Skip to content

Commit 886d451

Browse files
authored
Update discovery_web_server_local_file_inclusion_activity.toml
1 parent ff9b153 commit 886d451

File tree

1 file changed

+23
-23
lines changed

1 file changed

+23
-23
lines changed

rules/cross-platform/discovery_web_server_local_file_inclusion_activity.toml

Lines changed: 23 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -45,35 +45,35 @@ from
4545
4646
| where
4747
/* 1) Relative traversal */
48-
Esql.url_original_url_decoded_to_lower like "*../../../../*" or // Unix-style traversal
49-
Esql.url_original_url_decoded_to_lower like "*..\\\\..\\\\..\\\\..*" or // Windows-style traversal
50-
// Potential security check bypassing (enforcing multiple dots and shortening the pattern)
51-
Esql.url_original_url_decoded_to_lower like "*..././*" or
52-
Esql.url_original_url_decoded_to_lower like "*...\\*" or
53-
Esql.url_original_url_decoded_to_lower like "*....\\*" or
48+
Esql.url_original_url_decoded_to_lower like "*../../../../*" or // Unix-style traversal
49+
Esql.url_original_url_decoded_to_lower like "*..\\\\..\\\\..\\\\..*" or // Windows-style traversal
50+
// Potential security check bypassing (enforcing multiple dots and shortening the pattern)
51+
Esql.url_original_url_decoded_to_lower like "*..././*" or
52+
Esql.url_original_url_decoded_to_lower like "*...\\*" or
53+
Esql.url_original_url_decoded_to_lower like "*....\\*" or
5454
5555
/* 2) Linux system identity / basic info */
56-
Esql.url_original_url_decoded_to_lower like "*etc/passwd*" or
57-
Esql.url_original_url_decoded_to_lower like "*etc/shadow*" or
58-
Esql.url_original_url_decoded_to_lower like "*etc/hosts*" or
59-
Esql.url_original_url_decoded_to_lower like "*etc/os-release*" or
60-
Esql.url_original_url_decoded_to_lower like "*etc/issue*" or
56+
Esql.url_original_url_decoded_to_lower like "*etc/passwd*" or
57+
Esql.url_original_url_decoded_to_lower like "*etc/shadow*" or
58+
Esql.url_original_url_decoded_to_lower like "*etc/hosts*" or
59+
Esql.url_original_url_decoded_to_lower like "*etc/os-release*" or
60+
Esql.url_original_url_decoded_to_lower like "*etc/issue*" or
6161
6262
/* 3) Linux /proc enumeration */
63-
Esql.url_original_url_decoded_to_lower like "*proc/self/environ*" or
64-
Esql.url_original_url_decoded_to_lower like "*proc/self/cmdline*" or
65-
Esql.url_original_url_decoded_to_lower like "*proc/self/fd*" or
66-
Esql.url_original_url_decoded_to_lower like "*proc/self/exe*" or
63+
Esql.url_original_url_decoded_to_lower like "*proc/self/environ*" or
64+
Esql.url_original_url_decoded_to_lower like "*proc/self/cmdline*" or
65+
Esql.url_original_url_decoded_to_lower like "*proc/self/fd*" or
66+
Esql.url_original_url_decoded_to_lower like "*proc/self/exe*" or
6767
6868
/* 4) Linux webroots, configs & logs */
69-
Esql.url_original_url_decoded_to_lower like "*var/www*" or // generic webroot
70-
Esql.url_original_url_decoded_to_lower like "*wp-config.php*" or // classic WP config
71-
Esql.url_original_url_decoded_to_lower like "*etc/apache2*" or
72-
Esql.url_original_url_decoded_to_lower like "*etc/httpd*" or
73-
Esql.url_original_url_decoded_to_lower like "*etc/nginx*" or
74-
Esql.url_original_url_decoded_to_lower like "*var/log/apache2*" or
75-
Esql.url_original_url_decoded_to_lower like "*var/log/httpd*" or
76-
Esql.url_original_url_decoded_to_lower like "*var/log/nginx*" or
69+
Esql.url_original_url_decoded_to_lower like "*var/www*" or // generic webroot
70+
Esql.url_original_url_decoded_to_lower like "*wp-config.php*" or // classic WP config
71+
Esql.url_original_url_decoded_to_lower like "*etc/apache2*" or
72+
Esql.url_original_url_decoded_to_lower like "*etc/httpd*" or
73+
Esql.url_original_url_decoded_to_lower like "*etc/nginx*" or
74+
Esql.url_original_url_decoded_to_lower like "*var/log/apache2*" or
75+
Esql.url_original_url_decoded_to_lower like "*var/log/httpd*" or
76+
Esql.url_original_url_decoded_to_lower like "*var/log/nginx*" or
7777
7878
/* 5) Windows core files / identity */
7979
Esql.url_original_url_decoded_to_lower like "*windows/panther/*unattend*" or

0 commit comments

Comments
 (0)