On this page

Atomicorp WAF Rule 390907

Rule Summary

  • Rule ID: 390907
  • Status: Retired
  • Alert message: Atomicorp.com WAF Rules: Possible Shell Command Attempt
  • Observed CWEs: None documented

Description

This rules detects when shell commands and raw code are injected into a request.

Troubleshooting

False Positives

This rule may produce a false positive if an application allows the use of shell commands or raw code in a safe and secure manner. The rules contain a large library of known trusted methods, however it is possible an application may be using a previously untested method. It is not recommended that you disable this rule if you have a false positive. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

Tuning Guidance

See the Mod_security page for guidance on tuning this rule.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 390907
  • Source revision: 3118
  • Source revision date: 2013-01-22