diff --git a/Snort/regex/snort.1chip.regex b/Snort/regex/snort.1chip.regex index 57e4dcc..b92b28d 100644 --- a/Snort/regex/snort.1chip.regex +++ b/Snort/regex/snort.1chip.regex @@ -1,12 +1,7 @@ /[?&](search|topic)=[^&]*?(\x27|%27)(\s*|(%20)*)(\x3b|%3b)/si /[?&](search|topic)=[^&]*?(\x27|%27)(\s*|(%20)*)(\x3b|%3b)/si -/\%5b\%5f[0-9]{16}/sm -/uploadPath[^-]+?(%2e|\x2e){2}(%2f|\x2f)/mi -/(^|&)paths(%5b|\x5b)(%5d|\x5d)=[^&]*?(%2e|\x2e){2}(%2f|\x2f)/mi /[?&](path|file)Name=[^&]*?\x2e\x2e\x2f/i /from(%5f|_)prefix=[^&]*?(%2f|\/)[^&]*?e[^&]*?(%00|\x00)/i -/[?&]iprange=[^&]{68}/i -/[\x7b]{3}[\w\x7c\s]+\x3c[\w\x7c\s]+\x3d[\w\x7c\s]+\x3e[\x7d]{3}/smi /&?(ping(%5f|_)size=(%26|&)[^&\r\n]+?(%26&|&&)?|next_page=[^&\r\n]+?\.\.\/|submit_button=[^&\r\n]+?(?:%0[ad])?|wait_time=[^&\x2e\d\r\n]+?)/i /&?(ping(%5f|_)size=(%26|&)[^&\r\n]+?(%26&|&&)?|next_page=[^&\r\n]+?\.\.\/|submit_button=[^&\r\n]+?(?:%0[ad])?|wait_time=[^&\x2e\d\r\n]+?)/i /(traceroute|ping)=[^&]*?(%3b|\x3b)/i @@ -17,22 +12,12 @@ /[?&](CallbackParam|CallbackFn)=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|eval|script|onload|src)/i /[?&](k|u|cs)=[^&]+?(\x2e\x2e\x5c|%2E%2E%5C){2}/i -/handle\s*=\s*[\x22\x27][^\x22\x27]*?\x2e{2}/i /[?&]key=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i /[?&]configName=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i /[?&]configName=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i @@ -43,45 +28,29 @@ /[?&]configName=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i /[?&]configName=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i /[?&]appName=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i -/[^\x0d\x0a]{520}/smi -/[^\x0d\x0a]{520}/smi /[^<]+?(\x3B|%3B)/mi /(^|&)SelectedID=[^&]+?(\x3B|%3B)/mi /\/vgi\/(jovgraph|webappmon)\.exe/i -/FILECODE=[^&]{91}/i /\x26?arg\d+\s*=\s*[^\x26]*?(import|http)/i /(^|&)selectedLocale=[^&]+?([\x22\x27]|%22|%27)/i /[?&](groupid|usergroup_id)=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i /name=[\x22\x27]RadUAG_fileName[\x22\x27][\x0d\x0a]+?[^\x0d\x0a\x20]+?\.(asa|ascx|ashx|asmx|aspx|axd|config|dll|htm|shtm|asp|bat|com|exe|jsp|php|sys|txt|vbs)/i /[?&]state=[^&]*?[\x22\x27]/i -/(^|&)f\[\]=([^&]+(eval|exec|system|passthru|info))|([^&]{50})/i /]*?(SYSTEM|PUBLIC)/smi /[?&]tagList=[^&]+?([\x3E\x3C\x28\x29]|%3E|%3C|%28|%29)([\x22\x27]|%22|%27)/i /^\s+?alt=\x22[^\x22]+?\x22[^>]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i -/(data_select1|nameParams|schdParams|text1|schd_select1)=[^\x26]{512}/i /user=[^\r\n\x26]*?([\x22\x27]|%2[27])/i /\nContent-Disposition\x3a[^\n]*?name\s*=\s*(?P[\x22\x27]).*?\[(?P=quote)\x3b/ims /^>[^<]+?[\r\n]+?\x21/ /(define\(\s*(?P[\x22\x27])\s*(?P\w+)(?P=q1)\s*,\s*mt_getrandmax\(\)\s*\+\d+\s*\)\x3b.*?mt_rand\(\s*0\s*,\s*(?P=m1)\s*\)|(?P\$\w+)\s*=\s*mt_getrandmax\(\)\s*\+\s*\d+\s*\x3b.*?mt_rand\(\s*0\s*,\s*(?P=m2)\s*\)|mt_rand\(\s*0\s*,\s*mt_getrandmax\(\)\s*\+\s*\d+\s*\)\x3b)/smi /(define\(\s*(?P[\x22\x27])\s*(?P\w+)(?P=q1)\s*,\s*mt_getrandmax\(\)\s*\+\d+\s*\)\x3b.*?mt_rand\(\s*0\s*,\s*(?P=m1)\s*\)|(?P\$\w+)\s*=\s*mt_getrandmax\(\)\s*\+\s*\d+\s*\x3b.*?mt_rand\(\s*0\s*,\s*(?P=m2)\s*\)|mt_rand\(\s*0\s*,\s*mt_getrandmax\(\)\s*\+\s*\d+\s*\)\x3b)/smi /(define\(\s*(?P[\x22\x27])\s*(?P\w+)(?P=q1)\s*,\s*mt_getrandmax\(\)\s*\+\d+\s*\)\x3b.*?mt_rand\(\s*0\s*,\s*(?P=m1)\s*\)|(?P\$\w+)\s*=\s*mt_getrandmax\(\)\s*\+\s*\d+\s*\x3b.*?mt_rand\(\s*0\s*,\s*(?P=m2)\s*\)|mt_rand\(\s*0\s*,\s*mt_getrandmax\(\)\s*\+\s*\d+\s*\)\x3b)/smi -/(?P\x24\w+)\s*=\s*(new Tidy|Tidy->new)\x28\s*[\x22\x27]\x2a[\x22\x27]\s*\x29.{1,256}(?P=var)->diagnose/ims -/<\?(php)?.{1,256}define\s*\x28\s*str_repeat\s*\x28\s*[\x22\x27][^\x22\x27]+[\x22\x27]\s*\x2c\s*\x24argv/ims /]*?action\s*=\s*[\x22\x27][^\x22\x27]+ocPortal\/adminzone\/index\.php\?page=admin_ocf_join&type=step2[\x22\x27][^>]*?>/ims -/cal_from_jd\x28\s*\d{9,}/mi -/\x24(?P\w*)\s*=\s*(rand\x28\d\x2c\s*\d{9,}|\d{9,}).*?cal_from_jd\x28\s*\x24(?P=var)/smi -/^\w+\r?\n.{12}\x00{3}[\x32\x34\x6e\xaa\xac].{8}/ -/^\w+\r?\n.{12}\x00{3}[\x32\x34\x6e\xaa\xac].{8}/ -/^\w+\r?\n.{12}\x00{3}[\x32\x34\x6e\xaa\xac].{8}/ -/^\w+\r?\n.{12}\x00{3}([\x32\x34\x6e\xaa\xac].{8}|[\x78\x82].{12}|[\x8c\x96].{8}|\xa0.{8})[\x04-\xff]/ /\x24(?P\w*)\s*\x3d\s*new\s*ZipArchive\x28\x29.*?\x24(?P=var1)\x2d\x3eaddGlob\x28[\x22\x27]?(?!GLOB_BRACE|GLOB_MARK|GLOB_NOSORT|GLOB_NOCHECK|GLOB_NOESCAPE|GLOB_ERR|GLOB_ONLYDIR)/smi /[\x3f\x26]id=\d*?[\x28\x29\x22\x27]/is /((?P\$\w+)\s*=\s*(?P[\x22\x27])\s*[^(?P=q1)]+(\\x80|\x80).*?crypt\(\s*(?P=m1)|crypt\(\s*(?P[\x22\x27])\s*[^(?P=q1)]+(\\x80|\x80))/smi /((?P\$\w+)\s*=\s*(?P[\x22\x27])\s*[^(?P=q1)]+(\\x80|\x80).*?crypt\(\s*(?P=m1)|crypt\(\s*(?P[\x22\x27])\s*[^(?P=q1)]+(\\x80|\x80))/smi /((?P\$\w+)\s*=\s*(?P[\x22\x27])\s*[^(?P=q1)]+(\\x80|\x80).*?crypt\(\s*(?P=m1)|crypt\(\s*(?P[\x22\x27])\s*[^(?P=q1)]+(\\x80|\x80))/smi -/substr_replace\((\s*\$\w+\s*,\s*){3,}.*?\)\x3b/smi -/substr_replace\((\s*\$\w+\s*,\s*){3,}.*?\)\x3b/smi -/substr_replace\((\s*\$\w+\s*,\s*){3,}.*?\)\x3b/smi /[?&]filename=[^&]*?[\x22\x27][^&]*?\x3B/i /filename=(\x22|\x27)\.\.\x2f/smi /\.\.[\x5C\x2F]/mi @@ -92,7 +61,6 @@ /Referer\x3a[^\r\n]*?[\x27\x22]\x29[^\r\n]*?INSERT/i /Referer\x3a[^\r\n]*?[\x27\x22]\x29[^\r\n]*?SELECT/i /Content-Disposition\x3a[^\n]+filename\s*=\s*[\x22\x27][^\x22\x27]*?\.war[\x22\x27]/i -/EnteredAttrName=[^&]{32}/i /[?