/** * OWASP CRS v4.7.0 — rule descriptions (auto-generated from installed CRS). * Update by running the extraction script when upgrading CRS. */ export const CRS_RULES: Record = { 901001: "ModSecurity CRS is deployed without configuration! Please copy the crs-setup.conf.example template to crs-setup.conf,...", 901100: "Enabling body inspection", 901350: "Enabling forced body inspection for ASCII content", 901400: "Sampling: Disable the rule engine based on sampling_percentage and random number ", 901500: "Detection paranoia level configured is lower than the paranoia level itself. This is illegal. Blocking request. Aborting", 911011: "Method is not allowed by policy", 913011: "Found User-Agent associated with security scanner", 920011: "Invalid HTTP Request Line", 920013: "Range: Too many fields (6 or more)", 920015: "Invalid character in request (outside of printable chars below ascii 127)", 920017: "Range: Too many fields for pdf request (6 or more)", 920120: "Attempted multipart/form-data bypass", 920121: "Attempted multipart/form-data bypass", 920160: "Content-Length HTTP header is not numeric", 920170: "GET or HEAD Request with Body Content", 920171: "GET or HEAD Request with Transfer-Encoding", 920180: "POST without Content-Length or Transfer-Encoding headers", 920181: "Content-Length and Transfer-Encoding headers present", 920190: "Range: Invalid Last Byte Value", 920201: "Range: Too many fields for pdf request (63 or more)", 920210: "Multiple/Conflicting Connection Header Data Found", 920220: "URL Encoding Abuse Attack Attempt", 920221: "URL Encoding Abuse Attack Attempt", 920230: "Multiple URL Encoding Detected", 920240: "URL Encoding Abuse Attack Attempt", 920250: "UTF8 Encoding Abuse Attack Attempt", 920260: "Unicode Full/Half Width Abuse Attack Attempt", 920270: "Invalid character in request (null character)", 920271: "Invalid character in request (non printable characters)", 920273: "Invalid character in request (outside of very strict set)", 920274: "Invalid character in request headers (outside of very strict set)", 920275: "Invalid character in request headers (outside of very strict set)", 920280: "Request Missing a Host Header", 920290: "Empty Host Header", 920300: "Request Missing an Accept Header", 920310: "Request Has an Empty Accept Header", 920311: "Request Has an Empty Accept Header", 920320: "Missing User Agent Header", 920330: "Empty User Agent Header", 920340: "Request Containing Content, but Missing Content-Type header", 920341: "Request Containing Content Requires Content-Type header", 920350: "Host header is a numeric IP address", 920360: "Argument name too long", 920370: "Argument value too long", 920380: "Too many arguments in request", 920390: "Total arguments size exceeded", 920400: "Uploaded file size too large", 920410: "Total uploaded files size too large", 920420: "Request content type is not allowed by policy", 920430: "HTTP protocol version is not allowed by policy", 920440: "URL file extension is restricted by policy", 920450: "HTTP header is restricted by policy ()", 920451: "HTTP header is restricted by policy ()", 920460: "Abnormal character escapes in request", 920470: "Illegal Content-Type header", 920480: "Request content type charset is not allowed by policy", 920490: "Request header x-up-devcap-post-charset detected in combination with suspicious prefix", 920500: "Attempt to access a backup or working file", 920510: "Invalid Cache-Control request header", 920520: "Accept-Encoding header exceeded sensible length", 920521: "Illegal Accept-Encoding header", 920530: "Multiple charsets detected in content type header", 920540: "Possible Unicode character bypass detected", 920600: "Illegal Accept header: charset parameter", 920610: "Raw (unencoded) fragment