diff --git a/install/litespeed/httpd_config.xml b/install/litespeed/httpd_config.xml index 1eaf7b811..026bf6572 100755 --- a/install/litespeed/httpd_config.xml +++ b/install/litespeed/httpd_config.xml @@ -125,19 +125,7 @@ XSS attack log,deny,status:403,msg:'XSS attack' 1 - SecFilterSelective ARGS "(alert|expression|eval|url)[[:space:]]*\(" -SecFilterSelective ARGS "(&\{.+\}|(&#[[0-9a-fA-F]]|\x5cx[0-9a-fA-F]){2})" - -SecFilterSelective ARGS "((javascript|vbscript):|style[[:space:]]*=)" -SecFilterSelective ARGS "(fromCharCode|http-equiv|<.+>|innerHTML|dynsrc|-->)" -SecFilterSelective ARGS "document\.(body|cookie|location|write)" - -SecFilterSelective ARGS_VALUES "jsessionid|phpsessid|onReadyStateChange|xmlHttp" - -SecFilterSelective ARGS "<(applet|div|embed|iframe|img|meta|object|script|textarea)" - -# JavaScript event handlers -SecFilterSelective ARGS "on(Abort|Blur|Click|DblClick|DragDrop|Error|Focus|KeyUp|KeyDown|KeyPrerss|Load|Mouse(Down|Out|Over|Up)|Move|Reset|Resize|Select|Submit|Unload)" + SQL injection diff --git a/serverStatus/litespeed/httpd_config.xml b/serverStatus/litespeed/httpd_config.xml index 1eaf7b811..acc6069cf 100755 --- a/serverStatus/litespeed/httpd_config.xml +++ b/serverStatus/litespeed/httpd_config.xml @@ -125,31 +125,7 @@ XSS attack log,deny,status:403,msg:'XSS attack' 1 - SecFilterSelective ARGS "(alert|expression|eval|url)[[:space:]]*\(" -SecFilterSelective ARGS "(&\{.+\}|(&#[[0-9a-fA-F]]|\x5cx[0-9a-fA-F]){2})" - -SecFilterSelective ARGS "((javascript|vbscript):|style[[:space:]]*=)" -SecFilterSelective ARGS "(fromCharCode|http-equiv|<.+>|innerHTML|dynsrc|-->)" -SecFilterSelective ARGS "document\.(body|cookie|location|write)" - -SecFilterSelective ARGS_VALUES "jsessionid|phpsessid|onReadyStateChange|xmlHttp" - -SecFilterSelective ARGS "<(applet|div|embed|iframe|img|meta|object|script|textarea)" - -# JavaScript event handlers -SecFilterSelective ARGS "on(Abort|Blur|Click|DblClick|DragDrop|Error|Focus|KeyUp|KeyDown|KeyPrerss|Load|Mouse(Down|Out|Over|Up)|Move|Reset|Resize|Select|Submit|Unload)" - - - SQL injection - log,pass,msg:'SQL Injection attack' - 1 - #SQL generic -SecFilterSelective ARGS "drop[[:space:]]+(database|table|column|procedure)" -SecFilterSelective ARGS "delete[[:space:]]+from|create[[:space:]]+table|update.+set.+=|insert[[:space:]]+into.+values" -SecFilterSelective ARGS "select.+from|bulk[[:space:]]+insert|union.+select|alter[[:space:]]+table" -SecFilterSelective ARGS "or.+1[[:space:]]*=[[:space:]]1|or 1=1--'|'.+--" - -SecFilterSelective ARGS "into[[:space:]]+outfile|load[[:space:]]+data|/\*.+\*/" + /