Comments (10)
The regexp is quite complex yeah, I cannot really help you but saying that I
believe
the regexp is not well formed. Just a simple fact, the parenthesis don't match.
Did you try with the php-ids engine to see if it was compiling correctly --
which I
double? If not, you might want to report it there.
I still leave this issue open since I'm not sure what the problem exactly is.
Original comment by [email protected]
on 24 Apr 2009 at 2:15
from apache-scalp.
Original comment by [email protected]
on 24 Apr 2009 at 2:18
- Added labels: Usability
from apache-scalp.
[deleted comment]
from apache-scalp.
same thing still happening
Original comment by [email protected]
on 26 Jul 2009 at 8:38
from apache-scalp.
Remove the bloc lines numbered 45, and it will work.
This kind of regexp are hardley readable...
Original comment by [email protected]
on 28 Dec 2009 at 5:38
from apache-scalp.
fgeek@example:~$ ./scalp-0.4.py -l sites/example.org/log/access.log
error: the filters file (XML) doesn't exist
please download it at
https://svn.php-ids.org/svn/trunk/lib/IDS/default_filter.xml
File default_filter.xml still has that regexp and should be removed/changed.
b9a147a93ade7540982ba792e54cc8a6a427a9d1 default_filter.xml
dd4c6a2800e7ebb135a61526a88c231901cf5599 scalp-0.4.py
Original comment by [email protected]
on 1 Jul 2010 at 5:37
from apache-scalp.
IWFM: Removed filter id 44,45,46 from .xml
Original comment by [email protected]
on 30 Aug 2010 at 8:09
from apache-scalp.
I've found a few links to this in the historical updates wiki ( trac ) which
show this section changing in rule 45:
"<id>45</id><rule><![CDATA[(?:union\s*(?:all|distinct|[(!@]*)\s*[([]*\s*select)|
(?:\w+\s+like\s+\"
I've found that there are versions with "(!@]*)?\s*" and "(!@]*)*\s*", but
older versions have "(!@]*)\s*".
I've found that the last version permits it to compile and run fine ( although
the developers must be seeing some misidentification or they wouldn't fix it..
;-)
HTH, tom.
Original comment by [email protected]
on 25 Oct 2010 at 3:27
from apache-scalp.
Number 73 '(?i:(\%SYSTEMROOT\%))' doesn't compile either.
Original comment by [email protected]
on 6 Jan 2013 at 12:14
from apache-scalp.
The most up to date file is here:
https://raw.github.com/PHPIDS/PHPIDS/master/lib/IDS/default_filter.xml
Original comment by [email protected]
on 5 Sep 2013 at 3:42
from apache-scalp.
Related Issues (19)
- scalp 0.4 : error: the log file doesn't exist HOT 2
- Default filter file is at a new URL.
- issue when running sclep HOT 1
- Show ip for each match
- while using --period (IndexError: list index out of range) HOT 2
- error while using --period
- cannot be compiled properly issue HOT 4
- Feature Request
- C++ Changes and output
- XML file isn't available HOT 1
- Running on Windows ?
- SyntaxError: invalid syntax with python 2.5, need 2.4/2.3 compatibility HOT 19
- A bunch of false positives HOT 7
- SyntaxError: invalid syntax HOT 1
- Scalp not able to compile rule propery HOT 5
- Link to default_filters.xml on the Project Home page is incorrect
- Loading XML file './default_filter.xml'... The rule '(?:union....cannot be compiled properly HOT 20
- Scalp processes zero lines HOT 3
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from apache-scalp.