&]Using=_layouts/query.iqy.*?&List=[^&]+(script|src|location|document|onlick|onload)/i /sections=[^\r\n\x26]+(script|onclick|onload|onmouseover|html|[\x22\x27\x3c\x3e\x28\x29])/i /^[^\r\n]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i @@ -103,7 +71,6 @@ /\x3F\s*?-s/i /\x2ephp\x3f\s*-s/i /json\s*=\s*\x7b.*?\x22fn\x22\s*\x3a\s*\x22(getItems|folderRename|file(Delete|Copy))\x22\s*\x2c\s*\x22args\x22\s*\x3a\x5b?[^\x7d]*?\x22[^\x22]*?(\.\.|0day)[^\x22]*?\x22.*?\x7d/ims -/zip\x3a\x2f\x2f[^\x0A\x20\x09\x0B\x0C\x85\x3E\x3C]{400}/i /(\x5B|\x25\x35\x62)(\x5D|\x25\x35\x64)\x3D(\x3C|\x25\x33\x63)script/i /[\x26\x3f]page=[^\x26]*?\x25/i /objectname=[^\x26]*?(\x2e\x2e\x2f|[^a-z0-9])/i @@ -115,8 +82,6 @@ /([sp]key|csk)=[^\r\n\x26]+(script|onclick|onload|onmouseover|html|[\x22\x27\x3c\x3e\x28\x29])/i /ctl\d+\x24PlaceHolderMain\x24ctl\d+\x24customizeThemeSection\x24(accent1|accent2|accent3|accent4|accent5|accent6|dark1|dark2|light1|light2)=[^\r\n\x26]+(script|onclick|onload|onmouseover|[\x22\x27\x3c\x3e\x28\x29])/i /(amount|cartId|email|transId|transStatus)=[^&]*[\x22\x27\x3c\x3e]/ -/^UNLOCK\s+[^\s]{200}/smi -/^MKCOL\s+[^\s]{1000}/smi /(menuitem=|nav=)[^\x26\s]*[\x3e\x3d\x29\x3b]/i /refreshRateSetting=[^\x26\s]*[\x3e\x3d\x26]/i /action=[^\x26\s]*[\x3e\x3d\x26]/i @@ -140,7 +105,6 @@ /\x2Fadvanced1\.php\?[^\r\n]*?pluginpath\x5B0\x5D=(https?|ftps?)/i /tsep_config\x5babsPath\x5d=[^&]*?(https?|ftps?|php)/i /\x2F(conf|hslist)\.php\?[^\r\n]*?subdir=(https?|ftps?)/i -/userName\s*=([^\x5C\x26]{500}|[^5C]+\x5C[^\x26]{500})/i /\x2Faedating4CMS\.php?[^\r\n]*?dir\[inc\]=(https?|ftps?)/i /Language=(https?|ftps?)/i /ad_body_temp=(https?|ftps?)/i @@ -167,144 +131,67 @@ /\x2Fpost\.php3?[^\r\n]*?parent=[^\r\n\x26]*?union[^\r\n\x26]*select/i /\x2Fpost\.php3?[^\r\n]*?topic_id=[^\r\n\x26]*?union[^\r\n\x26]*select/i /\x2Findex\.php?[^\r\n]*?password=[^\r\n\x26]*?[\x22\x27][^\r\n\x26]*[\x22\x27]/i -/Oid\x3D[^\x0D\x0A]{1000}/i -/Template\x3D[^\x0D\x0A]{1000}/i -/passwd\x3D[^\x26\x3F\x3B\x0D\x0A]{29}/i -/userid\x3D[^\x26\x3F\x3B\x0D\x0A]{29}/i -/Host\x3A\s*[^\x0D\x0A]{121}/i /Deploy\s*(Enterprise)?\s*Applications/si /^(Frame)?\.jsf/ /j_password=(&|$|adminadmin)/ -/\x20\x00([^\x00].|.[^\x00]){255}/smi /\x26amp\x3B[^\r\n]+expression\x28/ /^(\.iqy|\.bqy).*(View|RowFolder)=[^&\x3b]*<\s*script/i /\x3c\x21DOCTYPE\s*doc\s*\x5b\x3c\x21ENTITY\s*[^\s]*\s*SYSTEM/i /hiddenSpanData=[^=]*(%3c|%28)/i /[?&]CalendarDate=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i -/^[^\x3c\x2f]{41}/ -/\x2ftimthumb\x2ephp\x3f[^\r\n]*?src=https?\x3a\x2f([^\x2e\x2f]+?\x2e){3}/i /actionOutcome=\x2F[^\x3F]+\x3F[^\x26]*\x23\x7B/i /\x3C\s*param\s*\x3E\s*\x3C\s*value\s*\x3E\s*\x3C\s*string\s*\x3E[^\x3C]*[\x2C\x3B]/smi /preauth\x3d[\x26\x7c]/i /<\s*[A-Z]+\s+[^>]*file\x3A\x2F\x2F\x2F/smi /<\s*[A-Z]+\s+[^>]*file\x3A\x5C\x5C127\x2e0\x2e0\x2e1/smi /&email=[^\x26]*(%3b|\x3b)/i -/act\x3D[^\x26\x3F\x3B\x0D\x0A]{300}/i -/MaxAge\x3D[^\x26\x3F\x3B\x0D\x0A]{300}/i -/ICount\x3D[^\x26\x3F\x3B\x0D\x0A\s]{300}/i -/txt_user_name_p\x3D[^\x26\x3F\x3B]{300}/i -/\x2FIMManager\x2FrdPage\x2Easpx\x3F.*?(loginTimeStamp|dbo|dateDiffParam|whereClause)\x3D[^\x26]*?(\x3B|\x23|\x2D{2})/s -/\x2FIMManager\x2Frdpageimlogic\x2Easpx\x3F.*?(loginTimeStamp|dbo|dateDiffParam|whereClause)\x3D[^\x26]*?(\x3B|\x23|\x2D{2})/s /Template\x3D[^\x26]*?\x25\d*n/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i -/Content-Disposition[^\r\n]+?filename\s*\x3D[^\r\n]*?\x2F(\x2E{2}\x5C|\x5C\x2E{2})/i /cn=[^\x00]*\x23[^\x00]*\x01\x01\x00/i /fileName\x3d[^\x26]*(\x2e\x2e\x5c|\x2e\x2e\x2f)/i /other=[^\x26]*(%26|%7c)/si -/^[^\x26]{512}/ /^[^\x26]*?\x25/ /\x26arg\d+\s*=\s*[^\r\n\x26]*import/i /(filename|type)=[^\x26]*?\x2E\x2E/ /^[^\x26]*?\x2E\x2E/ -/(data_select1|nameParams|schdParams|text1|schd_select1)=[^\x26]{512}/i -/displayWidth[\x2b\x20]\d[^\x2b\s\n]{128}/si -/displayWidth[\x2b\x20]\d[^\x2b\s\n]{128}/si -/fileName\x3d[^\r\n&]{235}/i /^Connection\x3A[^\r\n]+%/smi /^Expect\x3A[^\r\n]+<script>/smi /press_id\x3D\d+[^\&\r\n]/i -/(Context|Action)\x3D[^\x26\x3b]{1024}/i /groupList\x3d[^\x26]*\x3b/i -/password=[^\x26\r\n]{128}/smi -/userid=[^\x26\r\n]{128}/smi /pathToFiles=(ftp|https?)/i /premodDir=(ftp|https?)/i -/^[^&\x3b]{500}/i /^User-Agent\x3A[^\r\n]*?onload=/im /^User-Agent\x3A[^\r\n]*?<script/im "/^\w+\.(wav|alaw|ulaw|sln|gsm)\x22/i /index\.php\?.*mail=[^\r\n\x26]*\x3C\x3F/smi /index\.php\?.*date=[^\r\n\x26]*\x29\x3B/smi -/filename\s*?=[^\x3b\r\n]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i /uname=[^&]*%26/ /^(To|From)[^\x3e]*?\x3e[a-z0-9]*[^a-z0-9][^\x3c]*?\x3c\x2fconvert(To|From)/is -/pwd=(\!|\%21)CRYPT(\!|\%21)[^\r\n&]{513}/i /^Content-Disposition\x3A[^\r\n]*filename=(?P<q1>\x22|\x27|)[^\r\n]*?\x2Ephp(?P=q1)/smi -/\x2frobohelp\x2frobo\x2freserved\x2fweb\x2f[^\r\n]{0,60}\x2Ejsp/i /\x80(\x84|\x85\x00|\x86\x00\x00|\x87\x00\x00\x00)\xFF\xFF\xFF\xFF/smi /sort\x3d[^\s]*\x3b+/i -/InName\x3E[^\x3C]{100}/i /cai\x3a[^\x3e]*?(\x22|\x2522)[^\x3e\x22]*?-launcher/smi -/session=[^\s\x3b&]{520}/i /^(GET|POST)\h+[^\n]*?\x2E\x2E\x5C\x2E\x2E\x5C\x2E\x2E\x5C[^\n]*?HTTP/i /^(GET|POST)\h+[^\n]*?\x2E\x2E\x2F\x2E\x2E\x2F\x2E\x2E\x2F[^\n]*?HTTP/i -/(OvJavaScript|OvTitleFrame|OvHelpWindow|OvMap|OvSession|OvJavaLocale|OvOSLocale|OvLogin|OvDebug|OvDeveloper|OvTreeControl|OvJavaScript|OvProduct|OvPort|OvLocale|OvWebSession)\s*\x3D[^\x3B\x2C]{1024}/i /fileName=.