File: //usr/local/cwaf/rules/15_Outgoing_FilterASP.conf
# ---------------------------------------------------------------
# Comodo ModSecurity Rules
# Copyright (C) 2022 Comodo Security solutions All rights reserved.
#
# The COMODO SECURITY SOLUTIONS Mod Security Rule Set is distributed under
# THE COMODO SECURITY SOLUTIONS END USER LICENSE AGREEMENT,
# Please see the enclosed LICENCE file for full details.
# ---------------------------------------------------------------
# This is a FILE CONTAINING CHANGED or MODIFIED RULES FROM THE:
# OWASP ModSecurity Core Rule Set (CRS)
# ---------------------------------------------------------------
SecRule RESPONSE_BODY "(?:\b(?:javax\.servlet|(?:s(?:cripting\.filesystemobject|erver\.(?:createobject|mappath|(?:execut|(?:htm|ur)lencod)e))|wscript\.(?:network|shell)|(?:response\.(?:binary){0,1}writ|vbscript\.encod)e)\b)|\.(?:addheader|(?:loadfrom|(?:createtex|ge)t)file)\b|<jsp:)" \
"id:214610,msg:'COMODO WAF: ASP/JSP source code leakage||%{tx.domain}|%{tx.mode}|3',phase:4,capture,block,setvar:'tx.outgoing_points=+%{tx.points_limit3}',setvar:'tx.points=+%{tx.points_limit3}',logdata:'Matched Data: %{TX.0} found within %{MATCHED_VAR_NAME}: %{MATCHED_VAR}',ctl:auditLogParts=+E,t:none,rev:1,severity:3,tag:'CWAF',tag:'FilterASP'"