Added OCS Inventory NG Rules, updated Rainloop rules for NAXSI WAF

This commit is contained in:
Paul 2014-09-28 17:28:25 +02:00
parent 8929db5d4d
commit 3b4566458a
2 changed files with 39 additions and 5 deletions

View File

@ -0,0 +1,33 @@
BasicRule wl:1000 "mz:$URL:/ocsreports/index.php|BODY|NAME";
BasicRule wl:1000 "mz:$URL:/ocsreports/|BODY|NAME";
BasicRule wl:1001 "mz:$BODY_VAR:filtre_value";
BasicRule wl:1001 "mz:$URL:/ocsreports/index.php|$BODY_VAR:filtre_value";
BasicRule wl:1001 "mz:$URL:/ocsreports/index.php|BODY";
BasicRule wl:1001 "mz:BODY";
BasicRule wl:1009 "mz:$BODY_VAR:filtre_value";
BasicRule wl:1009 "mz:$URL:/ocsreports/index.php|$BODY_VAR:filtre_value";
BasicRule wl:1009 "mz:$URL:/ocsreports/index.php|BODY";
BasicRule wl:1009 "mz:$URL:/ocsreports/|$ARGS_VAR:password";
BasicRule wl:1009 "mz:$URL:/ocsreports/|$ARGS_VAR:username";
BasicRule wl:1009 "mz:$URL:/ocsreports/|ARGS";
BasicRule wl:1009 "mz:ARGS";
BasicRule wl:1009 "mz:BODY";
BasicRule wl:1010 "mz:$URL:/ocsreports/index.php|$ARGS_VAR:option";
BasicRule wl:1010 "mz:$URL:/ocsreports/index.php|ARGS";
BasicRule wl:1010 "mz:ARGS";
BasicRule wl:1011 "mz:$URL:/ocsreports/index.php|$ARGS_VAR:option";
BasicRule wl:1011 "mz:$URL:/ocsreports/index.php|ARGS";
BasicRule wl:1011 "mz:ARGS";
BasicRule wl:1013 "mz:$URL:/ocsreports/|$ARGS_VAR:password";
BasicRule wl:1013 "mz:$URL:/ocsreports/|$ARGS_VAR:username";
BasicRule wl:1013 "mz:$URL:/ocsreports/|ARGS";
BasicRule wl:1013 "mz:ARGS";
BasicRule wl:11 "mz:$URL:/ocsinventory/|BODY";
BasicRule wl:11 "mz:$URL:/ocsinventory|BODY";
BasicRule wl:1402 "mz:$URL:/ocsinventory/|HEADERS";
BasicRule wl:1402 "mz:$URL:/ocsinventory|HEADERS";
BasicRule wl:11 "mz:BODY";
BasicRule wl:1315 "mz:$HEADERS_VAR:cookie";
BasicRule wl:1205 "mz:BODY";
BasicRule wl:1100 "mz:BODY";
BasicRule wl:1015 "mz:BODY";

View File

@ -1,13 +1,14 @@
BasicRule wl:1000 "mz:$BODY_VAR:folders[]";
BasicRule wl:1015 "mz:$URL:/|$BODY_VAR:flagsuids";
BasicRule wl:1000,1310,1311 "mz:$URL:/|BODY|NAME";
BasicRule wl:1001,1302,1303 "mz:$URL:/|$BODY_VAR:from";
BasicRule wl:1008 "mz:$URL:/|$BODY_VAR:text";
BasicRule wl:1001,1008,1015,1302,1303 "mz:BODY";
BasicRule wl:1000,1310,1311 "mz:$URL:/|BODY|NAME";
BasicRule wl:1001,1008,1015,1302,1303 "mz:$URL:/|BODY";
BasicRule wl:1000,1001,1008,1015,1302,1303 "mz:BODY";
BasicRule wl:1000,1001,1008,1015,1302,1303 "mz:$URL:/|BODY";
BasicRule wl:1015 "mz:$BODY_VAR:flagsuids";
BasicRule wl:1001,1302,1303 "mz:$BODY_VAR:from";
BasicRule wl:1008 "mz:$BODY_VAR:text";
BasicRule wl:1200 "mz:$URL:/|ARGS";
BasicRule wl:1200 "mz:ARGS";
BasicRule wl:1007,1200 "mz:$URL:/|ARGS";
BasicRule wl:1007,1200 "mz:ARGS";
BasicRule wl:1200 "mz:$HEADERS_VAR:cookie";
BasicRule wl:1007 "mz:ARGS";