@@ -3,13 +3,13 @@ filter:
33 or :
44 - request_payload :
55 regex :
6- - " (?i)(?:<|%3[cC]|�*3[cC];|�*60;)[^>\\ n]{0,250}?\\ s+on[a-z0-9._-]{2,30}\\ s*=|<\\ s*(?:script|object| embed|svg|meta(?=[^>]*http-equiv\\ s*=\\ s*[\" ']?refresh)|iframe(?=[^>]*\\ bsrc\\ s*=\\ s*(?:[\" '])?\\ s*(?:javascript:|data:))|link(?=[^>]*\\ bhref\\ s*=\\ s*(?:[\" '])?\\ s*data:text/html))\\ b[^>]*>|style\\ s*=\\ s*[\" '][^\" '>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)[^\" '>]*[\" ']?|<\\ s*style\\ b[^>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)|<script[^>]*\\ bsrc\\ s*=\\ s*([\" '])?data:|\\ b(?:href|src)\\ s*=\\ s*(?:[\" '])?\\ s*javascript:\\ s*(?!;|void\\ s*\\ (\\ s*0\\ s*\\ )|void\\ s*0\\ b)|\\ bdata:text/html|[\" '\\ -\\\\\\ s;\\ (]*(?:alert\\ s*\\ (|prompt\\ s*\\ (|confirm\\ s*\\ (|eval\\ s*\\ ()[\" '\\ -\\\\\\ s;\\ (]*|document\\ .(?:cookie|domain)|location\\ .href|window\\ .location|(?:�*3c;|�*60;)"
6+ - " (?i)(?:<|%3[cC]|�*3[cC];|�*60;)[^>\\ n]{0,250}?\\ s+on[a-z0-9._-]{2,30}\\ s*=|<\\ s*(?:script|embed|svg|meta(?=[^>]*http-equiv\\ s*=\\ s*[\" ']?refresh)|iframe(?=[^>]*\\ bsrc\\ s*=\\ s*(?:[\" '])?\\ s*(?:javascript:|data:))|link(?=[^>]*\\ bhref\\ s*=\\ s*(?:[\" '])?\\ s*data:text/html))\\ b[^>]*>|style\\ s*=\\ s*[\" '][^\" '>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)[^\" '>]*[\" ']?|<\\ s*style\\ b[^>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)|<script[^>]*\\ bsrc\\ s*=\\ s*([\" '])?data:|\\ b(?:href|src)\\ s*=\\ s*(?:[\" '])?\\ s*javascript:\\ s*(?!;|void\\ s*\\ (\\ s*0\\ s*\\ )|void\\ s*0\\ b)|\\ bdata:text/html|[\" '\\ -\\\\\\ s;\\ (]*(?:alert\\ s*\\ (|prompt\\ s*\\ (|confirm\\ s*\\ (|eval\\ s*\\ ()[\" '\\ -\\\\\\ s;\\ (]*|document\\ .(?:cookie|domain)|location\\ .href|window\\ .location|(?:�*3c;|�*60;)"
77 - query_param :
88 regex :
9- - " (?i)(?:<|%3[cC]|�*3[cC];|�*60;)[^>\\ n]{0,250}?\\ s+on[a-z0-9._-]{2,30}\\ s*=|<\\ s*(?:script|object| embed|svg|meta(?=[^>]*http-equiv\\ s*=\\ s*[\" ']?refresh)|iframe(?=[^>]*\\ bsrc\\ s*=\\ s*(?:[\" '])?\\ s*(?:javascript:|data:))|link(?=[^>]*\\ bhref\\ s*=\\ s*(?:[\" '])?\\ s*data:text/html))\\ b[^>]*>|style\\ s*=\\ s*[\" '][^\" '>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)[^\" '>]*[\" ']?|<\\ s*style\\ b[^>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)|<script[^>]*\\ bsrc\\ s*=\\ s*([\" '])?data:|\\ b(?:href|src)\\ s*=\\ s*(?:[\" '])?\\ s*javascript:\\ s*(?!;|void\\ s*\\ (\\ s*0\\ s*\\ )|void\\ s*0\\ b)|\\ bdata:text/html|[\" '\\ -\\\\\\ s;\\ (]*(?:alert\\ s*\\ (|prompt\\ s*\\ (|confirm\\ s*\\ (|eval\\ s*\\ ()[\" '\\ -\\\\\\ s;\\ (]*|document\\ .(?:cookie|domain)|location\\ .href|window\\ .location|(?:�*3c;|�*60;)"
