summaryrefslogtreecommitdiff
path: root/config/default.rules
diff options
context:
space:
mode:
authorjvoisin2018-03-05 14:25:25 +0100
committerjvoisin2018-03-05 14:25:25 +0100
commit309481168de02f2dee5a4266359d72866442f665 (patch)
treeec87f191cb58bcf0dd02bf7478caa9f43b16ddf9 /config/default.rules
parent695f30817ecff47b5a556a79df2ba00fd8fd539e (diff)
Improve a bit the performances (+10%)
Diffstat (limited to 'config/default.rules')
-rw-r--r--config/default.rules12
1 files changed, 8 insertions, 4 deletions
diff --git a/config/default.rules b/config/default.rules
index 7e3ee53..a5ea3d1 100644
--- a/config/default.rules
+++ b/config/default.rules
@@ -8,10 +8,14 @@ sp.disable_function.function("mail").param("additional_parameters").value_r("\\-
8sp.disable_function.function("putenv").param("setting").value_r("LD_").drop() 8sp.disable_function.function("putenv").param("setting").value_r("LD_").drop()
9 9
10##Prevent various `include`-related vulnerabilities 10##Prevent various `include`-related vulnerabilities
11sp.disable_function.function_r("^(?:require|include)_once$").value_r("\\.(?:php|php7|inc|tpl)$").allow(); 11sp.disable_function.function("require_once").value_r("\.php$").allow();
12sp.disable_function.function_r("^require|include$").value_r("\\.(?:php|php7|inc|tpl)$").allow(); 12sp.disable_function.function("include_once").value_r("\.php$").allow();
13sp.disable_function.function_r("^(?:require|include)_once$").drop(); 13sp.disable_function.function("require").value_r("\.php$").allow();
14sp.disable_function.function_r("^require|include$").drop(); 14sp.disable_function.function("include").value_r("\.php$").allow();
15sp.disable_function.function("require_once").drop()
16sp.disable_function.function("include_once").drop()
17sp.disable_function.function("require").drop()
18sp.disable_function.function("include").drop()
15 19
16# Prevent `system`-related injections 20# Prevent `system`-related injections
17sp.disable_function.function("system").param("command").value_r("[$|;&`\\n]").drop(); 21sp.disable_function.function("system").param("command").value_r("[$|;&`\\n]").drop();