Current Path : /usr/share/modsecurity-crs/util/regexp-assemble/ |
Current File : //usr/share/modsecurity-crs/util/regexp-assemble/regexp-932110.txt |
# Word list for rule 932110 (RCE Windows command injection part 1/2) # # To convert to a regexp that can be pasted into the rule: # cat regexp-932110.txt | ./regexp-cmdline.py windows | ./regexp-assemble.pl # # Entries starting with ' are used verbatim. # Everything after # is a comment. # # To prevent some FP for a command, you can require command parameters # after a command. Only do this if the command regularly causes FP and if # allowing the bare command (without parameters) is not too dangerous. # (Note: due to \b following the regexp, a word boundary is also required # further on, so some letter/number is needed for a match). Example: # # diff@ 7z 7za 7zr addusers admodcmd arp@ assoc attrib azman bcdboot bcdedit bitsadmin bootcfg browstat cacls call@ certreq certutil #disabled for FP: change chdir@ chkdsk chkntfs cipher cleanmgr clearmem cluster cmd cmdkey comexp comp@ compact@ compmgmt con2prt convert copy csccmd cscript csvde curl date@ dcomcnfg debug defrag del@ delprof deltree devcon devmgmt diff@ dir@ diruse diskmgmt diskpart diskshadow dnsstat doskey driverquery dsacls dsadd dsget dsmod dsmove dsquery dsrm dxdiag echo egrep endlocal erase eventcreate eventvwr expand@ explorer fc@ fgrep find@ findstr foreach forfiles format@ freedisk fsmgmt fsutil ftp@ ftype gathernetworkinfo getmac git@ gpedit gpresult gpupdate hdwwiz hostname icacls ifmember inetcpl ipconfig irb irb1 irb18 irb19 irb20 irb21 irb22 java@ label@ logevent logman logoff logtime lusrmgr mapisend mbsacli md@ mdsched measure mkdir@ mklink mmsys mode@ more@ mount@ mountvol moveuser msconfig msg@ msiexec msinfo32 mstsc mysql mysqladmin mysqldump mysqldumpslow mysqlhotcopy mysqlshow nbtstat nc@ ncat net@ netcat netdom netsh netstat netsvc nmap nslookup ntbackup ntrights