X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=etc%2Frules%2Fweb_appsec_rules.xml;h=6448db266620cba3c4204c49cc4be460bddab53e;hp=3f405c0136f05683053ffa9adddc555573bf183c;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b diff --git a/etc/rules/web_appsec_rules.xml b/etc/rules/web_appsec_rules.xml old mode 100755 new mode 100644 index 3f405c0..6448db2 --- a/etc/rules/web_appsec_rules.xml +++ b/etc/rules/web_appsec_rules.xml @@ -13,17 +13,17 @@ - - License details: http://www.ossec.net/en/licensing.html --> - + + - on sites that are not updated. + --> - 31100 @@ -88,7 +88,7 @@ 31100 - "ZmEu"| "libwww-perl/|"the beast"|"Morfeus|"ZmEu|"Nikto|"w3af.sourceforge.net|MJ12bot/v + "ZmEu"| "libwww-perl/|"the beast"|"Morfeus|"ZmEu|"Nikto|"w3af.sourceforge.net|MJ12bot/v| Jorgee"|"Proxy Gear Pro|"DataCha0s Blacklisted user agent (known malicious user agent). @@ -110,7 +110,7 @@ - + 31100 " "Wget/ Blacklisted user agent (wget). @@ -151,11 +151,11 @@ PHPMyAdmin scans (looking for setup.php). - 31100 - .swp$|.bak$|/.htaccess|/server-status|/.ssh|/.history + .swp$|.bak$|/.htaccess|/server-status|/.ssh|/.history|/wallet.dat Suspicious URL access.