网络守护者物语:用 WAF 打跑坏蛋们的可爱冒险!

欢迎来到一个关于网络守护者的可爱冒险故事!在这片名为互联网的魔法世界中,我们的任务就是守护小镇不被各种坏蛋攻击哦~

用我们的 WAF(Web 应用防火墙)大剑,把坏蛋们统统赶跑!

完整规则可以直接复制

(http.request.uri.query contains ")/*") or 
(http.request.uri.query contains ")--") or 
(http.request.uri.query contains "benchmark(") or 
(http.request.uri.query contains "'0:0:20'") or 
(http.request.uri.query contains "MD5(") or 
(http.request.uri.query contains "%20waitfor%20delay%20") or 
(http.request.uri.query contains "%22") or 
(http.request.uri.query contains "%20/*") or 
(http.request.uri.query contains "%20--") or 
(http.request.uri.query contains "%20%23") or 
(http.request.uri.query contains ")%23") or 
(http.request.uri.query contains "script>") or 
(http.request.uri.query contains "%40") or 
(http.request.uri.query contains "%00") or 
(http.request.uri.query contains "<?php") or 
(http.request.uri.query contains "0x00") or 
(http.request.uri.query contains "0x08") or 
(http.request.uri.query contains "0x09") or 
(http.request.uri.query contains "0x0a") or 
(http.request.uri.query contains "0x0d") or 
(http.request.uri.query contains "0x1a") or 
(http.request.uri.query contains "0x22") or 
(http.request.uri.query contains "0x25") or 
(http.request.uri.query contains "0x27") or 
(http.request.uri.query contains "0x5c") or 
(http.request.uri.query contains "0x5f") or 
(http.request.uri.query contains "SELECT") or 
(http.request.uri.query contains "concat") or 
(http.request.uri.query contains "union") or 
(http.request.uri.query contains "0x50") or 
(http.request.uri.query contains "DROP") or 
(http.request.uri.query contains "WHERE") or 
(http.request.uri.query contains "ONION") or 
(http.request.uri.query contains "0x3c62723e3c62723e3c62723e") or 
(http.request.uri.query contains "0x3c696d67207372633d22") or 
(http.request.uri.query contains "OR") or 
(http.request.uri.query contains "0x3e") or 
(http.request.uri.query contains "<img") or 
(http.request.uri.query contains "<image") or 
(http.request.uri.query contains "document.cookie") or 
(http.request.uri.query contains "onerror()") or 
(http.request.uri.query contains "alert(") or 
(http.request.uri.query contains "window.") or 
(http.request.uri.query contains "String.fromCharCode(") or 
(http.request.uri.query contains "javascript:") or 
(http.request.uri.query contains "onmouseover=") or 
(http.request.uri.query contains "<BODY onload") or 
(http.request.uri.query contains "<style") or 
(http.request.uri.query contains "svg onload") or 
(http.request.uri.query contains "substring(") or 
(http.request.uri.query contains "length(") or 
(http.request.uri.query contains "version(") or 
(http.request.uri.query contains "database(") or 
(http.request.uri.query contains "user(") or 
(http.request.uri.query contains "AND 1=1") or 
(http.request.uri.query contains "AND 1=2") or 
(http.request.uri.query contains "OR 1=1") or 
(http.request.uri.query contains "OR 1=2") or 
(http.request.uri.query contains "%27OR1=1--") or 
(http.request.uri.query contains "UNION ALL SELECT") or 
(http.request.uri.query contains "/etc/passwd") or 
(http.request.uri.query contains "../../") or 
(http.request.uri.query contains "/proc/self/environ") or 
(http.request.uri.query contains "file=") or 
(http.request.uri.query contains "page=") or 
(http.request.uri.query contains "http://") or 
(http.request.uri.query contains "ftp://") or 
(http.request.uri.query contains "data://") or 
(http.request.uri.query contains "|cat") or 
(http.request.uri.query contains "&&") or 
(http.request.uri.query contains "||") or 
(http.request.uri.query contains "`") or 
(http.request.uri.query contains "$(") or 
(http.request.uri.query contains "ping") or 
(http.request.uri.query contains "curl") or 
(http.request.uri.query contains "wget") or 
(http.request.uri.query contains "%0d%0a") or 
(http.request.uri.query contains "%0a") or 
(http.request.uri.query contains "%0d") or 
(http.request.uri.query contains "phpinfo()") or 
(http.request.uri.query contains "hostname") or 
(http.request.uri.query contains "whoami") or 
(http.request.uri.query contains "uname -a") or 
(http.request.uri.query contains "pwd") or 
(http.request.uri.query contains "netstat")

 

 

 

第一关:SQL 注入魔王的骚扰

 

有一天,SQL 注入魔王突然出现在我们的网络小镇上,妄想用什么 SELECT 和 concat() 咒语来破坏数据库。

还试图用benchmark() 来偷偷搞破坏呢!

