1 <!-- @(#) $Id: ./etc/rules/web_rules.xml, 2013/02/28 dcid Exp $
4 - Official Web access rules for OSSEC.
6 - Copyright (C) 2009 Trend Micro Inc.
9 - This program is a free software; you can redistribute it
10 - and/or modify it under the terms of the GNU General Public
11 - License (version 2) as published by the FSF - Free Software
14 - License details: http://www.ossec.net/en/licensing.html
18 <group name="web,accesslog,">
19 <rule id="31100" level="0">
20 <category>web-log</category>
21 <description>Access log messages grouped.</description>
24 <rule id="31108" level="0">
25 <if_sid>31100</if_sid>
27 <compiled_rule>is_simple_http_request</compiled_rule>
28 <description>Ignored URLs (simple queries).</description>
31 <rule id="31101" level="5">
32 <if_sid>31100</if_sid>
34 <description>Web server 400 error code.</description>
37 <rule id="31102" level="0">
38 <if_sid>31101</if_sid>
39 <url>.jpg$|.gif$|favicon.ico$|.png$|robots.txt$|.css$|.js$|.jpeg$</url>
40 <compiled_rule>is_simple_http_request</compiled_rule>
41 <description>Ignored extensions on 400 error codes.</description>
44 <rule id="31103" level="6">
45 <if_sid>31100,31108</if_sid>
46 <url>=select%20|select+|insert%20|%20from%20|%20where%20|union%20|</url>
47 <url>union+|where+|null,null|xp_cmdshell</url>
48 <description>SQL injection attempt.</description>
49 <group>attack,sql_injection,</group>
52 <rule id="31104" level="6">
53 <if_sid>31100</if_sid>
55 <!-- Attempt to do directory transversal, simple sql injections,
56 - or access to the etc or bin directory (unix). -->
57 <url>%027|%00|%01|%7f|%2E%2E|%0A|%0D|../..|..\..|echo;|</url>
58 <url>cmd.exe|root.exe|_mem_bin|msadc|/winnt/|/boot.ini|</url>
59 <url>/x90/|default.ida|/sumthin|nsiislog.dll|chmod%|wget%|cd%20|</url>
60 <url>exec%20|../..//|%5C../%5C|././././|2e%2e%5c%2e|\x5C\x5C</url>
61 <description>Common web attack.</description>
62 <group>attack,</group>
65 <rule id="31105" level="6">
66 <if_sid>31100</if_sid>
67 <url>%3Cscript|%3C%2Fscript|script>|script%3E|SRC=javascript|IMG%20|</url>
68 <url>%20ONLOAD=|INPUT%20|iframe%20</url>
69 <description>XSS (Cross Site Scripting) attempt.</description>
70 <group>attack,</group>
73 <rule id="31106" level="6">
74 <if_sid>31103, 31104, 31105</if_sid>
76 <description>A web attack returned code 200 (success).</description>
77 <group>attack,</group>
80 <rule id="31110" level="6">
81 <if_sid>31100</if_sid>
82 <url>?-d|?-s|?-a|?-b|?-w</url>
83 <description>PHP CGI-bin vulnerability attempt.</description>
84 <group>attack,</group>
87 <rule id="31109" level="6">
88 <if_sid>31100</if_sid>
89 <url>+as+varchar</url>
90 <regex>%2Bchar\(\d+\)%2Bchar\(\d+\)%2Bchar\(\d+\)%2Bchar\(\d+\)%2Bchar\(\d+\)%2Bchar\(\d+\)</regex>
91 <description>MSSQL Injection attempt (/ur.php, urchin.js)</description>
92 <group>attack,</group>
96 <!-- If your site have a search engine, you may need to ignore
99 <rule id="31107" level="0">
100 <if_sid>31103, 31104, 31105</if_sid>
101 <url>^/search.php?search=|^/index.php?searchword=</url>
102 <description>Ignored URLs for the web attacks</description>
105 <rule id="31115" level="13" maxsize="7900">
106 <if_sid>31100</if_sid>
107 <description>URL too long. Higher than allowed on most </description>
108 <description>browsers. Possible attack.</description>
