Stripped and neutralized markup preventing SSI evaluation on Apache, Nginx, and IIS engines.
<!-- Loading sanitized output... -->
1. Web Server Hardening
Disable Server-Side Includes globally or disallow the #exec directive in Apache/Nginx virtual hosts:
# Apache HTTP Server (httpd.conf or .htaccess) # Disable SSI execution entirely: Options -Includes # OR allow file inclusions but strictly forbid execution of shell commands: Options +IncludesNOEXEC # ------------------------------------------------------------- # Nginx (nginx.conf) # SSI is disabled by default in Nginx unless explicitly turned on. ssi off; # If SSI is required for legacy fragments, ensure ssi_silent_errors is off # and never pass untrusted client parameters into SSI buffers: ssi_types text/html;
2. ModSecurity WAF Rule (CRS Pattern)
# OWASP ModSecurity Core Rule Set pattern for SSI Injection
SecRule REQUEST_COOKIES|REQUEST_COOKIES_NAMES|REQUEST_FILENAME|ARGS_NAMES|ARGS|XML:/* "@rx <!--\s*#(?:include|exec|echo|config|printenv)\b" \
"id:942510,\
phase:2,\
block,\
capture,\
t:none,t:urlDecodeUni,t:normalizePath,t:lowercase,\
msg:'Server-Side Includes (SSI) Injection Attack Detected',\
logdata:'Matched Data: %{TX.0} found within %{MATCHED_VAR_NAME}',\
tag:'application-multi',\
tag:'language-multi',\
tag:'platform-multi',\
tag:'attack-ssi-injection',\
severity:'CRITICAL'"