*?\x2E\x2E(\x2F|\x5C)/s /uname\x3D[^\x26\x2D\s]*?\x2D/i -/^GET\s+.*\x2Frequests\x2Fstatus\.xml\x3F.*smb\x3A\x2F\x2F[^\s\x0A\x0D]{251}/smi -/(arg=[^\x26]*?OVwSelection[^\x26]*?\x26.*?sel=[^\s\x26]{1023}|sel=[^\x26]{1023,}\x26.*?arg=[^\s\x26]*?OVwSelection)/s -/(arg=[^\x26]*?OVwSelection[^\x26]*?\x26.*?sel=[^\s\x26]{1023}|sel=[^\x26]{1023,}\x26.*?arg=[^\s\x26]*?OVwSelection)/s -/^Authorization\x3a(\s*|\s*\r?\n\s+)Basic\s[^\n]{512}/smi -/\/vgi\/(jovgraph|webappmon)\.exe.*?-textFile\+[^+]{201}/i /tid=[^&]/smi /^(?!false|off|no|0)/i /\x5flayouts\x2fhelp\x2easpx\x3f.*?cid0\x3d[A-Za-z\x5c\x2e0-9]*[^A-Za-z\x5c\x2f\x2e\x26\x3d0-9\s]/si -/OvAcceptLang\s*\x3d\s*[^\x3b\n]{300}/ism -/(((DestFile|encryptPass)\x3D[^\x26]{50})|((BaseDN|SearchFilter)\x3D[^\x26]{128}))/i -/(((DestFile|encryptPass)\x3D[^\x26]{50})|((BaseDN|SearchFilter)\x3D[^\x26]{128}))/i /\<\?xml[^\>]+encoding\s*\=\s*(\'|\")[^\'\"\>\%]*\%/ /\<\?xml[^\>]+encoding\s*\=\s*(\'|\")[^\'\"\>\%]*\%/ -/^Authorization\s*\x3A\s*Digest\s+([^\n\x2C]*\x2C){15}/im /^(GET|POST|TRACE|DESCRIBE|DELETE)/ /^Content-Length\s*\x3A\s/mi -/^Content-Length\s*\x3A\s*[1-9][0-9]{8}/mi -/\x2fwiki[^\n]*\x3fuselang=[^\n\x26\x3f]{2,}[a-zA-Z\x2d]/smi /(^|[\x26\x3f])val\s*?=\s*?([\x26]|$)/mi /^[^\x3b]*\x3b.*\x2ejsp/i /^(GET|POST)\s+[^\x0a]*?\x2fprn\x2e(htm|html|asp|cgi)/i -/^HOST\s*\x3a\s*[^\x0a]{1000}/mi -/sel\x3d[^\x26\x0a]{73}/i -/dated-rev-report.*?<D\x3aCREATIONDATE>([^\x3C]{75}|[\s\x20-\x3B\x3D-\x7E]{0,74}[^\s\x20-\x7E])/ims -/JSESSIONID=[^\s\x26\x3a\x22\x27\x3b]{300}/smi -/^\s*Accept-Language\s*\x3a\s*([^\r\n]*?\x2c){20}/mi -/OvOSLocale\s*\x3d\s*[^\x3b\s]{249}/mi /\x2Fwordpress\x2F\x3F[^\r\n]*cat\s*=\s*[^\r\n\x26]*\x2F\x2E\x2E/smi /tag_board\.php\x3F[^\r\n]*action=delete[^\r\n]*id=[^\r\n\x26]*(select|insert|delete)/smi /shoutbox_view\.php\x3F[^\r\n]*mode\s*=\s*(delete|edit)[^\r\n]*id\s*=\s*[^\r\n\x26]*[^\d]+/smi /evtdump\x3f.*?\x2525[^\x20]*?\x20HTTP/i -/^CONNECT\s[^\s]{1024}/i -/^Authorization\x3a\s*Basic[^\n]{256}/mi -/^Accept\x2dCharset\x3a\s*?([^\x3b\x3d\x2c]{1,36}\s*?[\x2d\x3b\x3d\x2c]\s*?)*[^\x2d\x3b\x2c\x3d\n]{37}/smi -/^Accept\x2dLanguage\x3a\s*(\w{1,36}\s*(\x2e|\x2d|\x3b|\x3d|\x2c)\s*)*[^\x2d\x3b\x2c\x3d\n]{37}/smi -/[?&]HTTP_(COOKIE|SERVER)=[^&]{256}/i -/SET_(SENDFROM|MAILHOST)\x28\x27[^\x27]{256}/i /\x26r\d\x3d[^\x26\s]*\x27/smi /\x26r\d\x3d\d*[^\x26\s\d]/smi /[\x80-\xff]/ -/\x2FCSuserCGI\x2Eexe\x3F.*?Logout.[^&]{96}/i -/TMlogonEncrypted=(\!|\%21)CRYPT(\!|\%21)[A-Z0-9]{512}/i /^\s*\x3a\s*[Nn][Tt][Ll][Mm]\s+TlRMTVNTUAADAAAA/ -/instancename=[^&\x3b\r\n]{513}/smi /password[\x3d\x3f][^\n\x26]*\x3c[^\n\x26]+\x3e/i /template\s*=\s*\x7b\x24/smi /comment=[^\x26\s]*[\x2f\x5c]/smi @@ -312,8 +199,6 @@ /proxystylesheet=[-a-z0-9_\.]*[^-a-z0-9_\.&\s]/smi /username[\x3d\x3f][^\n\x26]*\x3c[^\n\x26]+\x3e/i /action[\x3d\x3f][^\n\x26]*\x3c[^\n\x26]+\x3e/i -/^Content-Length\x3A\s*[^\r\n]{100}/smi -/^(\d{5,}|390[1-9]|39[1-9][0-9]|[4-9][0-9]{3})\x3A/ /method[\x22\x27]\s*?\x3a\s*?[\x22\x27][^\x22\x27]*?(system|eval)\s*?\x28/i /className[\x22\x27]\s*\x3a\s*[\x22\x27][^\x22\x27]*?(\x2e\x2e|%2e%2e)([\x5c\x2f]|%5c|%2f)/i /local_graph_id=(?!(\d+|)([\x26\s]|$))/smi @@ -321,53 +206,30 @@ /local_graph_id=(?!(\d+|)([\x26\s]|$))/smi /rra_id=(?!(\d+|all|)([\x26\s]|$))/smi /graph_(start|end|height|width)=(?!(\d+|)[\x26\s])/smi -/^(GET|POST)\s+[^\s]*(\x2fnds|\x2fdhost)[^\n]*\nHost\x3a\s*[^\n]{63}/i -/cache_lastpostdate\[[^\]]+\]=[^\x00\x3B\x3D]{30}/smi -/HTTP\/1\.[01].*?\n([^\r\n]+?\r?\n){32}/i -/AgentGuid\x3D[^\x3f\x26\x0D\x0A]{63}.*?Source\x3D[^\x3f\x26\x0D\x0A]{50}/s /[?&]netid=[^&]*?([\x60\x3b\x7c\x3c\x3e]|\x24\x28)/i /[?&]cdpnode=[^&]*?([\x60\x3b\x7c\x3c\x3e]|\x24\x28)/i /[?&]node=[^&]*?([\x60\x3b\x7c\x3c\x3e]|\x24\x28)/i /[?&]netid=[^&]*?%26/i /[?&]cdpnode=[^&]*?%26/i /[?&]node=[^&]*?%26/i -/WebAdmin\x2Edll\x3F[^\r\n]*?View=Logon.*?\r\n\r\n[^\r\n\x26]*User=[^\r\n\x26]{100}/smi -/\x2fnds[^\r\n]{1000}/smi /[\?\x20\x3b\x26]module=[a-zA-Z0-9]*[\x3b\x21\x7c\x3c\x3e\x60\x5c\x2f]/i -/^Host\x3a\s+?[^\x3a\n]*?\x3a[^\n]{100}/mi /^Content-Type\x3A\s+multipart\/form-data/smi /img\.pl\x3f[^\r\n]*f=[^\x26\r\n\x2e]*\x2e\x2e/smi /ShellExample\.cgi\?[^\n\r\&]*\x2a/i /^POST\s/smi -/\x2f[^\x2f]{188,}\x2ert/i -/mfcisapicommand=[^&\r\n\x3b]{250}/smi /awstats.pl?[^\r\n]*configdir=\x7C/i /^Content-Length\x3a(?!\x0d\x0a\x0d\x0a).*?^Content-Length\x3a/smi -/j_(username|password)=[^\n&]{256,}/smi /itemid=\d*[^\d\&\;\r\n]/i /db4web_c(\.exe)?\/.*(\.\.[\\\/]|[a-z]\:)/smi -/\/oftart\.exe\?[^\s]{100}/smi /^Content-Length\x3a(\s*|\s*\r?\n\s+)-\d+/smi -/php.*\x3f[^\n]{256}/smi -/^User-Agent\x3a[^\n]{216}/smi -/fn=Eye\d{4}_\d{2}\.log/msi /fn=\x2e\x2e(\x2f|\x5c)/msi /\/prn\.(asp|cgi|html?)/i /update=[^\r\n\x26]+/i -/connectID=[^&\x3b\r\n]{255}/smi -/username=[^&\x3b\r\n]{250}/smi -/username=[^&\x3b\r\n]{255}/si -/sid=[^&\x3b\r\n]{255}/si -/instancename=[^&\x3b\r\n]{513}/smi /forum=.*'/ /^Authorization\x3a(\s*|\s*\r?\n\s+)Basic\s+=/smi /^Authorization\x3a(\s*|\s*\r?\n\s+)Basic\s+=/smi /^Content-Length\s*\x3a\s*-\d+/mi /systempath=(https?|ftps?|php)/i -/^User-Agent\x3a[^\n]{244}/smi -/\Wfrom=[^\x3b&\n]{100}/si -/^DESCRIBE\s[^\n]{300}/smi -/^[^\x3a\x3f]{11,}\x3a\x2f/smi /page=(https?|ftps?|php)/i /GALLERY_BASEDIR=(https?|ftps?|php)/i /^Authorization\x3a(\s*|\s*\r?\n\s+)Basic\s+YWRtaW46cGFzc3dvcmQ/smi @@ -384,7 +246,6 @@ /calendar(|[-_]admin)\.pl/i /file=(https?