Other free sources from suricata IDS:
WAF:
The later contains things XSS/SQL injection like union select or (\|\| || OR || AND) 1==1
.... and many more which are missing from the current list (but less CMS-specific rules).
Don't you think that supporting/converting rules from owasp-modsecurity-crs would be a nicer long-term strategy. That way new rules provided there could automatically be used by fail2ban?
Other free sources from suricata IDS:
WAF:
The later contains things XSS/SQL injection like
union selector(\|\| || OR || AND) 1==1.... and many more which are missing from the current list (but less CMS-specific rules).
Don't you think that supporting/converting rules from
owasp-modsecurity-crswould be a nicer long-term strategy. That way new rules provided there could automatically be used by fail2ban?