341 lines
19 KiB
TypeScript
341 lines
19 KiB
TypeScript
/**
|
|
* OWASP CRS v4.7.0 — rule descriptions (auto-generated from installed CRS).
|
|
* Update by running the extraction script when upgrading CRS.
|
|
*/
|
|
export const CRS_RULES: Record<number, string> = {
|
|
901001: "ModSecurity CRS is deployed without configuration! Please copy the crs-setup.conf.example template to crs-setup.conf,...",
|
|
901100: "Enabling body inspection",
|
|
901350: "Enabling forced body inspection for ASCII content",
|
|
901400: "Sampling: Disable the rule engine based on sampling_percentage <pct> and random number <rnd>",
|
|
901500: "Detection paranoia level configured is lower than the paranoia level itself. This is illegal. Blocking request. Aborting",
|
|
911011: "Method is not allowed by policy",
|
|
913011: "Found User-Agent associated with security scanner",
|
|
920011: "Invalid HTTP Request Line",
|
|
920013: "Range: Too many fields (6 or more)",
|
|
920015: "Invalid character in request (outside of printable chars below ascii 127)",
|
|
920017: "Range: Too many fields for pdf request (6 or more)",
|
|
920120: "Attempted multipart/form-data bypass",
|
|
920121: "Attempted multipart/form-data bypass",
|
|
920160: "Content-Length HTTP header is not numeric",
|
|
920170: "GET or HEAD Request with Body Content",
|
|
920171: "GET or HEAD Request with Transfer-Encoding",
|
|
920180: "POST without Content-Length or Transfer-Encoding headers",
|
|
920181: "Content-Length and Transfer-Encoding headers present",
|
|
920190: "Range: Invalid Last Byte Value",
|
|
920201: "Range: Too many fields for pdf request (63 or more)",
|
|
920210: "Multiple/Conflicting Connection Header Data Found",
|
|
920220: "URL Encoding Abuse Attack Attempt",
|
|
920221: "URL Encoding Abuse Attack Attempt",
|
|
920230: "Multiple URL Encoding Detected",
|
|
920240: "URL Encoding Abuse Attack Attempt",
|
|
920250: "UTF8 Encoding Abuse Attack Attempt",
|
|
920260: "Unicode Full/Half Width Abuse Attack Attempt",
|
|
920270: "Invalid character in request (null character)",
|
|
920271: "Invalid character in request (non printable characters)",
|
|
920273: "Invalid character in request (outside of very strict set)",
|
|
920274: "Invalid character in request headers (outside of very strict set)",
|
|
920275: "Invalid character in request headers (outside of very strict set)",
|
|
920280: "Request Missing a Host Header",
|
|
920290: "Empty Host Header",
|
|
920300: "Request Missing an Accept Header",
|
|
920310: "Request Has an Empty Accept Header",
|
|
920311: "Request Has an Empty Accept Header",
|
|
920320: "Missing User Agent Header",
|
|
920330: "Empty User Agent Header",
|
|
920340: "Request Containing Content, but Missing Content-Type header",
|
|
920341: "Request Containing Content Requires Content-Type header",
|
|
920350: "Host header is a numeric IP address",
|
|
920360: "Argument name too long",
|
|
920370: "Argument value too long",
|
|
920380: "Too many arguments in request",
|
|
920390: "Total arguments size exceeded",
|
|
920400: "Uploaded file size too large",
|
|
920410: "Total uploaded files size too large",
|
|
920420: "Request content type is not allowed by policy",
|
|
920430: "HTTP protocol version is not allowed by policy",
|
|
920440: "URL file extension is restricted by policy",
|
|
920450: "HTTP header is restricted by policy (<matched>)",
|
|
920451: "HTTP header is restricted by policy (<matched>)",
|
|
920460: "Abnormal character escapes in request",
|
|
920470: "Illegal Content-Type header",
|
|
920480: "Request content type charset is not allowed by policy",
|
|
920490: "Request header x-up-devcap-post-charset detected in combination with suspicious prefix",
|
|
920500: "Attempt to access a backup or working file",
|
|
920510: "Invalid Cache-Control request header",
|
|
920520: "Accept-Encoding header exceeded sensible length",
|
|
920521: "Illegal Accept-Encoding header",
|
|
920530: "Multiple charsets detected in content type header",
|
|
920540: "Possible Unicode character bypass detected",
|
|
