Giter VIP home page Giter VIP logo

burp-regexer's People

Contributors

brnoleal avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar

Forkers

pr0xh4ck

burp-regexer's Issues

Pergunta sobre TOP REGEX

Ei

Parabéns pelo projeto.

Gostaria de saber se o correto para o "top regex" não deve ser o seguinte:

"Top 25 Cross-Site Scripting (XSS) Parameters": {
        "description": "",
        "regex": "[\?|&]q=|[\?|&]s=|[\?|&]search=|[\?|&]id=|[\?|&]lang=|[\?|&]keyword=|[\?|&]query=|[\?|&]page=|[\?|&]keywords=|[\?|&]year=|[\?|&]view=|[\?|&]email=|[\?|&]type=|[\?|&]name=|[\?|&]p=|[\?|&]month=|[\?|&]image=|[\?|&]list_type=|[\?|&]url=|[\?|&]terms=|[\?|&]categoryid=|[\?|&]key=|[\?|&]l=|[\?|&]begindate=|[\?|&]enddate="
    },
    "Top 25 Server-Side Request Forgery (SSRF) Parameters": {
        "description": "",
        "regex": "[\?|&]dest=|[\?|&]redirect=|[\?|&]uri=|[\?|&]path=|[\?|&]continue=|[\?|&]url=|[\?|&]window=|[\?|&]next=|[\?|&]data=|[\?|&]reference=|[\?|&]site=|[\?|&]html=|[\?|&]val=|[\?|&]validate=|[\?|&]domain=|[\?|&]callback=|[\?|&]return=|[\?|&]page=|[\?|&]feed=|[\?|&]host=|[\?|&]port=|[\?|&]to=|[\?|&]out=|[\?|&]view=|[\?|&]dir="
    },
    "Top 25 Local File Inclusion (LFI) Parameters": {
        "description": "",
        "regex": "[\?|&]cat=|[\?|&]dir=|[\?|&]action|[\?|&]board=|[\?|&]date=|[\?|&]detail=|[\?|&]file=|[\?|&]download=|[\?|&]path|[\?|&]folder=|[\?|&]prefix=|[\?|&]include=|[\?|&]page=|[\?|&]inc=|[\?|&]locate=|[\?|&]show=|[\?|&]doc=|[\?|&]site=|[\?|&]type=|[\?|&]view=|[\?|&]content=|[\?|&]document=|[\?|&]layout=|[\?|&]mod=|[\?|&]conf="
    },
    "Top 25 SQL Injection Parameters": {
        "description": "",
        "regex": "[\?|&]id=|[\?|&]page=|[\?|&]report=|[\?|&]dir=|[\?|&]search=|[\?|&]category=|[\?|&]file=|[\?|&]class|[\?|&]url=|[\?|&]news=|[\?|&]item=|[\?|&]menu=|[\?|&]lang=|[\?|&]name=|[\?|&]ref=|[\?|&]title=|[\?|&]view=|[\?|&]topic=|[\?|&]thread=|[\?|&]type=|[\?|&]date=|[\?|&]form=|[\?|&]main=|[\?|&]nav=|[\?|&]region="
    },
    "Top 25 Remote Code Execution (RCE) Parameters": {
        "description": "",
        "regex": "[\?|&]cmd=|[\?|&]exec=|[\?|&]command=|[\?|&]execute=|[\?|&]ping=|[\?|&]query=|[\?|&]jump=|[\?|&]code|[\?|&]reg=|[\?|&]do=|[\?|&]func=|[\?|&]arg=|[\?|&]option=|[\?|&]load=|[\?|&]process=|[\?|&]step=|[\?|&]read=|[\?|&]feature=|[\?|&]exe=|[\?|&]module=|[\?|&]payload=|[\?|&]run=|[\?|&]print="
    },
    "Top 25 Open Redirect Parameters": {
        "description": "",
        "regex": "[\?|&]format=|[\?|&]next=|[\?|&]url=|[\?|&]target=|[\?|&]rurl=|[\?|&]dest=|[\?|&]destination=|[\?|&]redir=|[\?|&]redirect_uri|[\?|&]redirect_url=|[\?|&]redirect=|[\?|&]out=|[\?|&]view=|[\?|&]to=|[\?|&]image_url=|[\?|&]go=|[\?|&]return=|[\?|&]returnTo=|[\?|&]return_to=|[\?|&]checkout_url=|[\?|&]continue=|[\?|&]return_path="
    }

em vez de como está atualmente. Nesse sentido, identificaria apenas os parâmetros em urls e não strings contendo o trecho.

Saudações

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.