PATH:
opt
/
bitninja-waf3
/
coreruleset
/
regex-assembly
/
include
##! Please refer to the documentation at ##! https://coreruleset.org/docs/development/regex_assembly/. ##! This is a list of schemes that can be used for RFI/SSRF (from https://en.wikipedia.org/wiki/List_of_URI_schemes): acap afp afs attachment beshare bitcoin blob callto cap cid cvs dav data dict dns dntp ed2k expect fd feed file finger fish ftp ftps git go gopher h323 http https iax icap imap imaps ipp ipps irc irc6 ircs jabber jar ldap ldapi ldaps local_file mailto maven mms mumble netdoc news nfs nntp nntps ogg paparazzi phar pop2 pop3 pop3s pres proxy psyc rmi rsync rtm rtmfp rtmp s3 sftp sip sips smb smtp smtps sms snews snmp ssh ssh2 svn svn\+ssh teamspeak telnet tftp turn turns udp unreal ut2004 ventrilo view-source vnc webcal ws wss xmpp xri ##! Adding also the list of PHP (sub)schemes that can be used for RFI/SSRF (from https://www.php.net/manual/en/wrappers.php): ssh2.shell ssh2.exec ssh2.tunnel ssh2.sftp ssh2.scp compress.zlib compress.bzip2 zip glob rar ogg expect php
[-] url-schemes.ra
[edit]
[-] charset-specification-no-anchors.ra
[edit]
[-] windows-commands-prefix.ra
[edit]
[+]
..
[-] unix-shell-pl3.ra
[edit]
[-] 932130.ra
[edit]
[-] unix-shell-upto3.ra
[edit]
[-] js-truthy-values.ra
[edit]
[-] unix-shell-evasion-prefix.ra
[edit]
[-] charset-specification.ra
[edit]
[-] sql-injection-function-names.ra
[edit]
[-] unix-shell-evasion-prefix-start-of-string.ra
[edit]
[-] windows-commands.ra
[edit]
[-] sql-injection-mysql-postgresql-procedures-functions.ra
[edit]
[-] allowed-charsets.ra
[edit]
[-] unix-shell-4andup.ra
[edit]