920600: "Illegal Accept header: charset parameter",
|
|
920610: "Raw (unencoded) fragment in request URI",
|
|
920620: "Multiple Content-Type Request Headers",
|
|
921011: "HTTP Request Smuggling Attack",
|
|
921013: "HTTP Header Injection Attack via payload (CR/LF detected)",
|
|
921015: "HTTP Range Header detected",
|
|
921017: "HTTP Parameter Pollution possible via array notation",
|
|
921120: "HTTP Response Splitting Attack",
|
|
921130: "HTTP Response Splitting Attack",
|
|
921140: "HTTP Header Injection Attack via headers",
|
|
921150: "HTTP Header Injection Attack via payload (CR/LF detected)",
|
|
921160: "HTTP Header Injection Attack via payload (CR/LF and header-name detected)",
|
|
921170: "HTTP Parameter Pollution (<var>)",
|
|
921190: "HTTP Splitting (CR/LF in request filename detected)",
|
|
921200: "LDAP Injection Attack",
|
|
921210: "HTTP Parameter Pollution after detecting bogus char after parameter array",
|
|
921240: "mod_proxy attack attempt detected",
|
|
921421: "Content-Type header: Dangerous content type outside the mime type declaration",
|
|
921422: "Content-Type header: Dangerous content type outside the mime type declaration",
|
|
922100: "Multipart content type global _charset_ definition is not allowed by policy",
|
|
922110: "Illegal MIME Multipart Header content-type: charset parameter",
|
|
922120: "Content-Transfer-Encoding was deprecated by rfc7578 in 2015 and should not be used",
|
|
922130: "Multipart header contains characters outside of valid range",
|
|
930011: "Path Traversal Attack (/../) or (/.../)",
|
|
930013: "OS File Access Attempt in REQUEST_HEADERS",
|
|
930110: "Path Traversal Attack (/../) or (/.../)",
|
|
930120: "OS File Access Attempt",
|
|
930130: "Restricted File Access Attempt",
|
|
931011: "Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address",
|
|
931013: "Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link",
|
|
931110: "Possible Remote File Inclusion (RFI) Attack: Common RFI Vulnerable Parameter Name used w/URL Payload",
|
|
931120: "Possible Remote File Inclusion (RFI) Attack: URL Payload Used w/Trailing Question Mark Character (?)",
|
|
931131: "Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link",
|
|
932011: "Remote Command Execution: Unix Command Injection (2-3 chars)",
|
|
932013: "Remote Command Execution: Unix Command Injection",
|
|
932015: "Remote Command Execution: Unix Command Injection",
|
|
932120: "Remote Command Execution: Windows PowerShell Command Found",
|
|
932125: "Remote Command Execution: Windows Powershell Alias Command Injection",
|
|
932130: "Remote Command Execution: Unix Shell Expression Found",
|
|
932131: "Remote Command Execution: Unix Shell Expression Found",
|
|
932140: "Remote Command Execution: Windows FOR/IF Command Found",
|
|
932160: "Remote Command Execution: Unix Shell Code Found",
|
|
932161: "Remote Command Execution: Unix Shell Code Found in REQUEST_HEADERS",
|
|
932170: "Remote Command Execution: Shellshock (CVE-2014-6271)",
|
|
932171: "Remote Command Execution: Shellshock (CVE-2014-6271)",
|
|
932175: "Remote Command Execution: Unix shell alias invocation",
|
|
932180: "Restricted File Upload Attempt",
|
|
932190: "Remote Command Execution: Wildcard bypass technique attempt",
|
|
932200: "RCE Bypass Technique",
|
|
932205: "RCE Bypass Technique",
|
|
932206: "RCE Bypass Technique",
|
|
932210: "Remote Command Execution: SQLite System Command Execution",
|
|
932220: "Remote Command Execution: Unix Command Injection with pipe",
|
|
932235: "Remote Command Execution: Unix Command Injection (command without evasion)",
|
|
932236: "Remote Command Execution: Unix Command Injection (command without evasion)",
|
|
932237: "Remote Command Execution: Unix Shell Code Found in REQUEST_HEADERS",
|
|
932238: "Remote Command Execution: Unix Shell Code Found in REQUEST_HEADERS",
|
|
932239: "Remote Command Execution: Unix Command Injection found in user-agent or referer header",
|
|
932240: "Remote Command Execution: Unix Command Injection evasion attempt detected",
|
|
932250: "Remote Command Execution: Direct Unix Command Execution",
