summaryrefslogtreecommitdiff
path: root/config
diff options
context:
space:
mode:
Diffstat (limited to 'config')
-rw-r--r--config/default.rules16
1 files changed, 8 insertions, 8 deletions
diff --git a/config/default.rules b/config/default.rules
index 82f8b5d..dc749e5 100644
--- a/config/default.rules
+++ b/config/default.rules
@@ -66,16 +66,16 @@ sp.disable_function.function("exec").param("command").value_r("[$|;&`\\n\\(\\)\\
66sp.disable_function.function("proc_open").param("command").value_r("[$|;&`\\n\\(\\)\\\\]").drop(); 66sp.disable_function.function("proc_open").param("command").value_r("[$|;&`\\n\\(\\)\\\\]").drop();
67 67
68# Prevent runtime modification of interesting things 68# Prevent runtime modification of interesting things
69sp.disable_function.function("ini_set").param("var_name").value("assert.active").drop(); 69sp.disable_function.function("ini_set").param("varname").value("assert.active").drop();
70sp.disable_function.function("ini_set").param("var_name").value("zend.assertions").drop(); 70sp.disable_function.function("ini_set").param("varname").value("zend.assertions").drop();
71sp.disable_function.function("ini_set").param("var_name").value("memory_limit").drop(); 71sp.disable_function.function("ini_set").param("varname").value("memory_limit").drop();
72sp.disable_function.function("ini_set").param("var_name").value("include_path").drop(); 72sp.disable_function.function("ini_set").param("varname").value("include_path").drop();
73sp.disable_function.function("ini_set").param("var_name").value("open_basedir").drop(); 73sp.disable_function.function("ini_set").param("varname").value("open_basedir").drop();
74 74
75# Detect some backdoors via environnement recon 75# Detect some backdoors via environnement recon
76sp.disable_function.function("ini_get").param("var_name").value("allow_url_fopen").drop(); 76sp.disable_function.function("ini_get").param("varname").value("allow_url_fopen").drop();
77sp.disable_function.function("ini_get").param("var_name").value("open_basedir").drop(); 77sp.disable_function.function("ini_get").param("varname").value("open_basedir").drop();
78sp.disable_function.function("ini_get").param("var_name").value_r("suhosin").drop(); 78sp.disable_function.function("ini_get").param("varname").value_r("suhosin").drop();
79sp.disable_function.function("function_exists").param("function_name").value("eval").drop(); 79sp.disable_function.function("function_exists").param("function_name").value("eval").drop();
80sp.disable_function.function("function_exists").param("function_name").value("exec").drop(); 80sp.disable_function.function("function_exists").param("function_name").value("exec").drop();
81sp.disable_function.function("function_exists").param("function_name").value("system").drop(); 81sp.disable_function.function("function_exists").param("function_name").value("system").drop();