in request URI", 920620: "Multiple Content-Type Request Headers", 921011: "HTTP Request Smuggling Attack", 921013: "HTTP Header Injection Attack via payload (CR/LF detected)", 921015: "HTTP Range Header detected", 921017: "HTTP Parameter Pollution possible via array notation", 921120: "HTTP Response Splitting Attack", 921130: "HTTP Response Splitting Attack", 921140: "HTTP Header Injection Attack via headers", 921150: "HTTP Header Injection Attack via payload (CR/LF detected)", 921160: "HTTP Header Injection Attack via payload (CR/LF and header-name detected)", 921170: "HTTP Parameter Pollution ()", 921190: "HTTP Splitting (CR/LF in request filename detected)", 921200: "LDAP Injection Attack", 921210: "HTTP Parameter Pollution after detecting bogus char after parameter array", 921240: "mod_proxy attack attempt detected", 921421: "Content-Type header: Dangerous content type outside the mime type declaration", 921422: "Content-Type header: Dangerous content type outside the mime type declaration", 922100: "Multipart content type global _charset_ definition is not allowed by policy", 922110: "Illegal MIME Multipart Header content-type: charset parameter", 922120: "Content-Transfer-Encoding was deprecated by rfc7578 in 2015 and should not be used", 922130: "Multipart header contains characters outside of valid range", 930011: "Path Traversal Attack (/../) or (/.../)", 930013: "OS File Access Attempt in REQUEST_HEADERS", 930110: "Path Traversal Attack (/../) or (/.../)", 930120: "OS File Access Attempt", 930130: "Restricted File Access Attempt", 931011: "Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address", 931013: "Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link", 931110: "Possible Remote File Inclusion (RFI) Attack: Common RFI Vulnerable Parameter Name used w/URL Payload", 931120: "Possible Remote File Inclusion (RFI) Attack: URL Payload Used w/Trailing Question Mark Character (?)", 931131: "Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link", 932011: "Remote Command Execution: Unix Command Injection (2-3 chars)", 932013: "Remote Command Execution: Unix Command Injection", 932015: "Remote Command Execution: Unix Command Injection", 932120: "Remote Command Execution: Windows PowerShell Command Found", 932125: "Remote Command Execution: Windows Powershell Alias Command Injection", 932130: "Remote Command Execution: Unix Shell Expression Found", 932131: "Remote Command Execution: Unix Shell Expression Found", 932140: "Remote Command Execution: Windows FOR/IF Command Found", 932160: "Remote Command Execution: Unix Shell Code Found", 932161: "Remote Command Execution: Unix Shell Code Found in REQUEST_HEADERS", 932170: "Remote Command Execution: Shellshock (CVE-2014-6271)", 932171: "Remote Command Execution: Shellshock (CVE-2014-6271)", 932175: "Remote Command Execution: Unix shell alias invocation", 932180: "Restricted File Upload Attempt", 932190: "Remote Command Execution: Wildcard bypass technique attempt", 932200: "RCE Bypass Technique", 932205: "RCE Bypass Technique", 932206: "RCE Bypass Technique", 932210: "Remote Command Execution: SQLite System Command Execution", 932220: "Remote Command Execution: Unix Command Injection with pipe", 932235: "Remote Command Execution: Unix Command Injection (command without evasion)", 932236: "Remote Command Execution: Unix Command Injection (command without evasion)", 932237: "Remote Command Execution: Unix Shell Code Found in REQUEST_HEADERS", 932238: "Remote Command Execution: Unix Shell Code Found in REQUEST_HEADERS", 932239: "Remote Command Execution: Unix Command Injection found in user-agent or referer header", 932240: "Remote Command Execution: Unix Command Injection evasion attempt detected", 932250: "Remote Command Execution: Direct