none,setvar:TX.lua_scan_duration=%{DURATION},setvar:TX.lua_scan_duration=-%{TX.lua_scan_start}" SecRule &TX:lua_present "@eq 1" "id:77350122,chain,phase:2,pass,nolog,severity:5,setvar:TX.lua_scan_time=%{DURATION},setvar:TX.lua_scan_time=-%{TX.lua_scan_start},tag:'service_im360',tag:'noshow'" SecRule FILES_TMPNAMES "!@rx ^$" "t:none" SecRule FILES "!@rx ^$" "id:77317957,phase:5,pass,nolog,auditlog,severity:5,t:none,ctl:auditLogParts=ABFHZ,msg:'IM360 WAF: File upload||File:%{MATCHED_VAR}||Size:%{FILES_SIZES}||Combined:%{FILES_COMBINED_SIZE}||User:%{SCRIPT_USERNAME}||SC:%{SCRIPT_FILENAME}||WPU:%{TX.wp_user}||Py time:%{TX.py_scan_time}||Lua time:%{TX.lua_scan_time}||RSV:8.02||T:APACHE||',tag:'service_im360',tag:'noshow'"
.
Edit
..
Edit
000_i360_init.conf
Edit
001_i360_pass.conf
Edit
002_i360_basic.conf
Edit
003_i360_wp_logic.conf
Edit
004_i360_vectors.conf
Edit
005_i360_bruteforce.conf
Edit
006_i360_malware.conf
Edit
007_i360_custom.conf
Edit
008_i360_wordpress.conf
Edit
009_i360_joomla.conf
Edit
010_i360_drupal.conf
Edit
011_i360_otherapps.conf
Edit
012_i360_spam.conf
Edit
013_i360_generic.conf
Edit
014_i360_infectors.conf
Edit
015_i360_filescan.conf
Edit
016_i360_monitor.conf
Edit
017_i360_weak_pass.conf
Edit
018_Disable_WP_Redirect.conf
Edit
IM360-LICENSE.txt
Edit
RELEASE
Edit
VERSION
Edit
bl_agents
Edit
bl_chains
Edit
bl_db_list
Edit
bl_db_list_ext
Edit
bl_ips
Edit
bl_os_files
Edit
bl_path_files
Edit
bl_scanners
Edit
bl_uri
Edit
bl_web_files
Edit
bl_wpboost_uri
Edit
bl_xss_input
Edit
changelog.json
Edit
changelog.txt
Edit
cloudav_list
Edit
crawlers-google-iplist.data
Edit
crawlers-iplist.data
Edit
crawlers-ualist.data
Edit
danme_top100
Edit
detectlua.lua
Edit
inspectfile.lua
Edit
ip-record.db
Edit
java_data
Edit
malware_found.list
Edit
malware_found_b64.list
Edit
malware_standalone.list
Edit
malware_standalone_b64.list
Edit
path_traversal
Edit
php_data
Edit
rbl_whitelist
Edit
rce_uri
Edit
risky-actions.list
Edit
trap.lua
Edit
trap_cookie.lua
Edit
userdata_dirb_URLs.data
Edit