9+ - " (?i)(?:<|%3[cC]|�*3[cC];|�*60;)[^>\\ n]{0,250}?\\ s+on[a-z0-9._-]{2,30}\\ s*=|<\\ s*(?:script|embed|svg|meta(?=[^>]*http-equiv\\ s*=\\ s*[\" ']?refresh)|iframe(?=[^>]*\\ bsrc\\ s*=\\ s*(?:[\" '])?\\ s*(?:javascript:|data:))|link(?=[^>]*\\ bhref\\ s*=\\ s*(?:[\" '])?\\ s*data:text/html))\\ b[^>]*>|style\\ s*=\\ s*[\" '][^\" '>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)[^\" '>]*[\" ']?|<\\ s*style\\ b[^>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)|<script[^>]*\\ bsrc\\ s*=\\ s*([\" '])?data:|\\ b(?:href|src)\\ s*=\\ s*(?:[\" '])?\\ s*javascript:\\ s*(?!;|void\\ s*\\ (\\ s*0\\ s*\\ )|void\\ s*0\\ b)|\\ bdata:text/html|[\" '\\ -\\\\\\ s;\\ (]*(?:alert\\ s*\\ (|prompt\\ s*\\ (|confirm\\ s*\\ (|eval\\ s*\\ ()[\" '\\ -\\\\\\ s;\\ (]*|document\\ .(?:cookie|domain)|location\\ .href|window\\ .location|(?:�*3c;|�*60;)"
1010 - request_headers :
1111 regex :
12- - " (?i)(?:<|%3[cC]|�*3[cC];|�*60;)[^>\\ n]{0,250}?\\ s+on[a-z0-9._-]{2,30}\\ s*=|<\\ s*(?:script|object| embed|svg|meta(?=[^>]*http-equiv\\ s*=\\ s*[\" ']?refresh)|iframe(?=[^>]*\\ bsrc\\ s*=\\ s*(?:[\" '])?\\ s*(?:javascript:|data:))|link(?=[^>]*\\ bhref\\ s*=\\ s*(?:[\" '])?\\ s*data:text/html))\\ b[^>]*>|style\\ s*=\\ s*[\" '][^\" '>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)[^\" '>]*[\" ']?|<\\ s*style\\ b[^>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)|<script[^>]*\\ bsrc\\ s*=\\ s*([\" '])?data:|\\ b(?:href|src)\\ s*=\\ s*(?:[\" '])?\\ s*javascript:\\ s*(?!;|void\\ s*\\ (\\ s*0\\ s*\\ )|void\\ s*0\\ b)|\\ bdata:text/html|[\" '\\ -\\\\\\ s;\\ (]*(?:alert\\ s*\\ (|prompt\\ s*\\ (|confirm\\ s*\\ (|eval\\ s*\\ ()[\" '\\ -\\\\\\ s;\\ (]*|document\\ .(?:cookie|domain)|location\\ .href|window\\ .location|(?:�*3c;|�*60;)"
12+ - " (?i)(?:<|%3[cC]|�*3[cC];|�*60;)[^>\\ n]{0,250}?\\ s+on[a-z0-9._-]{2,30}\\ s*=|<\\ s*(?:script|embed|svg|meta(?=[^>]*http-equiv\\ s*=\\ s*[\" ']?refresh)|iframe(?=[^>]*\\ bsrc\\ s*=\\ s*(?:[\" '])?\\ s*(?:javascript:|data:))|link(?=[^>]*\\ bhref\\ s*=\\ s*(?:[\" '])?\\ s*data:text/html))\\ b[^>]*>|style\\ s*=\\ s*[\" '][^\" '>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)[^\" '>]*[\" ']?|<\\ s*style\\ b[^>]*\\ b(?:expression|url\\ s*\\ (\\ s*['\" ]?\\ s*javascript:)|<script[^>]*\\ bsrc\\ s*=\\ s*([\" '])?data:|\\ b(?:href|src)\\ s*=\\ s*(?:[\" '])?\\ s*javascript:\\ s*(?!;|void\\ s*\\ (\\ s*0\\ s*\\ )|void\\ s*0\\ b)|\\ bdata:text/html|[\" '\\ -\\\\\\ s;\\ (]*(?:alert\\ s*\\ (|prompt\\ s*\\ (|confirm\\ s*\\ (|eval\\ s*\\ ()[\" '\\ -\\\\\\ s;\\ (]*|document\\ .(?:cookie|domain)|location\\ .href|window\\ .location|(?:�*3c;|�*60;)"
1313
1414info :
1515 name : " XSS"
0 commit comments