|
|
932260: "Remote Command Execution: Direct Unix Command Execution",
|
|
932270: "Remote Command Execution: Unix Shell Expression Found",
|
|
932300: "Remote Command Execution: SMTP Command Execution",
|
|
932301: "Remote Command Execution: SMTP Command Execution",
|
|
932310: "Remote Command Execution: IMAP Command Execution",
|
|
932311: "Remote Command Execution: IMAP Command Execution",
|
|
932320: "Remote Command Execution: POP3 Command Execution",
|
|
932321: "Remote Command Execution: POP3 Command Execution",
|
|
932330: "Remote Command Execution: Unix shell history invocation",
|
|
932331: "Remote Command Execution: Unix shell history invocation",
|
|
932370: "Remote Command Execution: Windows Command Injection",
|
|
932380: "Remote Command Execution: Windows Command Injection",
|
|
933011: "PHP Injection Attack: PHP Open Tag Found",
|
|
933013: "PHP Injection Attack: Medium-Risk PHP Function Name Found",
|
|
933015: "PHP Injection Attack: Variables Found",
|
|
933110: "PHP Injection Attack: PHP Script File Upload Found",
|
|
933111: "PHP Injection Attack: PHP Script File Upload Found",
|
|
933120: "PHP Injection Attack: Configuration Directive Found",
|
|
933130: "PHP Injection Attack: Variables Found",
|
|
933140: "PHP Injection Attack: I/O Stream Found",
|
|
933150: "PHP Injection Attack: High-Risk PHP Function Name Found",
|
|
933160: "PHP Injection Attack: High-Risk PHP Function Call Found",
|
|
933161: "PHP Injection Attack: Low-Value PHP Function Call Found",
|
|
933170: "PHP Injection Attack: Serialized Object Injection",
|
|
933180: "PHP Injection Attack: Variable Function Call Found",
|
|
933190: "PHP Injection Attack: PHP Closing Tag Found",
|
|
933200: "PHP Injection Attack: Wrapper scheme detected",
|
|
933210: "PHP Injection Attack: Variable Function Call Found",
|
|
933211: "PHP Injection Attack: Variable Function Call Found",
|
|
934011: "Node.js Injection Attack 1/2",
|
|
934013: "Node.js Injection Attack 2/2",
|
|
934110: "Possible Server Side Request Forgery (SSRF) Attack: Cloud provider metadata URL in Parameter",
|
|
934120: "Possible Server Side Request Forgery (SSRF) Attack: URL Parameter using IP Address",
|
|
934130: "JavaScript Prototype Pollution",
|
|
934140: "Perl Injection Attack",
|
|
934150: "Ruby Injection Attack",
|
|
934160: "Node.js DoS attack",
|
|
934170: "PHP data scheme attack",
|
|
941011: "XSS Attack Detected via libinjection",
|
|
941013: "XSS Attack Detected via libinjection",
|
|
941110: "XSS Filter - Category 1: Script Tag Vector",
|
|
941120: "XSS Filter - Category 2: Event Handler Vector",
|
|
941130: "XSS Filter - Category 3: Attribute Vector",
|
|
941140: "XSS Filter - Category 4: Javascript URI Vector",
|
|
941150: "XSS Filter - Category 5: Disallowed HTML Attributes",
|
|
941160: "NoScript XSS InjectionChecker: HTML Injection",
|
|
941170: "NoScript XSS InjectionChecker: Attribute Injection",
|
|
941180: "Node-Validator Deny List Keywords",
|
|
941181: "Node-Validator Deny List Keywords",
|
|
941190: "IE XSS Filters - Attack Detected",
|
|
941200: "IE XSS Filters - Attack Detected",
|
|
941210: "IE XSS Filters - Attack Detected",
|
|
941220: "IE XSS Filters - Attack Detected",
|
|
941230: "IE XSS Filters - Attack Detected",
|
|
941240: "IE XSS Filters - Attack Detected",
|
|
941250: "IE XSS Filters - Attack Detected",
|
|
941260: "IE XSS Filters - Attack Detected",
|
|
941270: "IE XSS Filters - Attack Detected",
|
|
941280: "IE XSS Filters - Attack Detected",
|
|
941290: "IE XSS Filters - Attack Detected",
|
|
941300: "IE XSS Filters - Attack Detected",
|
|
941310: "US-ASCII Malformed Encoding XSS Filter - Attack Detected",
|
|
941320: "Possible XSS Attack Detected - HTML Tag Handler",
|
|
941330: "IE XSS Filters - Attack Detected",
|
|
941340: "IE XSS Filters - Attack Detected",
|
|
941350: "UTF-7 Encoding IE XSS - Attack Detected",
|
|
941360: "JSFuck / Hieroglyphy obfuscation detected",
|
|
941370: "JavaScript global variable found",
|
|
941380: "AngularJS client side template injection detected",
|
|