Unix Command Execution", 932260: "Remote Command Execution: Direct Unix Command Execution", 932270: "Remote Command Execution: Unix Shell Expression Found", 932300: "Remote Command Execution: SMTP Command Execution", 932301: "Remote Command Execution: SMTP Command Execution", 932310: "Remote Command Execution: IMAP Command Execution", 932311: "Remote Command Execution: IMAP Command Execution", 932320: "Remote Command Execution: POP3 Command Execution", 932321: "Remote Command Execution: POP3 Command Execution", 932330: "Remote Command Execution: Unix shell history invocation", 932331: "Remote Command Execution: Unix shell history invocation", 932370: "Remote Command Execution: Windows Command Injection", 932380: "Remote Command Execution: Windows Command Injection", 933011: "PHP Injection Attack: PHP Open Tag Found", 933013: "PHP Injection Attack: Medium-Risk PHP Function Name Found", 933015: "PHP Injection Attack: Variables Found", 933110: "PHP Injection Attack: PHP Script File Upload Found", 933111: "PHP Injection Attack: PHP Script File Upload Found", 933120: "PHP Injection Attack: Configuration Directive Found", 933130: "PHP Injection Attack: Variables Found", 933140: "PHP Injection Attack: I/O Stream Found", 933150: "PHP Injection Attack: High-Risk PHP Function Name Found", 933160: "PHP Injection Attack: High-Risk PHP Function Call Found", 933161: "PHP Injection Attack: Low-Value PHP Function Call Found", 933170: "PHP Injection Attack: Serialized Object Injection", 933180: "PHP Injection Attack: Variable Function Call Found", 933190: "PHP Injection Attack: PHP Closing Tag Found", 933200: "PHP Injection Attack: Wrapper scheme detected", 933210: "PHP Injection Attack: Variable Function Call Found", 933211: "PHP Injection Attack: Variable Function Call Found", 934011: "Node.js Injection Attack 1/2", 934013: "Node.js Injection Attack 2/2", 934110: "Possible Server Side Request Forgery (SSRF) Attack: Cloud provider metadata URL in Parameter", 934120: "Possible Server Side Request Forgery (SSRF) Attack: URL Parameter using IP Address", 934130: "JavaScript Prototype Pollution", 934140: "Perl Injection Attack", 934150: "Ruby Injection Attack", 934160: "Node.js DoS attack", 934170: "PHP data scheme attack", 941011: "XSS Attack Detected via libinjection", 941013: "XSS Attack Detected via libinjection", 941110: "XSS Filter - Category 1: Script Tag Vector", 941120: "XSS Filter - Category 2: Event Handler Vector", 941130: "XSS Filter - Category 3: Attribute Vector", 941140: "XSS Filter - Category 4: Javascript URI Vector", 941150: "XSS Filter - Category 5: Disallowed HTML Attributes", 941160: "NoScript XSS InjectionChecker: HTML Injection", 941170: "NoScript XSS InjectionChecker: Attribute Injection", 941180: "Node-Validator Deny List Keywords", 941181: "Node-Validator Deny List Keywords", 941190: "IE XSS Filters - Attack Detected", 941200: "IE XSS Filters - Attack Detected", 941210: "IE XSS Filters - Attack Detected", 941220: "IE XSS Filters - Attack Detected", 941230: "IE XSS Filters - Attack Detected", 941240: "IE XSS Filters - Attack Detected", 941250: "IE XSS Filters - Attack Detected", 941260: "IE XSS Filters - Attack Detected", 941270: "IE XSS Filters - Attack Detected", 941280: "IE XSS Filters - Attack Detected", 941290: "IE XSS Filters - Attack Detected", 941300: "IE XSS Filters - Attack Detected", 941310: "US-ASCII Malformed Encoding XSS Filter - Attack Detected", 941320: "Possible XSS Attack Detected - HTML Tag Handler", 941330: "IE XSS Filters - Attack Detected", 941340: "IE XSS Filters - Attack Detected", 941350: "UTF-7 Encoding IE XSS - Attack Detected", 941360: "JSFuck / Hieroglyphy obfuscation detected", 941370: "JavaScript global variable found", 941380: "AngularJS client side template injection