PATH:
opt
/
bitninja-waf3
/
coreruleset
/
rules
# This list can be generated from restricted-files.data by running the following shell command: # body_start=$(grep -n -E -m 1 '^[^#$]' rules/restricted-upload.data | cut -d: -f1) # ed -s rules/restricted-upload.data <<EOF # $((body_start - 1)),\$d # w # q # EOF # words="$(awk ' !/^#/ {split($0, segments, "/")} {word = segments[length(segments)]} length(word) > 3 {print word}' rules/restricted-files.data | \ # sort | uniq)" # while read -r word; do # if [ "$(util/fp-finder/spell.sh -m -e - <<<"${word}")" != "${word}" ]; then # echo "${word}" >> rules/restricted-upload.data # fi # done <<<"${words}" .DS_Store .addressbook .bash_ .bashrc .bowerrc .cshrc .docker .env .eslintignore .eslintrc .fbcindex .forward .gitattributes .gitconfig .gitignore .gitlab-ci.yml .google_authenticator .hgignore .htaccess .htdigest .htpasswd .idea .jshintrc .ksh_history .lesshst .lhistory .lighttpdpassword .lldb-history .lynx_cookies .my.cnf .mysql_history .nano_history .node_repl_history .nsconfig .nsr .oh-my- .password-store .pearrc .pgpass .php_cs.dist .php_history .phpcs.xml .phpcs.xml.dist .pinerc .proclog .procmailrc .profile .psql_history .python_history .rediscli_history .rhistory .rhosts .sh_history .sqlite_history .tcshrc .travis.yml .user.ini .viminfo .vimrc .ws_ftp.ini .www_acl .wwwacl .xauthority .zhistory .zsh_history .zshrc Desktop.ini Dockerfile Thumbs.db Web.config acpi asound auth.json bootconfig bower.json buddyinfo cgroups cmdline composer.json composer.lock config.gz config.php config.yml config_dev.yml config_prod.yml config_test.yml cpuinfo database.yml default.settings.php diskstats dynamic_debug execdomains filesystems gruntfile.js hplip.conf hypervisor iomem ioports ipmi kallsyms kcore key-users kmsg kpagecgroup kpagecount kpageflags latency_stats loadavg local.xml mdstat meminfo mtrr notify-osd.log npm-debug.log npm-shrinkwrap.json ormconfig.json package-lock.json package.json packages.json pagetypeinfo parameters.php parameters.yml php.ini php_error.log php_errors.log phpcs.xml phpcs.xml.dist routing.yml sched_debug schedstat security.yml services.yml settings.inc.php settings.local.php settings.php sftp-config.json slabinfo soapConfig.xml softirqs sslvpn_websession sysrq-trigger sysvipc thread-self timer_list timer_stats tsconfig.json version_signature vmallocinfo vmstat weblogic.xml webpack.config.js wp-config.bak wp-config.old wp-config.php wp-config.temp wp-config.tmp wp-config.txt yarn.lock zoneinfo
[-] REQUEST-932-APPLICATION-ATTACK-RCE.conf
[edit]
[-] REQUEST-943-APPLICATION-ATTACK-SESSION-FIXATION.conf
[edit]
[-] ssrf.data
[edit]
[-] REQUEST-931-APPLICATION-ATTACK-RFI.conf
[edit]
[+]
..
[-] REQUEST-941-APPLICATION-ATTACK-XSS.conf
[edit]
[-] REQUEST-920-PROTOCOL-ENFORCEMENT.conf
[edit]
[-] REQUEST-949-BLOCKING-EVALUATION.conf
[edit]
[-] RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example
[edit]
[-] REQUEST-922-MULTIPART-ATTACK.conf
[edit]
[-] web-shells-php.data
[edit]
[-] REQUEST-933-APPLICATION-ATTACK-PHP.conf
[edit]
[-] RESPONSE-953-DATA-LEAKAGES-PHP.conf
[edit]
[-] RESPONSE-950-DATA-LEAKAGES.conf
[edit]
[-] REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example
[edit]
[-] sql-errors.data
[edit]
[-] restricted-files.data
[edit]
[-] restricted-upload.data
[edit]
[-] REQUEST-921-PROTOCOL-ATTACK.conf
[edit]
[-] REQUEST-913-SCANNER-DETECTION.conf
[edit]
[-] php-config-directives.data
[edit]
[-] RESPONSE-951-DATA-LEAKAGES-SQL.conf
[edit]
[-] php-variables.data
[edit]
[-] RESPONSE-954-DATA-LEAKAGES-IIS.conf
[edit]
[-] unix-shell.data
[edit]
[-] REQUEST-901-INITIALIZATION.conf
[edit]
[-] php-function-names-933151.data
[edit]
[-] iis-errors.data
[edit]
[-] REQUEST-911-METHOD-ENFORCEMENT.conf
[edit]
[-] RESPONSE-952-DATA-LEAKAGES-JAVA.conf
[edit]
[-] scanners-user-agents.data
[edit]
[-] RESPONSE-980-CORRELATION.conf
[edit]
[-] php-function-names-933150.data
[edit]
[-] REQUEST-944-APPLICATION-ATTACK-JAVA.conf
[edit]
[-] java-errors.data
[edit]
[-] windows-powershell-commands.data
[edit]
[-] REQUEST-942-APPLICATION-ATTACK-SQLI.conf
[edit]
[-] java-classes.data
[edit]
[-] php-errors-pl2.data
[edit]
[-] php-errors.data
[edit]
[-] REQUEST-905-COMMON-EXCEPTIONS.conf
[edit]
[-] RESPONSE-959-BLOCKING-EVALUATION.conf
[edit]
[-] REQUEST-930-APPLICATION-ATTACK-LFI.conf
[edit]
[-] RESPONSE-955-WEB-SHELLS.conf
[edit]
[-] java-code-leakages.data
[edit]
[-] REQUEST-934-APPLICATION-ATTACK-GENERIC.conf
[edit]
[-] lfi-os-files.data
[edit]