“( \s|\S)*(exec(\s|\+)+(s|x)p\w+)(\s|\S)*” //Exec Commond
“( \s|\S)*((%3C)|<)((%2F)|/)*[a-z0-9%]+((%3E)|>)(\s|\S)*” //Simple XSS
“( \s|\S)*((%65)|e)(\s)*((%76)|v)(\s)*((%61)|a)(\s)*((%6C)|l)(\s|\S)*” //Eval XSS
“( \s|\S)*((%3C)|<)((%69)|i|I|(%49))((%6D)|m|M|(%4D))((%67)|g|G|(%47))[^\n]+((%3E)|>)(\s|\S)*” //Image XSS
“( \s|\S)*((%73)|s)(\s)*((%63)|c)(\s)*((%72)|r)(\s)*((%69)|i)(\s)*((%70)|p)(\s)*((%74)|t)(\s|\S)*” //Script XSS
“( \s|\S)*((%27)|(‘)|(%3D)|(=)|(/)|(%2F)|(“)|((%22)|(-|%2D){2})|(%23)|(%3B)|(;))+(\s|\S)*” //SQL Injection
幾種常見攻擊的正則表達式
標簽:exec