detected", 941390: "Javascript method detected", 941400: "XSS JavaScript function without parentheses", 942011: "SQL Injection Attack Detected via libinjection", 942013: "SQL Injection Attack: SQL Operator Detected", 942015: "Detects HAVING injections", 942017: "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)", 942101: "SQL Injection Attack Detected via libinjection", 942130: "SQL Injection Attack: SQL Boolean-based attack detected", 942131: "SQL Injection Attack: SQL Boolean-based attack detected", 942140: "SQL Injection Attack: Common DB Names Detected", 942150: "SQL Injection Attack: SQL function name detected", 942151: "SQL Injection Attack: SQL function name detected", 942152: "SQL Injection Attack: SQL function name detected", 942160: "Detects blind sqli tests using sleep() or benchmark()", 942170: "Detects SQL benchmark and sleep injection attempts including conditional queries", 942180: "Detects basic SQL authentication bypass attempts 1/3", 942190: "Detects MSSQL code execution and information gathering attempts", 942200: "Detects MySQL comment-/space-obfuscated injections and backtick termination", 942210: "Detects chained SQL injection attempts 1/2", 942220: "Looking for integer overflow attacks, these are taken from skipfish, except 2.2.2250738585072011e-308 is the 'magic...", 942230: "Detects conditional SQL injection attempts", 942240: "Detects MySQL charset switch and MSSQL DoS attempts", 942250: "Detects MATCH AGAINST, MERGE and EXECUTE IMMEDIATE injections", 942260: "Detects basic SQL authentication bypass attempts 2/3", 942270: "Looking for basic sql injection. Common attack string for mysql, oracle and others", 942280: "Detects Postgres pg_sleep injection, waitfor delay attacks and database shutdown attempts", 942290: "Finds basic MongoDB SQL injection attempts", 942300: "Detects MySQL comments, conditions and ch(a)r injections", 942310: "Detects chained SQL injection attempts 2/2", 942320: "Detects MySQL and PostgreSQL stored procedure/function injections", 942321: "Detects MySQL and PostgreSQL stored procedure/function injections", 942330: "Detects classic SQL injection probings 1/3", 942340: "Detects basic SQL authentication bypass attempts 3/3", 942350: "Detects MySQL UDF injection and other data/structure manipulation attempts", 942360: "Detects concatenated basic SQL injection and SQLLFI attempts", 942361: "Detects basic SQL injection based on keyword alter or union", 942362: "Detects concatenated basic SQL injection and SQLLFI attempts", 942370: "Detects classic SQL injection probings 2/3", 942380: "SQL Injection Attack", 942390: "SQL Injection Attack", 942400: "SQL Injection Attack", 942410: "SQL Injection Attack", 942420: "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (8)", 942430: "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (12)", 942431: "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)", 942432: "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)", 942441: "SQL Comment Sequence Detected", 942450: "SQL Hex Encoding Identified", 942460: "Meta-Character Anomaly Detection Alert - Repetitive Non-Word Characters", 942470: "SQL Injection Attack", 942480: "SQL Injection Attack", 942490: "Detects classic SQL injection probings 3/3", 942500: "MySQL in-line comment detected", 942510: "SQLi bypass attempt by ticks or backticks detected", 942511: "SQLi bypass attempt by ticks detected", 942520: "Detects basic SQL authentication bypass attempts 4.0/4", 942521: "Detects basic SQL authentication bypass attempts 4.1/4", 942522: "Detects basic SQL authentication bypass attempts 4.1/4", 942530: "SQLi query termination detected", 942540: "SQL Authentication bypass (split query)", 942550: "JSON-Based SQL Injection", 942560: "MySQL Scientific Notation