Skip to content

What it blocks

Command and code injection

Someone tries to run their own commands on your server.

What it is

Shell commands or program code sent as input, hoping the server runs it.

  • ; cat /etc/passwd after a file name
  • PHP code in an upload's name
  • A crafted object that runs code when the site reads it

Why it matters

When it works, the attacker controls the server and everything on it.

If a real visitor is ever stopped

This can catch real text about programming, or a tool of yours that sends commands on purpose. Mark the request as real and that one field is let through.