如何在.htaccess文件里设置拦截post攻击

 

在.htaccess文件里面加

 

# Enable ModSecurity

SecFilterEngine On

# Reject requests with status 403

SecFilterDefaultAction “deny,log,status:403”

# Require Content-Length to be provided with

# every POST request

SecFilterSelective REQUEST_METHOD “^POST$” chain

SecFilterSelective HTTP_Content-Length “^$”