941390: "Javascript method detected",
|
|
941400: "XSS JavaScript function without parentheses",
|
|
942011: "SQL Injection Attack Detected via libinjection",
|
|
942013: "SQL Injection Attack: SQL Operator Detected",
|
|
942015: "Detects HAVING injections",
|
|
942017: "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (3)",
|
|
942101: "SQL Injection Attack Detected via libinjection",
|
|
942130: "SQL Injection Attack: SQL Boolean-based attack detected",
|
|
942131: "SQL Injection Attack: SQL Boolean-based attack detected",
|
|
942140: "SQL Injection Attack: Common DB Names Detected",
|
|
942150: "SQL Injection Attack: SQL function name detected",
|
|
942151: "SQL Injection Attack: SQL function name detected",
|
|
942152: "SQL Injection Attack: SQL function name detected",
|
|
942160: "Detects blind sqli tests using sleep() or benchmark()",
|
|
942170: "Detects SQL benchmark and sleep injection attempts including conditional queries",
|
|
942180: "Detects basic SQL authentication bypass attempts 1/3",
|
|
942190: "Detects MSSQL code execution and information gathering attempts",
|
|
942200: "Detects MySQL comment-/space-obfuscated injections and backtick termination",
|
|
942210: "Detects chained SQL injection attempts 1/2",
|
|
942220: "Looking for integer overflow attacks, these are taken from skipfish, except 2.2.2250738585072011e-308 is the 'magic...",
|
|
942230: "Detects conditional SQL injection attempts",
|
|
942240: "Detects MySQL charset switch and MSSQL DoS attempts",
|
|
942250: "Detects MATCH AGAINST, MERGE and EXECUTE IMMEDIATE injections",
|
|
942260: "Detects basic SQL authentication bypass attempts 2/3",
|
|
942270: "Looking for basic sql injection. Common attack string for mysql, oracle and others",
|
|
942280: "Detects Postgres pg_sleep injection, waitfor delay attacks and database shutdown attempts",
|
|
942290: "Finds basic MongoDB SQL injection attempts",
|
|
942300: "Detects MySQL comments, conditions and ch(a)r injections",
|
|
942310: "Detects chained SQL injection attempts 2/2",
|
|
942320: "Detects MySQL and PostgreSQL stored procedure/function injections",
|
|
942321: "Detects MySQL and PostgreSQL stored procedure/function injections",
|
|
942330: "Detects classic SQL injection probings 1/3",
|
|
942340: "Detects basic SQL authentication bypass attempts 3/3",
|
|
942350: "Detects MySQL UDF injection and other data/structure manipulation attempts",
|
|
942360: "Detects concatenated basic SQL injection and SQLLFI attempts",
|
|
942361: "Detects basic SQL injection based on keyword alter or union",
|
|
942362: "Detects concatenated basic SQL injection and SQLLFI attempts",
|
|
942370: "Detects classic SQL injection probings 2/3",
|
|
942380: "SQL Injection Attack",
|
|
942390: "SQL Injection Attack",
|
|
942400: "SQL Injection Attack",
|
|
942410: "SQL Injection Attack",
|
|
942420: "Restricted SQL Character Anomaly Detection (cookies): # of special characters exceeded (8)",
|
|
942430: "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (12)",
|
|
942431: "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (6)",
|
|
942432: "Restricted SQL Character Anomaly Detection (args): # of special characters exceeded (2)",
|
|
942441: "SQL Comment Sequence Detected",
|
|
942450: "SQL Hex Encoding Identified",
|
|
942460: "Meta-Character Anomaly Detection Alert - Repetitive Non-Word Characters",
|
|
942470: "SQL Injection Attack",
|
|
942480: "SQL Injection Attack",
|
|
942490: "Detects classic SQL injection probings 3/3",
|
|
942500: "MySQL in-line comment detected",
|
|
942510: "SQLi bypass attempt by ticks or backticks detected",
|
|
942511: "SQLi bypass attempt by ticks detected",
|
|
942520: "Detects basic SQL authentication bypass attempts 4.0/4",
|
|
942521: "Detects basic SQL authentication bypass attempts 4.1/4",
|
|
942522: "Detects basic SQL authentication bypass attempts 4.1/4",
|
|
942530: "SQLi query termination detected",
|
|
942540: "SQL Authentication bypass (split query)",
|
|
942550: "JSON-Based SQL Injection",
|
|
942560: "MySQL Scientific Notation payload detected",
|
|