payload detected", 943011: "Possible Session Fixation Attack: Setting Cookie Values in HTML", 943110: "Possible Session Fixation Attack: SessionID Parameter Name with Off-Domain Referer", 943120: "Possible Session Fixation Attack: SessionID Parameter Name with No Referer", 944011: "Remote Command Execution: Suspicious Java class detected", 944013: "Potential Remote Command Execution: Log4j / Log4shell", 944015: "Base64 encoded string matched suspicious keyword", 944017: "Potential Remote Command Execution: Log4j / Log4shell", 944110: "Remote Command Execution: Java process spawn (CVE-2017-9805)", 944120: "Remote Command Execution: Java serialization (CVE-2015-4852)", 944130: "Suspicious Java class detected", 944140: "Java Injection Attack: Java Script File Upload Found", 944150: "Potential Remote Command Execution: Log4j / Log4shell", 944200: "Magic bytes Detected, probable java serialization in use", 944210: "Magic bytes Detected Base64 Encoded, probable java serialization in use", 944240: "Remote Command Execution: Java serialization (CVE-2015-4852)", 944250: "Remote Command Execution: Suspicious Java method detected", 944260: "Remote Command Execution: Malicious class-loading payload", 949052: "Inbound Anomaly Score Exceeded in phase 1 (Total Score: %{TX.BLOCKING_INBOUND_ANOMALY_SCORE})", 949110: "Inbound Anomaly Score Exceeded (Total Score: %{TX.BLOCKING_INBOUND_ANOMALY_SCORE})", 950010: "Directory Listing", 950013: "The Application Returned a 500-Level Status Code", 950140: "CGI source code leakage", 951010: "Microsoft Access SQL Information Leakage", 951120: "Oracle SQL Information Leakage", 951130: "DB2 SQL Information Leakage", 951140: "EMC SQL Information Leakage", 951150: "firebird SQL Information Leakage", 951160: "Frontbase SQL Information Leakage", 951170: "hsqldb SQL Information Leakage", 951180: "informix SQL Information Leakage", 951190: "ingres SQL Information Leakage", 951200: "interbase SQL Information Leakage", 951210: "maxDB SQL Information Leakage", 951220: "mssql SQL Information Leakage", 951230: "mysql SQL Information Leakage", 951240: "postgres SQL Information Leakage", 951250: "sqlite SQL Information Leakage", 951260: "Sybase SQL Information Leakage", 952010: "Java Source Code Leakage", 952110: "Java Errors", 953010: "PHP Information Leakage", 953013: "PHP Information Leakage", 953110: "PHP source code leakage", 953120: "PHP source code leakage", 954010: "Disclosure of IIS install location", 954110: "Application Availability Error", 954120: "IIS Information Leakage", 954130: "IIS Information Leakage", 955010: "Web shell detected", 955013: "webadmin.php file manager", 955110: "r57 web shell", 955120: "WSO web shell", 955130: "b4tm4n web shell", 955140: "Mini Shell web shell", 955150: "Ashiyane web shell", 955160: "Symlink_Sa web shell", 955170: "CasuS web shell", 955180: "GRP WebShell", 955190: "NGHshell web shell", 955200: "SimAttacker web shell", 955210: "Unknown web shell", 955220: "lama web shell", 955230: "lostDC web shell", 955240: "Unknown web shell", 955250: "Unknown web shell", 955260: "Ru24PostWebShell web shell", 955270: "s72 Shell web shell", 955280: "PhpSpy web shell", 955290: "g00nshell web shell", 955300: "PuNkHoLic shell web shell", 955310: "azrail web shell", 955320: "SmEvK_PaThAn Shell web shell", 955330: "Shell I web shell", 955340: "b374k m1n1 web shell", 959052: "Outbound Anomaly Score Exceeded in phase 3 (Total Score: %{tx.blocking_outbound_anomaly_score})", 959100: "Outbound Anomaly Score Exceeded (Total Score: %{tx.blocking_outbound_anomaly_score})", 980099: "Anomaly Scores: Inbound/Outbound anomaly score summary", } export function getRuleDescription(ruleId: number): string { return CRS_RULES[ruleId] ?? `Rule ${ruleId} — see coreruleset.org for details` }