不怕!有我们 WAF 小骑士在,轻松挡住魔王的攻击:

(http.request.uri.query contains "SELECT") or 
(http.request.uri.query contains "union") or 
(http.request.uri.query contains "concat") or 
(http.request.uri.query contains "benchmark(")

哼哼,魔王的这些咒语被我们一下子封印掉啦!

然后它只能灰溜溜地逃回黑暗角落。我们的数据库宝库安全啦!

 

 

 

 

 

 

第二关:XSS 小妖精的恶作剧

 

接下来,是那些搞恶作剧的 XSS 小妖精!他们会偷偷在 URL 里插入 <script> 标签,试图偷看别人的小秘密,甚至搞破坏。

可惜,我们早已在城墙上布好了 WAF 魔法阵,嘻嘻,他们的恶作剧是进不来的哟~

(http.request.uri.query contains "script>") or 
(http.request.uri.query contains "document.cookie") or 
(http.request.uri.query contains "alert(") or 
(http.request.uri.query contains "onerror()")

那些调皮的妖精还没靠近城镇就被挡在外面啦!✧(≖ ◡ ≖) 我们的用户们依然可以安心浏览,没有坏坏的脚本乱跳出来捣乱啦!

 

 

 

 

 

 

 

第三关:路径遍历术士的诡计

 

这次来的是诡计多端的路径遍历术士。他们想通过一些路径,像什么 /etc/passwd 和 ../../ ,来试图进入我们的小镇核心。可是别忘了,我们的防御可不是一般的强哦!(ᴗ)و诡计术士的捷径被一层层魔法屏障挡住啦!

(http.request.uri.query contains "/etc/passwd") or 
(http.request.uri.query contains "../../") or 
(http.request.uri.query contains "/proc/self/environ")

他们根本进不去啦,只能无奈地离开。我们的小镇依旧是那么平静、安全!

 

 

 

 

 

 

 

 

 

第四关:命令注入黑骑士的末路

 

忽然出现了一群命令注入的黑骑士,带着他们的 curl 、 ping 和 MARKDOWN_HASHaf9d83836ecf1f49c598bcb1995b3c98MARKDOWNHASH 这样的攻击手段,想要控制我们的服务器!

别担心,有我们的 WAF 大剑,一剑斩断这些命令黑骑士的入侵!

(http.request.uri.query contains "curl") or 
(http.request.uri.query contains "ping") or 
(http.request.uri.query contains "wget") or 
(http.request.uri.query contains "&&") or 
(http.request.uri.query contains "||")

这些骑士被我们帅气地挡在了城墙之外,他们的命令根本无效!我们的服务器依旧在轻松运行中,所有人都对我们竖起了大拇指!

 

 

 

 

 

 

 

 

 

 

终极 BOSS:调皮的 CRLF 注入妖怪

 

最后,别忘了那些小妖怪们!他们会偷偷使用 phpinfo() 、 whoami 这样的命令,试图探测我们的系统信息。

可是我们已经用 WAF 的全知之眼看穿了这些诡计!

(http.request.uri.query contains "%0d%0a") or 
(http.request.uri.query contains "phpinfo()") or 
(http.request.uri.query contains "whoami")

抓到你们了!小妖怪们别想再调皮啦,这些诡计根本不管用!

 

 

 

 

 

 

 

 

最终篇章:我们的守护与胜利

 

每一位守护者的职责就是确保小镇的和平与安全。通过我们的 WAF 大剑,SQL 注入魔王、XSS 小妖精、路径遍历术士、命令注入黑骑士和调皮的 CRLF 妖怪都被我们一一打败了!

 

这场守护战虽然艰辛,但每个防御规则都是我们守护小镇的必备技能!你也可以加入这场冒险,将这些 WAF 规则放在你的网络中,守护你自己的小镇不被坏蛋攻击哦!

 

用 WAF 的力量,保护网络世界的和平吧!

 

别让那些坏蛋破坏我们的城镇,继续勇敢守护下去吧!

 

 

 

 

未经允许不得转载:泥人传说 » 网络守护者物语:用 WAF 打跑坏蛋们的可爱冒险!
分享到:
赞(0)

评论抢沙发

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址