Re: Hidden Dir in URI

2010-03-13 Thread Ned Slider
John Hardin wrote: On Mon, 8 Mar 2010, Ned Slider wrote: John Hardin wrote: On Mon, 8 Mar 2010, Ned Slider wrote: > > So I've refined the rule to specifically exclude hitting on the > sequence ../. which stops the rule triggering on multiple relative > paths. > > uriLOCAL_URI_H

Re: Hidden Dir in URI

2010-03-13 Thread John Hardin
On Mon, 8 Mar 2010, Ned Slider wrote: John Hardin wrote: On Mon, 8 Mar 2010, Ned Slider wrote: > > So I've refined the rule to specifically exclude hitting on the > sequence ../. which stops the rule triggering on multiple relative > paths. > > uriLOCAL_URI_HIDDEN_DIR/(?!.{

Re: Hidden Dir in URI (Was: FreeMail plugin updated - banks)

2010-03-08 Thread John Hardin
On Mon, 8 Mar 2010, Ned Slider wrote: John Hardin wrote: On Mon, 8 Mar 2010, Ned Slider wrote: > > So I've refined the rule to specifically exclude hitting on the sequence > ../. which stops the rule triggering on multiple relative paths. > > uriLOCAL_URI_HIDDEN_DIR/(?!.{6}\.

Re: Hidden Dir in URI (Was: FreeMail plugin updated - banks)

2010-03-08 Thread Ned Slider
John Hardin wrote: On Mon, 8 Mar 2010, Ned Slider wrote: So I've refined the rule to specifically exclude hitting on the sequence ../. which stops the rule triggering on multiple relative paths. uriLOCAL_URI_HIDDEN_DIR/(?!.{6}\.\.\/\..).{8}\/\../ How about: uri LOC

Re: Hidden Dir in URI (Was: FreeMail plugin updated - banks)

2010-03-08 Thread John Hardin
On Mon, 8 Mar 2010, Ned Slider wrote: Adam Katz wrote: > > On 15-May-2009, at 12:46, Adam Katz wrote: > > > uri URI_HIDDEN /.{7}\/\../ LuKreme wrote: > > That won't catch > > http://www.spammer.example.com/.../hidden-malware.asf, it will only > > catch the relative url form "../path/to/c

Re: Hidden Dir in URI (Was: FreeMail plugin updated - banks)

2010-03-08 Thread Ned Slider
Adam Katz wrote: On 15-May-2009, at 12:46, Adam Katz wrote: uri URI_HIDDEN /.{7}\/\../ LuKreme wrote: That won't catch http://www.spammer.example.com/.../hidden-malware.asf, it will only catch the relative url form "../path/to/content" which SA improperly prefaces with "http://"; uri URI_HID