|ftps?|php)/i "/^\w+\s+[^\n\s\?]*\.jsp/smi -/sel\x3d[^\x26\x0a]{73}/i /loadadminpage=(https?|ftps?)/i /\/template\/album.php\?ET_FLE=(ftps?|https?|php)\:/i /sourceFolder\x3D(https?|ftps?|php)\x3A/ @@ -410,7 +271,6 @@ /_wpSelected=([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i /RadUAG_fileName=[^&]+?\.(asa|ascx|ashx|asmx|aspx|axd|config|dll|htm|shtm|asp|bat|com|exe|jsp|php|sys|txt|vbs)/i /domain=[^&]*?([\x3b\x60]|\x24\x28|%3b|%60|%24%28)/i -/password=[^\x26]{1024}/smi /(^|&)pingstr=[^&]*?(\x60|\x24\x28|%60|%24%28|%26)/mi /(^|&)databasename=[^&]*?(\x27|%27)[^&]*?(\x3b|%3b)/mi /(^|&)db(_|%5f)pass=[^&]*?(\x27|%27)[^&]*?(\x3b|%3b)/mi @@ -435,11 +295,7 @@ /dir\x5bplugins\x5d\x3d\s*?(https?|ftps?|php)/i /dir\x5bplugins\x5d\x3d\s*?(https?|ftps?|php)/i /POST \/(?<uri>.*?) TT((?!\r\n\r\n).)*?ost: (?<host>[^\r\n]*?)((?!\r\n\r\n).)*?eferer: https?:\/\/((?!(?=host))|[^\/]*?\/(?!(?=uri)))/ims -/<FilePath[^>]*?>[^<]*?(\x2e|%2e){2}([\x5c\x2f]|%5c|%2f)/i -/<in[^>]*?>[^<]*?(\x3b|(\x2d|%2d){2}|%3b)/i -/\x3astring[^>]*?>[^<]*?(\x2e|%2e){2}([\x5c\x2f]|%5c|%2f)/i /[?&]chartid=[^&]*?\x2e\x2e\x2f/i -/(^|&)chartid=[^&]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i /[?&]skin=[^&]*?\x2e\x2e\x2f/i /[?&](filename|customerid)=[^&]*?\x2e\x2e/i /^['"][^'"]*?([a-z]:\\?\\|\.\.)/im @@ -447,49 +303,28 @@ /[?&]openid_identifier=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i /[?&]txtSearch=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i /[?&]txtSearch=[^&]+?([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i -/name\s*?=\s*?[\x22\x27]?uploadDir[^\x3b]+?(?:(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)|C(\x3a|%3a)(\x5c|%5c))/i -/(^|&)uploadDir=[^&]*?(?:(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)|C(\x3a|%3a)(\x5c|%5c))/mi /[?&]filename=[^&]*?\x2e\x2e\x2f/i -/(^|&)filename=[^&]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/mi /[?&](traceroute|ping)=[^&]*?(%3b|\x3b)/i /[?&]skin=[^&]*?\x2e\x2e\x2f/i /[?&]skin=[^&]*?\x2e\x2e\x2f/i -/filename\s*?=\s*?[\x22\x27]?[^\r\n]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i -/filename=[^&]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i /^driverFolderName\x3a[^\r\n]*?\x2e\x2e[\x2f\x5c]/mi -/[?&]\w+=[^&]{1023}/i -/(^|&)\w+=[^&]{1023}/mi /(?<=[?&])(?>service_name|device|ssid_num|cfKeyWord_Domain|h_skeyword)=[^&]*?[\x3c\x3e]/i /TimeToLive=[^&]*?(%60|\x60)/i /\/setup.cgi.*?TimeToLive=[^&]*?(%60|\x60)/i -/<filename[^>]*?>[^<]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i /[?&][hs]wtype=[^&]*?\x2e\x2e\x2f/i -/(^|&)[hs]wtype=[^&]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/mi /[?&]file=[^&]*?\x2e\x2e\x2f/i -/(^|&)file=[^&]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/mi -/iptest\=(\d{1,3}\.){3}\d{1,3}(\x3B|\x253b)/i /(RequestAccessController|Login)$/ -/^\/fp\/servlet\/(equestAccessontroller|Login)\?.{0,60}?file\=\/.{0,30}?conf.{0,30}?\.xml/ -/MaxAge=[^\x26\x3F\x3B\x0D\x0A]{300}/i /^['"][^'"]*?([a-z]:\\?\\|\.\.)/im -/\/vgi\/(jovgraph|webappmon)\.exe.*?-textFile\+[^+]{201}/i /<LogClientInstallation.*?<userid>[^<]*?\x3b.*?</userid/s /<value>.*?[\x21\x7c\x3a\x40\x24\x23\x25\x5e\x26\x2a\x28\x29].*?</value>/i /<value>.*?[\x21\x7c\x3a\x40\x24\x23\x25\x5e\x26\x2a\x28\x29].*?</value>/i -/uid\x3D\d{0,10}?[A-Za-z\x3B\x25]/ -/uid\x3D\d{0,10}?[A-Za-z\x3B\x25]/ /[?&](name|email|subject|message)=[^&]*?((\x22|%22)\s*?([\x3b\x7c]|%3b|%7c)|(\x60|\x24\x28|%60|%24%28))/i /\x2falertcloud\x2findex\.php[^\n\s]*?[?&](height|width)(?!%26)[^&\n\s]*?%22(\x7d\x7d|%7D%7D)(\x3b|%3b)/i -/(^|&)(not-)?catlist(\x5b|%5b)\d?(\x5d|%5d)=[^&]*?(\x27|%27)(\x29|%29)[\x7c(%7c)]{2}/i /[?&]language=[^&]*?\x2e\x2e\x2f/i /[?&]login-(name|class)=[^&]*?[\x22\x27][^&]*?select/i /<!ENTITY[^>]*?SYSTEM/smi -/(^|&)TM(\x5f|%5f)Block(\x5f|%5f)URL=[^&]{246}/mi -/address\d{1,5}\x3D[^\x26]*(\x22|\x2522)/smi /^\x2Fsnort\x2Fsnort_log_view.php\x3F.*logfile\x3D(?!/var/log)|([\x2F]?\x2e\x2e)/smi /^.*logfile\x3D(?!/var/log)|([\x2F]?\x2e\x2e)/smi -/interval=(\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z\x2F|)P\d{13}/i -/interval\s?=\s?(\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z\x2F|)P\w{13}/i /[?&]function=(eval|exec|passthru|proc_open|shell_exec|system)/i /(^|&)destination_ip=[^&]*?(\x60|\x24\x28|%60|%24%28)/mi /^FILELOCATION\x3a[^\r\n]*?\x2e\x2e\x2f/mi @@ -503,20 +338,17 @@ /(^|&)latitude=[^&]*?([\x22\x27\x3C\x3E\x28\x29]|script|onload|src)/i /(^|&)website=[^&]*?([\x22\x27\x3C\x3E\x28\x29]|script|onload|src)/i /collect[^&]+?file=[^&]*?\x2e\x2e\x2f/i -/https?\x3a\x2f\x2f[^>\x22]{268}/smi /^\x2Findex\x2Ephp\x3Fq=vwrooms\x2Flogout[^\x3E]*?\x26module=[^\x26]+(script|onload|onmouseover|\x27|\x22|\x3c|\x3e|src)/smi /^\x2Findex\x2Ephp\x3Fq=vwrooms\x2Flogout[^\x3E]*?\x26message=[^\x26]+(script|onload|onmouseover|\x27|\x22|\x3c|\x3e|src)/smi /ThemeOverride\x3D[^&]*(\x2F\x3E|\x7D\x3B)/ /\<userName\>[a-z&\x3B]+?\s?(select|union|insert|delete|ascii|update)/i /file=[\x7c\x27]/i -/userId\s*?=[^>]*?(\x2e|%2e){2}([\x5c\x2f]|%5c|%2f)/i /[?&]username=[^&]*?\x22[^&]*?\x29/i /(^|&)username=[^&]*?(\x22|%22)[^&]*?(\x29|%29)/i /[?&]password=[^&]*?\x22[^&]*?\x29/i /(^|&)password=[^&]*?(\x22|%22)[^&]*?(\x29|%29)/i /[?&]xml_path=[^&]*?\x2e\x2e\x2f/i /[?&]url_name=[^&]*?\x2e\x2e\x2f/i -/(^|&)(source|query)=[^&]*?(\x2e|%2e){2}([\x5c\x2f]|%5c|%2f)/i /RetrieveProperties.