109 <group>invalid_access,</group>
113 <!-- 500 error codes, server error
114 - http://www.w3.org/Protocols/rfc2616/rfc2616-sec10.html
116 <rule id="31120" level="5">
117 <if_sid>31100</if_sid>
119 <description>Web server 500 error code (server error).</description>
122 <rule id="31121" level="4">
123 <if_sid>31120</if_sid>
125 <description>Web server 501 error code (Not Implemented).</description>
128 <rule id="31122" level="5">
129 <if_sid>31120</if_sid>
131 <options>alert_by_email</options>
132 <description>Web server 500 error code (Internal Error).</description>
133 <group>system_error,</group>
136 <rule id="31123" level="4">
137 <if_sid>31120</if_sid>
139 <options>alert_by_email</options>
140 <description>Web server 503 error code (Service unavailable).</description>
144 <!-- Rules to ignore crawlers -->
145 <rule id="31140" level="0">
146 <if_sid>31101</if_sid>
147 <compiled_rule>is_valid_crawler</compiled_rule>
148 <description>Ignoring google/msn/yahoo bots.</description>
151 <!-- Ignoring nginx 499's -->
152 <rule id="31141" level="0">
153 <if_sid>31101</if_sid>
155 <description>Ignored 499's on nginx.</description>
159 <rule id="31151" level="10" frequency="12" timeframe="90">
160 <if_matched_sid>31101</if_matched_sid>
162 <description>Multiple web server 400 error codes </description>
163 <description>from same source ip.</description>
164 <group>web_scan,recon,</group>
167 <rule id="31152" level="10" frequency="6" timeframe="120">
168 <if_matched_sid>31103</if_matched_sid>
170 <description>Multiple SQL injection attempts from same </description>
171 <description>source ip.</description>
172 <group>attack,sql_injection,</group>
175 <rule id="31153" level="10" frequency="8" timeframe="120">
176 <if_matched_sid>31104</if_matched_sid>
178 <description>Multiple common web attacks from same source ip.</description>
179 <group>attack,</group>
182 <rule id="31154" level="10" frequency="8" timeframe="120">
183 <if_matched_sid>31105</if_matched_sid>
185 <description>Multiple XSS (Cross Site Scripting) attempts </description>
186 <description>from same source ip.</description>
187 <group>attack,</group>
190 <rule id="31161" level="10" frequency="12" timeframe="120">
191 <if_matched_sid>31121</if_matched_sid>
193 <description>Multiple web server 501 error code (Not Implemented).</description>
194 <group>web_scan,recon,</group>
197 <rule id="31162" level="10" frequency="12" timeframe="120">
198 <if_matched_sid>31122</if_matched_sid>
200 <description>Multiple web server 500 error code (Internal Error).</description>
201 <group>system_error,</group>
204 <rule id="31163" level="10" frequency="12" timeframe="120">
205 <if_matched_sid>31123</if_matched_sid>
207 <description>Multiple web server 503 error code (Service unavailable).</description>
208 <group>web_scan,recon,</group>
211 <rule id="31164" level="6">
212 <if_sid>31100</if_sid>
213 <url>=%27|select%2B|insert%2B|%2Bfrom%2B|%2Bwhere%2B|%2Bunion%2B</url>
214 <description>SQL injection attempt.</description>
215 <group>attack,sqlinjection,</group>
218 <rule id="31165" level="6">
219 <if_sid>31100</if_sid>
220 <url>%EF%BC%87|%EF%BC%87|%EF%BC%87|%2531|%u0053%u0045</url>
221 <description>SQL injection attempt.</description>
222 <group>attack,sqlinjection,</group>
225 </group> <!-- Web access log -->