/ Published in: Apache
block evil incarnate query strings
Expand |
Embed | Plain Text
Copy this code and paste it in your HTML
<ifmodule mod_rewrite.c> RewriteCond %{QUERY_STRING} \.\.\/ [NC,OR] RewriteRule .* - [F,L] </ifmodule> # block evil incarnate user agents SetEnvIfNoCase User-Agent "shell_exec" keep_out SetEnvIfNoCase User-Agent "passthru" keep_out SetEnvIfNoCase User-Agent "function" keep_out <Limit GET POST> order allow,deny allow from all deny from env=keep_out </Limit>
URL: http://perishablepress.com/press/2008/09/15/evil-incarnate-but-easily-blocked/