Protection against Bash injection

Marc Stern <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <[email protected]>
For those who remember, we (Approach Belgium) published in 2011 the 
"cmdLine" transformation that handles most Windows cmd injections (and 
some basic bash injections). The "cmdLine" transformation is now 
officially part of ModSecurity for years.

We were also using, to protect our customers for some years, an 
additional transformation blocking several other bash injections.
We decided to also give it to the community.
The source code and the explanations are available on 
https://www.approach.be/en/modsecurity.html

Enjoy


	*Marc Stern
Cyber-Security Consulting Director*
Approach Belgium <https://www.approach.be>
Axis Park - Rue Edouard Belin 7 - 1435 Mont-Saint-Guibert - Belgium
Follow us: <https://www.linkedin.com/company/16513/> 
<https://twitter.com/ApproachBe>
/*Inspiring the cyber-security community*/


This e-mail and any attachment are confidential and intended solely for 
the use of the individual to whom it is addressed. If you are not the 
intended recipient, please contact the sender and delete this message 
and any attachment from your system. Unauthorised publication, use, 
dissemination, forwarding, printing or copying of this e-mail and its 
associated attachments is strictly prohibited.

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.