*?<(\x5F|\w+\x3A\x5F)/smi /src=https?\x3a\x2f[^\x26\x20]*?(\x24\x28|%24%28)/i /cgi-bin\/webbbs\/webbbs_config\.pl\?.*?followup=[^\x26]*?\x7/ @@ -526,11 +358,8 @@ /personalID=\d+?[^\d]/i /[?&]abs_path=[^&]*?(https?|ftps?|php)/i /php\?goto=(https?|ftps?|php)/i -/^\x2fcgi-bin\x2f[^\x2f]{360,}\.(plx?|cgi)$/i /xsd\x3astring[^>]*?>[^<]*?([\x3b\x7c\x26]|\x24\x28|%3b|%7c|%26|%24%28)/i /xsd\x3astring[^>]*?>[^<]*?([\x3b\x7c\x26]|\x24\x28|%3b|%7c|%26|%24%28)/i -/filename\s*?=\s*?[\x22\x27]?[^\r\n]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i -/filename=[^&]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i /_sysSessionPath=(https?|ftps?|php)/i /\x2fgitlist\x2f[^\r\n]*?([\x60\x3b\x7c]|\x24\x28)/i /\x2FaedatingCMS\.php?[^\r\n]*?dir\[inc\]=(https?|ftps?)/i @@ -542,8 +371,6 @@ /HTTP_AUTH_LOGIN\x3A\s*?\x27/ /[?&]fileDate=[^&]*?([\x3b\x60]|\x24\x28)/i /[?&]fileDate=[^&]*?%26/i -/filename\s*?=\s*?[\x22\x27]?[^\r\n]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i -/(^|&)filename=[^&]*?(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i /[?&]filename=[^&]*?\x2e\x2e\x2f/i /(^|&)hostname=[^&]*?(\x27|%27)/i /[?&]hostname=[^&]*?\x27/i @@ -552,15 +379,11 @@ /(^|&)key(\x5b|%5b)key(\x5d|%5d)=[^&]*?([\x60\x3b\x7c]|\x24\x28|%60|%3b|%7c|%26|%24%28)/i /[?&]\w+?=[^&]*?([\x60\x3b\x7c]|\x24\x28)/i /filename\s*?=\s*?[\x22\x27]?[^\r\n]*?\x2ephp/i -/(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i -/(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i /xsd\x3astring[^>]*?>[^<]*?([\x3b\x7c\x26\x60]|\x24\x28)/i -/(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)/i /(^|&)\w+?=[^&]*?(eval|exec|passthru|proc_open|shell_exec|system)/i /\x27\x3b[^\r\n]*?(eval|exec|passthru|proc_open|shell_exec|system)/i /[?&]img=[^&]*?(http|ftp)/i /device(\x3d|%3d)(\x22|%22)((?!(\x22|%22)).)*?([\x60\x3b\x7c]|\x24\x28|%60|%3b|%7c|%24%28)/i -/name\s*?=\s*?[\x22\x27]?poLibMaintenanceFileSave[^\x3b]+?(?:^(\x2f|%2f)|(\x2e|%2e){2}([\x2f\x5c]|%2f|%5c)|C(\x3a|%3a)(\x5c|%5c))/im /<\x3f[^>]*?(eval|exec|passthru|proc_open|shell_exec|system)/i /[?&]filename=[^&]*?\x2e\x2e\x2f/i /[?&](filename|regionID)=[^&]*?\x2e\x2e\x2f/i @@ -571,26 +394,18 @@ /\x26newkey=.*?[\x3B\x60\x7C\x24]/ /\x26confcode=.*?[\x3B\x60\x7C\x24]/ /^[\x21-\x2f\x3a-\x3f\x5b-\x60\x7b-\x7e]/ -/((\x3c\x00?)*\x2a\x00?[^\x2a\x3c]*){5}/ /\x5c\x00\x5c\x00[^\x5c]*?\x5c\x00\x00\x00/ -/^\x00.{3}\xffSMB[\x02\x03\x06\x07\x08\x09\x0f\x29\x2a\x2d\x82\x83\x84\xa2\xa5].{61}[\x5c\x2f]\x00?(.\x00?)+?[\x5c\x2f]\x00?(.\x00?){5}\x7e\x00?(.\x00?){2}\x2E\x00?(.\x00?){3}(?!\x00\x00?)/ /^\x00+/ /^\x00+/ /^User-Agent\x3A[^\r\n]+Kindle\x2F3\x2E0\x2B/smi -/mos\s{2}\dm\s\d/ /^SSH-[12]\.\d+/smi /^\s*\w+\s+NO LOGIN/smi /User-Agent\x3A[^\n\r]+Google[^\n\r]+Desktop/smi /^User-Agent\x3A[^\n\r]+Gizmo/smi -/[\x5e\x7d\x7b\x21\x5b\x5d\x5f\x60\x24\x25\x2a\x3c\x3e\x23\x3a\x3f\x2b\x7c]{2,50}?/smi -/\&status=\d{4}\&mid=\w{32}/i /User-Agent\x3a\s[^\x0d\x0a]*Paros/ /^\x23([\x22\x27\x3c\x3e\x28\x29]|script|onload|src)/i /view\x2Dsource\x3Ahttp\x3A\x2F\x2F[^\x3B]*?url\x3Dhttps/smi /(before|after).*?((display\x3atable|counter-reset\x3a)|(counter-reset\x3a|display\x3atable)).*?ruby\s*{\s*float\x3a/si -/^2\d{2}[^\n]*?\x22{2}/ -/window\.open\x28\x27[\w\W]{0,35}\x3aalert\x28document\.cookie\x29\x27/smi -/window\.open\x28\x27[\w\W]{0,35}\x3aalert\x28document\.cookie\x29\x27/smi /ruby\s*{\s*float\x3a.*?ruby\x3a(before|after).*?(display\x3atable|counter-reset\x3a)/si /<iframe[^>]*?srcdoc\s?=\s?[\x22\x27]<script>/smi /\x2eeot([\?\x5c\x2f]|$)/smi @@ -608,7 +423,6 @@ /\x2emanifest([\?\x5c\x2f]|$)/smi /\x2eeps([\?\x5c\x2f]|$)/smi /\x2ewma([\?\x5c\x2f]|$)/smi -/^\x57(\x83\xCD\xFF)?\x89\xE5\x8D\x9C\x24.{4}\x31\xC0\x50\x39\xDC\x75\xFB\x46\x46\x53\x68.{4}\x57\x83\xC3\x04\x53\x68.{4}\x56\x83\xC3\x04\x53\x50\xC7\x03.{4}\x90\x90/ /\x2egif([\?\x5c\x2f]|$)/smi /\x2ecrx([\?\x5c\x2f]|$)/smi /\x2exls([\?\x5c\x2f]|$)/smi @@ -618,7 +432,6 @@ /\x2epmd([\?\x5c\x2f]|$)/smi /\x2etif(f)?([\?\x5c\x2f]|$)/smi /\x2edisco([\?\x5c\x2f]|$)/smi -/^(\x72\xED\xB8\x01.{3}|\x8A\x07\x72\xEB\xB8\x01\x00\x00\x00)\x01\xDB\x75\x07\x8B\x1E\x83\xEE\xFC\x11\xDB\x11\xC0\x01\xDB[\x73\x77].{3}\x8B\x1E\x83\xEE\xFC/ /\x2edxf([\?\x5c\x2f]|$)/smi /\x2elzh([\?\x5c\x2f]|$)/smi /\x2ehhp([\?\x5c\x2f]|$)/smi @@ -1087,10 +900,8 @@ /filename=\x22[^\x22]*\x2ejob\x22/i /filename=\x22[^\x22]*\x2ecur\x22/i /filename=\x22[^\x22]*\x2eclass\x22/i -/^(\x72\xED\xB8\x01.{3}|\x8A\x07\x72\xEB\xB8\x01\x00\x00\x00)\x01\xDB\x75\x07\x8B\x1E\x83\xEE\xFC\x11\xDB\x11\xC0\x01\xDB[\x73\x77].{3}\x8B\x1E\x83\xEE\xFC/ /90\x0D?\x0A[^\x20]*\x20[^\x0A]*\x0A/i /filename=\x22[^\x22]*\x2eclass\x22/i -/^\x57(\x83\xCD\xFF)?\x89\xE5\x8D\x9C\x24.{4}\x31\xC0\x50\x39\xDC\x75\xFB\x46\x46\x53\x68.{4}\x57\x83\xC3\x04\x53\x68.{4}\x56\x83\xC3\x04\x53\x50\xC7\x03.{4}\x90\x90/ /\x2ej2k([\?\x5c\x2f]|$)/smi /\x2ejpm([\?\x5c\x2f]|$)/smi /\x2ejp2([\?\x5c\x2f]|$)/smi @@ -1366,229 +1177,80 @@ /filename=[\x22\x27]?[^\n]*\x2ebcl[\x22\x27\s]/si /filename=[\x22\x27]?[^\n]*\x2ebcl[\x22\x27\s]/si /\x2f[\w\x2d]*\x2e+$/m -/^\/[a-z0-9]{12}\.jnlp$/ -/^\/[a-f0-9]{9}\.jar$/ /var\s+(?P<variable>\w+)\=document\.createElement.*?\x3b(?P=variable)\.setAttribute.*?document\.body\.appendChild\x28(?P=variable)\x29/i -/[^&]+&[a-z]=[a-f0-9]{16}&[a-z]=[a-f0-9]{16}$/ /\&k=\d+($|\&h=)/ -/filename\=[a-z0-9]{24}\.jar/ -/filename\=[a-z0-9]{24}\.exe/ -/^\/[a-z0-9]{1,4}\.jar$/ -/^\/[a-z0-9]{1,4}\.jnlp$/ -/\r\nHost\x3a\x20[a-z0-9\x2d\x2e]+\.com\x2d[a-z0-9\x2d\x2e]+(\x3a\d{1,5})?