summaryrefslogtreecommitdiff
path: root/config
diff options
context:
space:
mode:
authorjvoisin2018-07-23 14:57:55 +0200
committerjvoisin2018-07-23 14:57:55 +0200
commita40c6c11be746af62e90eb871c108008d7f91c1d (patch)
tree9cd0b9a5ac5b322d21da024428251706554456ab /config
parent81849ac95837d343064a4989eb8d00a87bf02b2d (diff)
Allow the inclusion of `.inc` files
Diffstat (limited to 'config')
-rw-r--r--config/default.rules8
1 files changed, 4 insertions, 4 deletions
diff --git a/config/default.rules b/config/default.rules
index b16434f..6cc67e6 100644
--- a/config/default.rules
+++ b/config/default.rules
@@ -17,10 +17,10 @@ sp.disable_function.function("mail").param("additional_parameters").value_r("\\-
17sp.disable_function.function("putenv").param("setting").value_r("LD_").drop() 17sp.disable_function.function("putenv").param("setting").value_r("LD_").drop()
18 18
19##Prevent various `include`-related vulnerabilities 19##Prevent various `include`-related vulnerabilities
20sp.disable_function.function("require_once").value_r("\.php$").allow(); 20sp.disable_function.function("require_once").value_r("\.(php|inc)$").allow();
21sp.disable_function.function("include_once").value_r("\.php$").allow(); 21sp.disable_function.function("include_once").value_r("\.(php|inc)$").allow();
22sp.disable_function.function("require").value_r("\.php$").allow(); 22sp.disable_function.function("require").value_r("\.(php|inc)$").allow();
23sp.disable_function.function("include").value_r("\.php$").allow(); 23sp.disable_function.function("include").value_r("\.(php|inc)$").allow();
24sp.disable_function.function("require_once").drop() 24sp.disable_function.function("require_once").drop()
25sp.disable_function.function("include_once").drop() 25sp.disable_function.function("include_once").drop()
26sp.disable_function.function("require").drop() 26sp.disable_function.function("require").drop()