1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203
|
# Word list for rule 932150 (RCE Unix command injection)
# To lower FP, this rule requires whitespace after a command.
#
# To convert to a regexp that can be pasted into the rule:
# cat regexp-932150.txt | ./regexp-cmdline.py unix | ./regexp-assemble.pl
#
# Entries starting with ' are used verbatim.
# Everything after # is a comment.
#
bash
bsdcat
bsdiff
bsdtar
builtin
bzcat
bzdiff
bzegrep
bzfgrep
bzgrep
bzless
bzmore
cc
command
coproc
csh
curl
dash
diff
dmesg
doas
echo
egrep
env
eval
exec
fetch
fgrep
filetest
ftpstats
ftpwho
gcc
GET
grep
gzcat
gzip
head
hup
irb
irb1
irb18
irb19
irb20
irb21
irb22
java
jobs -x
lastcomm
lastlog
lastlogin
lessecho
lessfile
lesspipe
lftp
lftpget
ls
ls-F
lsb_release
lscpu
lsmod
lsof
lspci
lsusb
lwp
lwp-download
lynx
lzcat
lzcmp
lzdiff
lzegrep
lzfgrep
lzgrep
lzless
lzma
lzmore
mailq
mlocate
mysqladmin
mysqldump
mysqldumpslow
mysqlhotcopy
mysqlshow
nc
nc.openbsd
nc.traditional
ncat
netcat
netkit-ftp
netstat
nohup
nping
nstat
onintr
perl
perl5
pftp
pgrep
php
php5
php7
ping
pkexec
pkill
popd
printenv
ptar
ptardiff
ptargrep
python
python2
python3
python3m
rcp
realpath
rename
repeat
replace
rmdir
rmuser
rnano
rsync
ruby
ruby1
ruby18
ruby19
ruby20
ruby21
ruby22
sched
scp
sdiff
sed
sendmail
setenv
setsid
sftp
sh
sh.distrib
socat
source
ssh
strings
sudo
svn
sysctl
tail
tailf
tar
tcping
tcptraceroute
tcsh
telnet
time
timeout
traceroute
traceroute6
uname
uncompress
unlzma
unrar
unset
unxz
unzip
useradd
userdel
usermod
vigr
vipw
w3m
wget
whoami
xargs
xz
xzcat
xzcmp
xzdec
xzdiff
xzegrep
xzfgrep
xzgrep
xzless
xzmore
zcat
zcmp
zdiff
zegrep
zfgrep
zgrep
zip
zless
zmore
zrun
zsh
|