LFI and Path Traversal Attack in HTTP URI

This rule detects HTTP requests attempting to perform Local File Inclusion (LFI) or path traversal attacks by searching for patterns such as '/../' sequences and common sensitive file paths like /etc/passwd, /etc/shadow, or /proc/self/environ in the URI.