//get intercept rule$getfilter= "\\<.+javascript:window\\[.{ 1}\\\\x|<.*= (&#\\d+?;?) +?>|<.* (DATA|SRC) =data:text\\/html.*>|\\b (alert\\ (|confirm\\ (|expression\\ (|prompt\\ (|benchmark\s*?\\ (\d+?| Sleep\s*?\\ ([\d\.] +?\\) |load_file\s*?\\ () |<[a-z]+?\\b[^>]*?\\bon ([A-z]{4,}) \s*?=|^\\+\\/v (8|9) |\\b (and|or) \\b\\s*? (\ \ \ \ \ \ \ \ \\d]+?=[\\ (\ \) ' \ "\\d]+?| [\ \ \ \ \ \ \ a-za-z]+?=[\\ (\ \) ' \ ' a-za-z]+?| >|<|\s+? [\\w]+?\\s+?\\bin\\b\\s*?\ (|\\blike\\b\\s+?[ \ "']) |\\/\\*.+?\\*\\/|<\\s*script\\b|\\bexec\\b| Union.+? SELECT (\ \ +\\) |\\s+?. +?)| UPDATE (\ \ +\\) |\\s+?. +?) Set| Insert\\s+into.+? values| (select| DELETE) (\ \ (. +\\) |\\s+?. +?\\s+?) From (\ \ (. +\\) |\\s+?. +?)| (create| alter| drop| TRUNCATE) \\s+ (table| DATABASE) ";//Post interception rules$postfilter= "<.*= (&#\\d+?;?) +?>|<.*data=data:text\\/html.*>|\\b (alert\\ (|confirm\\ (|expression\\ (|prompt\\ (|benchmark\s*?\\) (\d+?| Sleep\s*?\\ ([\d\.] +?\\) |load_file\s*?\\ () |<[^>]*?\\b (onerror|onmousemove|onload|onclick|onmouseover) \\b|\\b (and|or) \\b\\s* ? (\ \ \ \ \ \ \ \ \\d]+?=[\\ (\ \) ' \ "\\d]+?| [\ \ \ \ \ \ \ a-za-z]+?=[\\ (\ \) ' \ ' a-za-z]+?| >|<|\s+? [\\w]+?\\s+?\\bin\\b\\s*?\ (|\\blike\\b\\s+?[ \ "']) |\\/\\*.+?\\*\\/|<\\s*script\\b|\\bexec\\b| Union.+? SELECT (\ \ +\\) |\\s+?. +?)| UPDATE (\ \ +\\) |\\s+?. +?) Set| Insert\\s+into.+? values| (select| DELETE) (\ \ (. +\\) |\\s+?. +?\\s+?) From (\ \ (. +\\) |\\s+?. +?)| (create| alter| drop| TRUNCATE) \\s+ (table| DATABASE) ";//Cookie Blocking Rules$cookiefilter= "Benchmark\s*?\\ (\d+?| Sleep\s*?\\ ([\d\.] +?\\) |load_file\s*?\\ (|\\b (and|or) \\b\\s*? ( [\ \ \ \ \ \ \ \\d]+?=[\\ (\ \) ' \ ' \\d]+?| [\ \ \ \ \ \ \ a-za-z]+?=[\\ (\ \) ' \ ' a-za-z]+?| >|<|\s+? [\\w]+?\\s+?\\bin\\b\\s*?\ (|\\blike\\b\\s+?[ \ "']) |\\/\\*.+?\\*\\/|<\\s*script\\b|\\bexec\\b| Union.+? SELECT (\ \ +\\) |\\s+?. +?)| UPDATE (\ \ +\\) |\\s+?. +?) Set| Insert\\s+into.+? values| (select| DELETE) (\ \ (. +\\) |\\s+?. +?\\s+?) From (\ \ (. +\\) |\\s+?. +?)| (create| alter| drop| TRUNCATE) \\s+ (table| DATABASE) ";
Not much to say.