X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=etc%2Frules%2Fweb_rules.xml;fp=etc%2Frules%2Fweb_rules.xml;h=6d40e604dffd3c2f63aff13db73fee51b1f7b5b2;hp=bba91f4a11912e156aaff879b479a2cbaaa31d8b;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b diff --git a/etc/rules/web_rules.xml b/etc/rules/web_rules.xml old mode 100755 new mode 100644 index bba91f4..6d40e60 --- a/etc/rules/web_rules.xml +++ b/etc/rules/web_rules.xml @@ -13,8 +13,8 @@ - - License details: http://www.ossec.net/en/licensing.html --> - - + + web-log @@ -40,18 +40,18 @@ is_simple_http_request Ignored extensions on 400 error codes. - + - 31100 + 31100,31108 =select%20|select+|insert%20|%20from%20|%20where%20|union%20| union+|where+|null,null|xp_cmdshell SQL injection attempt. attack,sql_injection, - + 31100 - + %027|%00|%01|%7f|%2E%2E|%0A|%0D|../..|..\..|echo;| @@ -69,7 +69,7 @@ XSS (Cross Site Scripting) attempt. attack, - + 31103, 31104, 31105 ^200 @@ -132,7 +132,7 @@ Web server 500 error code (Internal Error). system_error, - + 31120 ^503 @@ -155,7 +155,7 @@ Ignored 499's on nginx. - + 31101 @@ -168,14 +168,14 @@ 31103 Multiple SQL injection attempts from same - souce ip. + source ip. attack,sql_injection, - + 31104 - Multiple common web attacks from same souce ip. + Multiple common web attacks from same source ip. attack, @@ -183,24 +183,24 @@ 31105 Multiple XSS (Cross Site Scripting) attempts - from same souce ip. + from same source ip. attack, - + 31121 Multiple web server 501 error code (Not Implemented). web_scan,recon, - + 31122 Multiple web server 500 error code (Internal Error). system_error, - + 31123