Your IP : 216.73.216.95


Current Path : /usr/share/modsecurity-crs.bk/util/regexp-assemble/
Upload File :
Current File : //usr/share/modsecurity-crs.bk/util/regexp-assemble/regexp-932110.txt

# Word list for rule 932110 (RCE Windows command injection part 1/2)
#
# To convert to a regexp that can be pasted into the rule:
#   cat regexp-932110.txt | ./regexp-cmdline.py windows | ./regexp-assemble.pl
#
# Entries starting with ' are used verbatim.
# Everything after # is a comment.
#
# To prevent some FP for a command, you can require command parameters
# after a command. Only do this if the command regularly causes FP and if
# allowing the bare command (without parameters) is not too dangerous.
# (Note: due to \b following the regexp, a word boundary is also required
# further on, so some letter/number is needed for a match). Example:
#
#   diff@

7z
7za
7zr
addusers
admodcmd
arp@
assoc
attrib
azman
bcdboot
bcdedit
bitsadmin
bootcfg
browstat
cacls
call@
certreq
certutil
#disabled for FP: change
chdir@
chkdsk
chkntfs
cipher
cleanmgr
clearmem
cluster
cmd
cmdkey
comexp
comp@
compact@
compmgmt
con2prt
convert
copy
csccmd
cscript
csvde
curl
date@
dcomcnfg
debug
defrag
del@
delprof
deltree
devcon
devmgmt
diff@
dir@
diruse
diskmgmt
diskpart
diskshadow
dnsstat
doskey
driverquery
dsacls
dsadd
dsget
dsmod
dsmove
dsquery
dsrm
dxdiag
echo
egrep
endlocal
erase
eventcreate
eventvwr
exit
expand@
explorer
fc@
fgrep
find@
findstr
foreach
forfiles
format@
freedisk
fsmgmt
fsutil
ftp@
ftype
gathernetworkinfo
getmac
git@
gpedit
gpresult
gpupdate
hdwwiz
hostname
icacls
ifmember
inetcpl
ipconfig
irb
irb1
irb18
irb19
irb20
irb21
irb22
java@
label@
logevent
logman
logoff
logtime
lusrmgr
mapisend
mbsacli
md@
mdsched
measure
mkdir@
mklink
mmsys
mode@
more@
mount@
mountvol
moveuser
msconfig
msg@
msiexec
msinfo32
mstsc
mysql
mysqladmin
mysqldump
mysqldumpslow
mysqlhotcopy
mysqlshow
nbtstat
nc@
ncat
net@
netcat
netdom
netsh
netstat
netsvc
nmap
nslookup
ntbackup
ntrights