\r\n/i -/php\?jnlp\=[a-f0-9]{10}($|\x2c)/ -/\/elections\.php\?([a-z0-9]+\x3d\d{1,3}\&){9}[a-z0-9]+\x3d\d{1,3}$/ -/^Host:\s*?[a-f0-9]{63,64}\./im -/\/[a-z]{4}\.html\?j\=\d{6,7}$/i -/\/[a-z]{4}\.html\?i\=\d{6,7}$/i -/\/([0-9][0-9a-z]{2}|[0-9a-z][0-9][0-9a-z]|[0-9a-z]{2}[0-9])\.jar$/ -/\/count\d{2}\.php$/ -/\/\d{2}\.html$/ -/\/[a-z]{4}\.html\?h\=\d{6,7}$/i -/[a-z0-9]{32}\.(?:jar|swf)/ -/[a-z0-9]{32}\.jar/ -/\/[a-f0-9]{16}([a-f0-9]{16})?\/ff\.php/ -/\/[a-f0-9]{16}\/q\.php/ -/\.js\/\?[a-z]+\=[a-z]{1,4}/ /\.php\?setup=d\&s=\d+\&r=\d+/i /\.php\?action=jv\&h=\d+/i /^\/jmx.jar?r=\d+/i /^\/jhan.jar?r=\d+/i -/^\/amor\d{0,2}\.jar/ -/\x2F[0-9]{3}\.pdf$/ /\<iframe\ssrc\=[^>]*\x22\swidth\=1\sheight\=1\sframeborder\=/ -/\/Java([0-9]{1,2})?\.jar\?java=[0-9]{2}/ -/\?java\=[0-9]{2,6}$/ -/^\/[a-zA-Z0-9]{24,}\/[0-9]{9,10}\/[0-9]{7,10}$/ -/^\/[a-zA-Z0-9]{24,}\/[0-9]{9,10}\/[a-z]+\.jar$/ -/^\/[a-zA-Z0-9]{24,}\/Qm[a-zA-Z0-9]+\/[a-z]+\.js$/ -/^\/[a-zA-Z0-9]{24,}\/[0-9]{9,10}\/[a-z]+\.pdf$/ -/\/[a-zA-Z0-9]{32}\.jar/ -/\/[a-f0-9]{32}\/q\.php/ -/\/jdb\/inf\.php\?id=[a-f0-9]{32}$/i /\/\[fx]\.jar$/ /\&h=11$/ -/\/[a-zA-Z0-9]{76,81}\/[a-zA-Z0-9]{4,10}\.eot$/ -/\/[a-zA-Z0-9]{76,81}\/[a-zA-Z0-9]{4,10}\.pdf$/ -/\/[a-zA-Z0-9]{4,10}\.jar$/ /\/pdfx\.html$/ -/\x2f\d{3}\.jar/ -/\.php\?[a-z]{2,8}=[a-z0-9]{2}\x3a[a-z0-9]{2}\x3a[a-z0-9]{2}\x3a[a-z0-9]{2}\x3a[a-z0-9]{2}\&[a-z]{2,8}=/ /User-Agent\x3a[^\x0d\x0a]*Java\/1\./ /\.php\?j=1&k=[0-9](i=[0-9])?$/ -/^\x2f[A-Za-z0-9]{33}\?s=\d\&m=\d$/ -/filename\x3d\w{8}\.jar/i /User-Agent\x3a[^\r\n]*Java\/1\./ /User-Agent\x3a[^\r\n]*Java\/1\./ /User-Agent\x3a[^\r\n]*Java\/1\./ /User-Agent\x3a[^\r\n]*Java\/1\./ -/filename\=[a-z0-9]{24}\.exe/ -/filename=p50[a-z0-9]{9}[0-9]{12}\.pdf/ -/filename\=[a-z0-9]{24}\.jar/ -/body\x3e\x3cdiv\s[a-z]{3}\x3d\x22[a-z]{3}\x22/ -/setup=[a-z]\&s=\d\&r=\d{5}$/i /setup=[a-z]$/i -/\&h=\d{5}$/i -/(action|setup)=[a-z]{1,4}/i -/\.php\?[a-z]{2,12}=[a-f0-9]{10,64}&[a-z]{2,12}=.*?&[a-z]{2,12}=/ -/\x3cscript\x3etry\x7b\w+\x2b\x2b([^\x7d]{1,4})?\x7dcatch\x28/smi -/fewbgazr([^\x7d]{1,3})?\x7dcatch\x28/smi -/hwehes[a-z0-9]{15,22}hwehes/smi -/\?page\=[a-f0-9]{16}/smi -/profile\.php\?woman\=[a-f0-9]{16}/smi -/Math\x2eround([^\x7d]{1,3})?\x7dcatch\x28/smi -/Math\x2efloor([^\x7d]{1,3})?\x7dcatch\x28/smi /src=\d+&gpr=\d+&tkr[ib]?=/ -/totype(\x22|\x27)([^\x7d]{1,4})?\x7dcatch\x28/smi -/^\/[0-9]{8}\.html$/ /code=\"[a-z]\.[a-z][\.\"][ c]/ -/<applet[^>]+(archive|src)\s*?=\s*?(\x22|\x27|)\s*?(\d{5}\.jar|[^>]+\/\d{5}\.jar)/smi -/=[0-9a-f]{8}\.jar/ -/^\/[0-9]{5}\.jar$/ -/^\/\w{1,2}\/\w{1,3}\.class$/ -/^images.php\?t=\d{2,7}$/ -/prototype\x2d([^\x7d]{1,5})?\x7dcatch\x28/smi -/g\/\d{9}\/[0-9a-f]{32}\/[0-9]$/ -/index.php\?[0-9a-f]{32}$/ -/src.php\?case\=[a-f0-9]{16}/smi -/showthread\.php\?t\=[a-f0-9]{16}\x27\x3b/smi -/prototype([^\x7d]{1,3})?\x7dcatch\x28/smi -/prototype([^\x7d]{1,3})?\x7dcatch\x28/smi -/([@\x2da-z0-9]+?\x5e){10}/smi -/search\.php\?page=[a-f0-9]{16}$/ -/\.php\?[^=]+?=[a-f0-9]{16}$/ /\d+(.)\d+\1\d+\1\d+\1\d+\1\d+\1/ /adp\d?\.php\?[fe]=/ -/\d{1,3}(.)\d{1,3}\1\d{1,3}\1\d{1,3}\1\d{1,3}\1/ /[\d\.]+/ /pdf\.php\?pdf=[0-9A-F]+&type=\d+&o=[^&]+&b=/ -/var ([^\s]+) = ''\x3Bvar ([^,]+), ([^,]+).*\1 = \1 \+ String\.fromCharCode\(\2\).*\!= 64\) \{ \1 = \1 \+ String\.fromCharCode\(\3\)\x3b\}.*\x3breturn unescape\(\1\)\x3b\}return 0\x3b\}/ /^\/load\.php\?spl=[^&]+&b=[^&]+&o=[^&]+&i=/ /CRiMEPACK [\d\.]+/ /load\.php\?spl=(Spreadsheet|DirectX_DS|MS09-002|MS06-006|mdac|RoxioCP v3\.2|wvf|flash|Opera_telnet|compareTo|jno|Font_FireFox|pdf_exp|aol|javad|ActiveX_pack)/ /\?spl=\d&br=[^&]+&vers=[^&]+&s=/ /\?spl=\d&br=[^&]+&vers=[^&]+&s=/ -/(,\d{1,3}){20}/ -/(#\d{1,2}){20}/ /\/[a-z]\.php\?e=[\da-f]+&f=[\da-f]+$/ /\/[a-z]\.php\?f=[\da-f]+&e=[\da-f]+$/ -/main\.php\?page=[a-f0-9]{16}$/ -/stat2\.php\?w=\d+\x26i=[0-9a-f]{32}\x26a=\d+/i /\.php\?b=[A-F0-9]+&v=1\./ /\&k=\d+($|\&h=)/ /php\?sf=\d+\&Ze=\d+\&m=\d+/ -/\/[a-f0-9]{32}\/a\.php/ -/\/[a-f0-9]{16}\/a\.php/ /\/jovf\.html$/ /\/jlnp\.html$/ /\/jorg\.html$/ /\x2ephp\x3f[a-z]+=[a-fA-Z0-9]+&[a-z]+=[0-9]+$/i -/filename\=\d{4}\.exe$/ -/\x2fn\.php\?h=[a-zA-Z0-9]*?\&s=[a-zA-Z0-9]{1,5}$/i -/\x2f\?[0-9a-f]{60,66}[\x3b\d]*$/ -/\/(?:[^\/]+?\/[a-z]{2,24}[_-][a-z]{2,16}([_-][a-z]{2,16})*?|closest\/[a-z0-9]{15,25})\.php\?[\(\)\!\*\w-]+=[\(\)\!\*\w-]+&[\(\)\*\!\w-]+=[\(\)\!\*\w-]+$/ /\/m1\.exe$/ -/^\/[a-f0-9]{32}\/[a-z]{1,15}-[a-z]{1,15}\.php/ /for\x28(?P\w+)=0\x3b(?P=var)<(?P\w+)\.innerHTML.length\x3b(?P=var)\+=2\x29\x20\w+\+=\w+\x28(?P=var2)/ -/^\/[a-z0-9]{32}\/[a-z0-9]{32}\.jnlp/ -/\/(?:[^\/]+?\/[a-z]{2,24}[_-][a-z]{2,16}([_-][a-z]{2,16})*?|closest\/[a-z0-9]{15,25})\.php\?[\(\)\!\*\w-]+=[\(\)\!\*\w-]+&[\(\)\*\!\w-]+=[\(\)\!\*\w-]+&[\(\)\!\*\w-]+=[\(\)\!\*\w-]+&[\(\)\!\*\w-]+=[\(\)\!\*\w-]+&[\(\)\!\*\w-]+=[\(\)\!\*\w-]+$/ -/^\/[a-f0-9]{32}\/[0-9]$/i -/^\/[a-f0-9]{32}\/[a-f0-9]{32}\.jar$/i -/^\/[a-f0-9]{32}\/[a-f0-9]{32}\.swf$/i -/^\/[a-f0-9]{8}\.js\?cp\x3d/mi -/^\/blog\/[a-zA-Z0-9]{3}\.(g(3|e)d|mm|vru|be|nut)$/ -/\/[0-9a-f]{32}\/[0-9]{10}\.pdf$/ -/\/(?:[^\/]+?\/[a-z]{2,24}|closest\/[a-z0-9]{15,25})\.php\?[ab10]+=[ab10]+&[ab10]+=[ab10]+$/ -/\/(?:[^\/]+?\/[a-z]{2,24}|closest\/[a-z0-9]{15,25})\.php\?