8000 fix: detect IXMZUXBG by theseion · Pull Request #3130 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

fix: detect IXMZUXBG #3130

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Feb 19, 2023
Merged

fix: detect IXMZUXBG #3130

merged 1 commit into from
Feb 19, 2023

Conversation

theseion
Copy link
Contributor
@theseion theseion commented Feb 19, 2023

Detect logical operators in shell commands; necessary for header injection detection.

This commit also update the evasion suffix used by the cmdline processor.

detect logical operators in shell commands; necessary for header
injection detection
@theseion theseion marked this pull request as ready for review February 19, 2023 15:50
@theseion theseion requested a review from dune73 February 19, 2023 15:50
@theseion theseion merged commit 5dd7f3c into coreruleset:v4.0/dev Feb 19, 2023
@theseion theseion deleted the fix-IXMZUXBG branch February 19, 2023 16:06
@dune73
Copy link
Member
dune73 commented Feb 19, 2023

Looks good to me. Thank you.

How likely are FPs here in your view?

@theseion
Copy link
Contributor Author

Not very. A match requires one of the known command words, immediately followed by & or |. Not more prone to FP as command word + space IMO.

@dune73
Copy link
Member
dune73 commented Feb 19, 2023

Thank you. This was just for the record.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants
0