943011: "Possible Session Fixation Attack: Setting Cookie Values in HTML",
|
|
943110: "Possible Session Fixation Attack: SessionID Parameter Name with Off-Domain Referer",
|
|
943120: "Possible Session Fixation Attack: SessionID Parameter Name with No Referer",
|
|
944011: "Remote Command Execution: Suspicious Java class detected",
|
|
944013: "Potential Remote Command Execution: Log4j / Log4shell",
|
|
944015: "Base64 encoded string matched suspicious keyword",
|
|
944017: "Potential Remote Command Execution: Log4j / Log4shell",
|
|
944110: "Remote Command Execution: Java process spawn (CVE-2017-9805)",
|
|
944120: "Remote Command Execution: Java serialization (CVE-2015-4852)",
|
|
944130: "Suspicious Java class detected",
|
|
944140: "Java Injection Attack: Java Script File Upload Found",
|
|
944150: "Potential Remote Command Execution: Log4j / Log4shell",
|
|
944200: "Magic bytes Detected, probable java serialization in use",
|
|
944210: "Magic bytes Detected Base64 Encoded, probable java serialization in use",
|
|
944240: "Remote Command Execution: Java serialization (CVE-2015-4852)",
|
|
944250: "Remote Command Execution: Suspicious Java method detected",
|
|
944260: "Remote Command Execution: Malicious class-loading payload",
|
|
949052: "Inbound Anomaly Score Exceeded in phase 1 (Total Score: %{TX.BLOCKING_INBOUND_ANOMALY_SCORE})",
|
|
949110: "Inbound Anomaly Score Exceeded (Total Score: %{TX.BLOCKING_INBOUND_ANOMALY_SCORE})",
|
|
950010: "Directory Listing",
|
|
950013: "The Application Returned a 500-Level Status Code",
|
|
950140: "CGI source code leakage",
|
|
951010: "Microsoft Access SQL Information Leakage",
|
|
951120: "Oracle SQL Information Leakage",
|
|
951130: "DB2 SQL Information Leakage",
|
|
951140: "EMC SQL Information Leakage",
|
|
951150: "firebird SQL Information Leakage",
|
|
951160: "Frontbase SQL Information Leakage",
|
|
951170: "hsqldb SQL Information Leakage",
|
|
951180: "informix SQL Information Leakage",
|
|
951190: "ingres SQL Information Leakage",
|
|
951200: "interbase SQL Information Leakage",
|
|
951210: "maxDB SQL Information Leakage",
|
|
951220: "mssql SQL Information Leakage",
|
|
951230: "mysql SQL Information Leakage",
|
|
951240: "postgres SQL Information Leakage",
|
|
951250: "sqlite SQL Information Leakage",
|
|
951260: "Sybase SQL Information Leakage",
|
|
952010: "Java Source Code Leakage",
|
|
952110: "Java Errors",
|
|
953010: "PHP Information Leakage",
|
|
953013: "PHP Information Leakage",
|
|
953110: "PHP source code leakage",
|
|
953120: "PHP source code leakage",
|
|
954010: "Disclosure of IIS install location",
|
|
954110: "Application Availability Error",
|
|
954120: "IIS Information Leakage",
|
|
954130: "IIS Information Leakage",
|
|
955010: "Web shell detected",
|
|
955013: "webadmin.php file manager",
|
|
955110: "r57 web shell",
|
|
955120: "WSO web shell",
|
|
955130: "b4tm4n web shell",
|
|
955140: "Mini Shell web shell",
|
|
955150: "Ashiyane web shell",
|
|
955160: "Symlink_Sa web shell",
|
|
955170: "CasuS web shell",
|
|
955180: "GRP WebShell",
|
|
955190: "NGHshell web shell",
|
|
955200: "SimAttacker web shell",
|
|
955210: "Unknown web shell",
|
|
955220: "lama web shell",
|
|
955230: "lostDC web shell",
|
|
955240: "Unknown web shell",
|
|
955250: "Unknown web shell",
|
|
955260: "Ru24PostWebShell web shell",
|
|
955270: "s72 Shell web shell",
|
|
955280: "PhpSpy web shell",
|
|
955290: "g00nshell web shell",
|
|
955300: "PuNkHoLic shell web shell",
|
|
955310: "azrail web shell",
|
|
955320: "SmEvK_PaThAn Shell web shell",
|
|
955330: "Shell I web shell",
|
|
955340: "b374k m1n1 web shell",
|
|
959052: "Outbound Anomaly Score Exceeded in phase 3 (Total Score: %{tx.blocking_outbound_anomaly_score})",
|
|
959100: "Outbound Anomaly Score Exceeded (Total Score: %{tx.blocking_outbound_anomaly_score})",
|
|
980099: "Anomaly Scores: Inbound/Outbound anomaly score summary",
|
|
}
|
|
|
|
export function getRuleDescription(ruleId: number): string {
|
|
return CRS_RULES[ruleId] ?? `Rule ${ruleId} — see coreruleset.org for details`
|
|
} |