[ab10]+=[ab10]+&[ab10]+=[ab10]+&[ab10]+=[ab10]+&[ab10]+=[ab10]+&[ab10]+=[ab10]+$/ -/\.php\?catalogp\=\d{2}$/ -/^\/[a-f0-9]{32}\/\d{10}\/[a-f0-9]{32}\.jar$/i /^\/\d+\.ld$/ /\/[a-zA-Z_-]+\.ee$/ /^\/\d+/\d\.zip$/ -/\/[a-z0-9]{9}\.jnlp$/ /\/\d+\/\d\.zip\x27\x3b/ -/\/[a-f0-9]{32}\/\d{10}\/[a-f0-9]{32}\/\d{10}\.tpl$/ /filename=[\x22\x27]?\d\.exe[\x22\x27]?/i -/^\/i.html\?[a-z0-9]{4}\x3[a-z0-9]{15}/smi /\/[a-z]+\?[a-z]+\=[a-z]+$/ -/Referer\x3a\x20[^\s]*\x3a8000\x2f[a-z]+\?[a-z]+=\d{6,7}\x0d\x0a/ -/Referer\x3a\x20[^\s]*\x3a8000\x2f[a-z]+\?[a-z]+=\d{6,7}\x0d\x0a/ -/^\/1[a-z]{0,13}[0-9]{0,12}[a-z][a-z0-9]{1,11}$/ -/^\/0[a-z]{0,13}[0-9]{0,12}[a-z][a-z0-9]{1,11}$/ /\/[a-zA-Z_-]+\.rtf$/ /\/[a-zA-Z_-]+\.doc$/ -/^\/f\/1\d{9}\/\d{9,10}(\/\d)+$/ -/^\/\d{9,10}\/1\d{9}\.jar$/ -/^\/\d{10}\/\d{10}\.tpl$/ /^\/cnt\.php\?id=\d+$/ /\/\d+\.mp3$/ -/\x2f[a-z]+\?[a-z]+=\d{6,7}$/ /Referer\x3a[^\n]*fla\.php\?wq=[a-f0-9]+\x0d\x0a/ /\.php\?hgfc\=[a-f0-9]+$/ /\.html\?jar$/ -/\.html\?sv=[1-5](\,\d+?){1,3}$/ -/^\/\d{1,2}(?[A-Z])\d{1,2}(?=letter)\d{1,2}(?=letter)\d{1,2}\.pdf$/ -/^\/\d{4}\/\d{7}$/ -/filename=(?![a-f]{24}|\d{24})[a-f\d]{24}\.exe\r\n/ -/\/[a-f0-9]{32}\.jar$/ -/\/[a-f0-9]{32}\.swf$/ -/\/(?:java(?:db|im|rh)|silver|flash|msie)\.php\?id=[a-f\d]{20}/i -/^\/\?[a-f0-9]{32}$/ -/^\/[a-f0-9]{32}\.eot$/ -/^\/\d{8,11}\/1[34]\d{8}\.pdf$/ -/^(\/\d{8,11})?(\/\d)?\/1[34]\d{8}\.htm$/ -/\/i\.html\?[a-z0-9]+\=[a-zA-Z0-9]{25}/ -/\/\?[a-z0-9]{9}\=[a-zA-Z0-9]{45}/ /\/fnts\.html$/ -/^\/\/?[a-z0-9_]{7,8}\/\??[0-9a-f]{60,68}[\x3b\x2c\d+]*$/ -/^\/[a-z0-9_-]{48}$/i /\/download\.asp\?p\=\d$/i /\?a=dw[a-z]$/ /var\s(?P\w+)\s?=\s?document\.createElement\x28\x22iframe\x22\x29.*?(?P=name)\.style\.visibility.*?(?P=name)\.src\s?=\s?[\x22\x27][^\x22\x27]*\.php.*?\.appendChild\x28(?P=name)\x29/i -/^\/f(?:\/\d)?\/1[34]\d{8}(?:\/\d{9,10})?(?:\/\d)+[^a-zA-Z]{1,6}$/ -/^(?:\/\d{9,10})?(?:\/\d)?\/1[34]\d{8}\.jar$/ /\/\d+\.mp3\?rnd=\d+$/ -/^\/(?:[\/_]*?[a-f0-9]){32}[\/_]*?\/\d+?$/ -/^\/(?:[a-f0-9]{32}\/[a-f0-9]{32})$/ -/\/[a-f0-9]{32}\/[a-f0-9]{32}\x22/ /\d+\.mp3$/ -/^\/\d{9,10}\/1\/1\d{9}\.pdf$/ /\.php\?req=(?:x(?:ap|ml)|swf(IE)?|mp3|jar)\&/i -/^\/[a-f0-9]{32}\.php\?q=[a-f0-9]{32}$/ /var\s+(?P\w+)\=function\(.*?\x27\x2b(?P=name)\(\d+\x29/ -/\/[a-f0-9]{32}\.jar/ -/\/load(?:(?:db|rh|silver|msie|im|flash|fla[0-9]{4,5}))\.php/ /\/java(rh|db)\.php$/ /\/flash201(3|4)\.php$/ /^[\w+\/]+(?:(?:LmvdA|5lb3Q)==?|uZ90)[\x22\x27]/si -/[a-zA-Z0-9]\/[a-f0-9]{5}\.swf[\x22\x27]/ -/^\/[-\w]{70,78}==?$/ -/^(?:\/\d{9,10})?(?:\/[16])?\/1[34]\d{8}\.swf$/ /\/modules\/\d\.jar$/ /\/load_module\.php\?user\=(n1|1|2|11)$/ /\/modules\/(n?\d|nu)\.swf$/ /\x3bfunction\s(?P\w)\x28.*\x3b(?P=name)\x28\x22[\da-z]+\x22\x29\x3b/ -/\/3\/[A-Z]{2}\/[a-f0-9]{32}\sTT/ -/\/3\/[A-Z]{2}\/[a-f0-9]{32}\.mkv/ -/\/3\/[A-Z]{2}\/[a-f0-9]{32}\.djvu/ -/\/3\/[A-Z]{2}\/[a-f0-9]{32}\/\d+\.\d+\.\d+\.\d+\// /filename=[a-z]+\.jat/ -/^\/[\w-]{60,78}$/ -/GET\s\/[\w-]{64}\sTT\/1\.[^\x2f]+ost\x3a\x20[^\x3a]+\x3a\d+\x0d\x0a/ -/^\/\d{2,4}\.xap$/ -/\/[a-z]{1,4}\x2ehtml\x3f0\x2e[0-9]{15,}$/ /(var jquery_datepicker=)|(jquery_datepicker.replace)/ /Host\x3a[^\n]+\x3a\d+\x0d\x0a/ /\x2f[\w\x2d]*\x2e+$/m /^User-Agent:[^\n]*?MSIE\s[56]/mi /^User-Agent:[^\n]*?MSIE\s[56]/mi /^User-Agent:[^\n]*?MSIE\s[56]/mi -/css\s*?\x28\s*?[\x22\x27]margin[^\x29]*?[\x22\x27]\s*?\x2c\s*?[\x22\x27]\d{12,}\s*?px/smi -/css\s*?\x28\s*?[\x22\x27]margin[^\x29]*?[\x22\x27]\s*?\x2c\s*?[\x22\x27]\d{12,}\s*?px/smi -/((?!).)*?function (?\w+).*?\{[^}]*?location\.reload\(.*?]*?onload\s*=\s*[\x22\x27](?=onload)/ims -/((?!).)*?function (?\w+).*?\{[^}]*?history\.go\(\s*0\s*\).*?]*?onload\s*=\s*[\x22\x27](?=onload)/ims -/((?!).)*?function (?\w+).*?\{[^}]*?location\.reload\(.*?]*?onload\s*=\s*[\x22\x27](?=onload)/ims -/((?!).)*?function (?\w+).*?\{[^}]*?history\.go\(\s*0\s*\).*?]*?onload\s*=\s*[\x22\x27](?=onload)/ims /document\.execCommand\s*\(\s*([\x22\x27])superscript\1\s*\)/ims /var\s+?(?P[^\s]+?)\s*?=\s*?document\.createElement\(.*?(?P=var)\.runtimeStyle.*?\.border[^=\x3b]*?=\s*?[^\x3b]*?[\x22\x27](\d+?\s|\s+?\d)/smi /var\s+?(?P[^\s]+?)\s*?=\s*?document\.createElement\(.*?(?P=var)\.runtimeStyle.*?\.border[^=\x3b]*?=\s*?[^\x3b]*?[\x22\x27](\d+?\s|\s+?\d)/smi @@ -1599,33 +1261,22 @@ /setInterval\s*\x28[^\x29]+\x2efocus\x28\x29/smi /]*src\s*=\s*[\x22\x27][^\x22\x27]*\.json[\x22\x27][^>]*language=vbs/i /]*src\s*=\s*[\x22\x27][^\x22\x27]*\.json[\x22\x27][^>]*language=vbs/i -/<\s*style[^>]*?(?=.{20,512}<\s*\/\s*style\s*>).{0,500}\{\s*\;\s*\w+\s*=\s*expression\s*\x28/ims /\w*).*?\w*)\s*\x28\x29.*?\x7b[^\x7d]*?document\x2ewrite.*?\w*).*?\w*)\s*\x28\x29.*?\x7b[^\x7d]*?document\x2ewrite.*?]*?(?>content\s*=\s*"history"[^>]*?name\s*=\s*"save"|name\s*=\s*"save"[^>]*?content\s*=\s*"history")\s*>.*?<\s*style[^>]*?>.*?\.(?P\w+)\s*\{[^}]*?behavior\s*\:[^\;]*?url\s*\x28[^\x29]*?#savehistory[^\x29]*?\x29.*?(?P\w+)\.outerHTML\s*=.*?id\s*=\s*[\x22\x27](?P=element)[\x22\x27].*?class=[\x22\x27]?(?P=class)[\x23\x27]?/ims -/<\s*meta[^>]*?(?>content\s*=\s*"history"[^>]*?name\s*=\s*"save"|name\s*=\s*"save"[^>]*?content\s*=\s*"history")\s*>.*?<\s*style[^>]*?>.*?\.(?P\w+)\s*\{[^}]*?behavior\s*\:[^\;]*?url\s*\x28[^\x29]*?#savehistory[^\x29]*?\x29.*?(?P\w+)\.outerHTML\s*=.*?id\s*=\s*[\x22\x27](?P=element)[\x22\x27].*?class=[\x22\x27]?(?P=class)[\x23\x27]?/ims /]*?PUT\s*=\s*[\x22\x27](?P\w*).*?function\s*(?P=func).*?