Skip to content

What it blocks

Command and code injection

Someone tries to run their own commands on your server.

What it is

Shell commands or program code sent as input, hoping the server runs it.

  • ; cat /etc/passwd after a file name
  • PHP code in an upload's name
  • A crafted object that runs code when the site reads it

Why it matters

When it works, the attacker controls the server and everything on it.

When it stops a real visitor

This can catch real text about programming, or a tool of yours that sends commands on purpose. Mark the request as real and that one field is let through.

What you will see most

The request contained shell commands.
The input included commands for the server's command line.
The request contained PHP code.
The input included the opening tag of a PHP program.
All 45 rules in this kind, as the rule set names them

For your web person. OWASP Core Rule Set 4.25.0, paranoia level 1.

  • 932120Remote Command Execution: Windows PowerShell Command Found
  • 932125Remote Command Execution: Windows Powershell Alias Command Injection
  • 932130Remote Command Execution: Unix Shell Expression Found
  • 932140Remote Command Execution: Windows FOR/IF Command Found
  • 932160Remote Command Execution: Unix Shell Code Found
  • 932170Remote Command Execution: Shellshock (CVE-2014-6271)
  • 932171Remote Command Execution: Shellshock (CVE-2014-6271)
  • 932175Remote Command Execution: Unix shell alias invocation
  • 932180Restricted File Upload Attempt
  • 932230Remote Command Execution: Unix Command Injection (2-3 chars)
  • 932235Remote Command Execution: Unix Command Injection (command without evasion)
  • 932250Remote Command Execution: Direct Unix Command Execution
  • 932260Remote Command Execution: Direct Unix Command Execution
  • 932270Remote Command Execution: Unix Shell Expression Found
  • 932280Remote Command Execution: Brace Expansion Found
  • 932330Remote Command Execution: Unix shell history invocation
  • 932340Remote Command Execution: Direct Unix Command Execution (No Arguments)
  • 932370Remote Command Execution: Windows Command Injection
  • 932380Remote Command Execution: Windows Command Injection
  • 933100PHP Injection Attack: PHP Open Tag Found
  • 933110PHP Injection Attack: PHP Script File Upload Found
  • 933120PHP Injection Attack: Configuration Directive Found
  • 933130PHP Injection Attack: Variables Found
  • 933135PHP Injection Attack: Variable Access Found
  • 933140PHP Injection Attack: I/O Stream Found
  • 933150PHP Injection Attack: High-Risk PHP Function Name Found
  • 933160PHP Injection Attack: High-Risk PHP Function Call Found
  • 933170PHP Injection Attack: Serialized Object Injection
  • 933180PHP Injection Attack: Variable Function Call Found
  • 933200PHP Injection Attack: Wrapper scheme detected
  • 933210PHP Injection Attack: Variable Function Call Found
  • 933220PHP Injection Attack: PHP Session File Upload Attempt
  • 934100Node.js Injection Attack 1/2
  • 934110Possible Server Side Request Forgery (SSRF) Attack: Cloud provider metadata URL in Parameter
  • 934130JavaScript Prototype Pollution
  • 934150Ruby Injection Attack
  • 934160Node.js DoS attack
  • 934170PHP data scheme attack
  • 934190Possible Server Side Request Forgery (SSRF) Attack: Scheme-less localhost or internal hostname detected
  • 944011Remote Command Execution: Suspicious Java class detected
  • 944110Remote Command Execution: Java process spawn (CVE-2017-9805)
  • 944120Remote Command Execution: Java serialization (CVE-2015-4852)
  • 944130Suspicious Java class detected
  • 944140Java Injection Attack: Java Script File Upload Found
  • 944150Potential Remote Command Execution: Log4j / Log4shell