Important: The following are free for non commercial use.
This means you can download and use them as an end user only. Any commercial use of those rules is prohibited without the consent of the organization.




 001-upload.conf This rule controls the user's ability to upload files to the site.
 002-SQLInjection.conf These rules filter out attempts to inject unauthorized SQL statements into request parameters.
 003-XSS.conf These rules filter out attempts to inject unauthorized scripts into request parameters.
 004-pathTraversal.conf These rules filter out attempts to illegally navigate through the host system.
 005-requestValidation.conf These rules filter out attempts to establish a connection through non-standard user agents.
 006-probes.conf These rules filter out attempts to probe the host for system information.



(c) 2005-2006 WebSecurityAuthority.org
ModSecurity and mod_security are trademarks of Thinking Stone Ltd (http://www.thinkingstone.com)
For more information or enquires please send us an email at info@WebSecurityAuthority.org