\x7b[^\x7c]*?CollectGarbage\x28\x29/sm /]*?PUT\s*=\s*[\x22\x27](?P\w*).*?function\s*(?P=func).*?\x7b[^\x7c]*?CollectGarbage\x28\x29/sm /(?P[A-Z\d_]+)\x2Estyle\x2Ebehavior\s*\x3D\s*\x22url\x28\x27\x23default\x23userData\x27\x29\x22.*?(?P=obj)\x2EsetAttribute\x28[^,]+,\s*[A-Z]/smi /]+name\s*=\s*[\x22\x27](?P\w+)[\x22\x27].*?><\x2fiframe\s*>.*?window\x2eopen\x28.{1,30}(?P=iframe_name).*?window\x2eopen\x28.{1,60}(?P=iframe_name)/smi -/\w+)[\x22\x27]?)*><\x2fiframe\s*>.*?window\x2eopen\x28.{1,30}(?P=iframe_name).*?window\x2eopen\x28.{1,60}(?P=iframe_name)/smi -/]+?dir\s*?=\s*?[\x22\x27]\s*?rtl\s*?[\x22\x27].*?(&#?x?[a-z\d]{2,4}\x3b){100}/si -/]+?dir\s*?=\s*?[\x22\x27]\s*?rtl\s*?[\x22\x27].*?(&#?x?[a-z\d]{2,4}\x3b){100}/si -/]*?>.*?<[^>]*?\sid=(?P(\x22|\x27|))(?P[^\x22\x27\s>]+?)(?P=q1).*?<[^>]*?\s+id=(?P(\x22|\x27|))(?P[^\x22\x27\s>]+?)(?P=q2).*?<\x2fsvg>.*?]*?>.*?(document\.getElementById\([^)]*?((?P=id1)|(?P=id2))[^)]*?\).*?\.setCapture\(.*?\).*?){2}/smi /var\s+?(?P[^\s]+?)\s*?=\s*?document\.selection\.createRange\([^\(]*?\).*?var\s+?(?P[^\s]+?)\s*?=\s*?document\.body\.getElementsByTagName\(\s*?[\x22\x27]\s*?\*\s*?[\x22\x27]\s*?\).*?var\s+?(?P[^\s]+?)\s*?=\s*?(?P=elements)\s*?\[\s*?\d\s*?\].*?(?P=range)\.moveToElementText\(\s*?(?P=el)\s*?\).*?(?P=range)\.collapse\(\s*?true\s*?\).*?(?P=range)\.select\(.*?(?P=range)\.pasteHTML\(/si /var\s+?(?P[^\s]+?)\s*?=\s*?document\.body\.getElementsByTagName\(\s*?[\x22\x27]\s*?\*\s*?[\x22\x27]\s*?\).*?var\s+?(?P[^\s]+?)\s*?=\s*?(?P=elements)\s*?\[\s*?\d\s*?\].*?var\s+?(?P[^\s]+?)\s*?=\s*?document\.selection\.createRange\([^\(]*?\).*?(?P=range)\.moveToElementText\(\s*?(?P=el)\s*?\).*?(?P=range)\.collapse\(\s*?true\s*?\).*?(?P=range)\.select\(.*?(?P=range)\.pasteHTML\(/si -/var\s*?(?P\w+)s*?=s*?document.createElement\s*?\([\x22\x27][\w]s*?[\x3a\x3b]\s*?shape[\x22\x27]\).*?(?P=m1)s*?.\s*?setAttribute\s*?\(\s*?[\x22\x27]\s*?path\s*?[\x22\x27]\s*?,\s*?[\x22\x27][^\x29]{506}.*?(?P=m1)\.s*?path/smi /onbeforeeditfocus\s*?=\s*?[\x22\x27]document\x2ewrite/ism /window\x2elocation\s*=\s*unescape\s*\x28\s*["']\x25[^"']*https?\x3a/ /window\x2elocation\s*=\s*unescape\s*\x28\s*["']\x25[^"']*https?\x3a/ /getElementById\s*\x28\s*[\x22\x27](?P[^\x22\x27]*?)[\x22\x27]\s*\x29\.remove.*?<\s*marquee[^>]*?id\s*=\s*[\x22\x27](?P=id)[\x22\x27]/ims /<\s*marquee\s*([^>]*?height\s*=\s*[\x22\x27]?0[^\d]|>\s*<\s*\/\s*marquee\s*>|[^>]*?id\s*=\s*[\x22\x27](?[^\x22\x27]*?)[\x22\x27].*?getElementyd\s*\x28\s*[\x22\x27](?=id)[\x22\x27]\s*\x29\.remove)/ims -/appendChild\x28\s*document\x2ecreateElement\x28\s*[\x22\x27]button[\x22\x27].*?outerText\s*=\s*[\x22\x27]{2}/smi -/appendChild\x28\s*document\x2ecreateElement\x28\s*[\x22\x27]button[\x22\x27].*?outerText\s*=\s*[\x22\x27]{2}/smi /(body\s*?onload\s*?\x3d\s*?[\x22\x22](?P\w+).*?function\s*?(?P=func)\s*?\x28[^\x7b]+?\x7b[^\x7d]+?var\s*?(?P\w+)\s*?\x3d\s*?document\.getElement[^\x7d]+?\.style\.\w+\s*?\x3d\s*?document\.createElement[^\x7d]+?CollectGarbage[^\x7d]+?(?P=var)\.(inner|outer)HTML)|(function\s*?(?P\w+)\s*?\x28[^\x7b]+?\x7b[^\x7d]+?var\s*?(?P\w+)\s*?\x3d\s*?document\.getElement[^\x7d]+?\.style\.\w+\s*?\x3d\s*?document\.createElement[^\x7d]+?CollectGarbage[^\x7d]+?(?P=var2)\.(inner|outer)HTML.*?body\s*?onload[^\x3e]+?)(?P=func2)/ims /]+?id\s*?\x3d\s*?(?P\x22|\x27|)(?P\w+)(?P=quoteVar1).*?button.*(?P=fieldName)\x2einnerHTML.*?button/smi /]+?id\s*?\x3d\s*?(?P\x22|\x27|)(?P\w+)(?P=quoteVar1).*?button.*(?P=fieldName)\x2einnerHTML.*?button/smi @@ -1635,12 +1286,8 @@ /execCommand\x28\s*?[\x22\x27]selectAll[\x22\x27]\s*?\x29/i /body[^>]*?onload[^>]*?onselect/i /<\s*script.*?(?P\w+)\s*=\s*document\.getElementById\s*\x28\s*[\x22\x27](?P[^\x22\x27]+)[\x22\x27]\s*\x29.*?((?P=var)\.span.*?<\s*table.*?]*?id\s*=\s*[\x22\x27]?(?P=col_id)[^>]*?>.*?<\s*\/\s*table\s*>|<\s*col.*?id\s*=\s*[\x22\x27]?(?=col_id)[^>]*?span\s*=\s*[\x22\x27]?\d)/ims -/<[^>]*?style\s*[>=].{1,1024}margin\s*\x3a\s*[^\x3b\x7d]*?-\d+.*?[\x7b\x3b]/ims /\x2eonreadystatechange\s*=\s*(?P\w+)\s*\x3b.*?function\s+(?P=del_func)\s*\x28[^\x7b]*?\x7b[^\x7d]*?\x2e(?:innerHTML\s*=|outerHTML\s*=|write)/smi /function\s+[a-z0-9_]+\s*\x28.*?(?P[a-z0-9_]+)\s*=\s*[^\x3B]*?\x2Erecordset\x3B.*?(?P=var)\x2EcacheSize\s*=\s*-0x.*?(?P=var)\x2EMove/smi -/(.*?(<[uo]l[^>]*?>.*?){6,}]*?>.*?]*?>[^\x3b]*?innerHTML\s*=[^\x3b]*?\x3b)|().)*?function (?\w+).*?\{[^}]*?document\.writeln\([\x22\x27]{2}\).*?]*?on(scroll|load)\s*=\s*[\x22\x27](?=onload)/ims -/((?!).)*?function (?\w+).*?\{[^}]*?document\.writeln\([\x22\x27]{2}\).*?]*?on(scroll|load)\s*=\s*[\x22\x27](?=onload)/ims -/[\w\W]{680}/smi -/[\w\W]{680}/smi -/(?P[a-z0-9]+)\s*\x3D\s*document\x2EcreateElement\x28[\x22\x27]media[\x22\x27]\x29.*?(?P=var)\x2EinnerHTML\s*\x3D\s*[\x22\x27]\x3Cruby\x3E[\x22\x27].*?(?P=var)\x2EinnerHTML\s*\x3D\s*[\x22\x27]{2}/smi -/(?P[a-z0-9]+)\s*\x3D\s*document\x2EcreateElement\x28[\x22\x27]media[\x22\x27]\x29.*?(?P=var)\x2EinnerHTML\s*\x3D\s*[\x22\x27]\x3Cruby\x3E[\x22\x27].*?(?P=var)\x2EinnerHTML\s*\x3D\s*[\x22\x27]{2}/smi /function.*?\x28[^\x7b]+?\x7b[^\x7d]+?var\s*?(?P\w+)\s*?\x3d[^\x7d]+?\.createRange\x28[^\x7d]+?(?P=var)\.deleteContents\x28[^\x7d]+?\.execCommand\x28\s*?[\x22\x27]\s*?insertIFrame/ims /function.*?\x28[^\x7b]+?\x7b[^\x7d]+?var\s*?(?P\w+)\s*?\x3d[^\x7d]+?\.createRange\x28[^\x7d]+?(?P=var)\.deleteContents\x28[^\x7d]+?\.execCommand\x28\s*?[\x22\x27]\s*?insertIFrame/ims /(?P