8000 update word list for rule 932115 (RCE Windows command injection part 2/2) · Issue #2671 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

update word list for rule 932115 (RCE Windows command injection part 2/2) #2671

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
Tracked by #2621
fzipi opened this issue Jun 29, 2022 · 7 comments · Fixed by #3170
Closed
Tracked by #2621

update word list for rule 932115 (RCE Windows command injection part 2/2) #2671

fzipi opened this issue Jun 29, 2022 · 7 comments · Fixed by #3170
Assignees

Comments

@fzipi
Copy link
Member
fzipi commented Jun 29, 2022

This file should be updated with binaries from the lolbas-project.

@fzipi fzipi mentioned this issue Jun 29, 2022
34 tasks
@fzipi fzipi changed the title Update regexp data file 932115 with Windows commands update regexp data file 932115 with Windows commands Jun 29, 2022
@fzipi fzipi changed the title update reg 8000 exp data file 932115 with Windows commands update regexp data file 932115.data with Windows commands Jun 29, 2022
@fzipi fzipi changed the title update regexp data file 932115.data with Windows commands update word list for rule 932115 (RCE Windows command injection part 2/2) Jul 10, 2022
@github-actions
Copy link
Contributor
github-actions bot commented Nov 8, 2022

This issue has been open 120 days with no activity. Remove the stale label or comment, or this will be closed in 14 days

@53cur3M3
Copy link
Contributor

https://lolbas-project.github.io/ might be a useful list of windows binaries. This is a curated list used by (at least some) pentesters.

@fzipi
Copy link
Member Author
fzipi commented Dec 23, 2022

Taking a second look, and after adding all of the lolbas binaries to 932110, we can add all cmd commands from windows in this rule.

The list should come from https://raw.githubusercontent.com/MicrosoftDocs/windowsserverdocs/main/WindowsServerDocs/administration/windows-commands/windows-commands.md

@franbuehler
Copy link
Contributor
franbuehler commented Mar 19, 2023

curl https://raw.githubusercontent.com/MicrosoftDocs/windowsserverdocs/main/WindowsServerDocs/administration/windows-commands/windows-commands.md | grep -oE '^-\s\[\w+\]' | cut -f2 -d[ | cut -f1 -d]

  • With ^-\s we only get commands listed as bullet points and not links in the text
  • With \w+ we only get commands consisting of only one word and not wbadmin delete catalog for example.

If I get this right, the current rule 932115 should be the new rule 932380 like mentioned in this comment here.

@franbuehler
Copy link
Contributor

@theseion : do you know where I have to fix this (renaming of the rule 932115 to 932380)?

@theseion
Copy link
Contributor

Actually, that looks like an error to me. 932110 was renamed to 932370 but 932115 still exists and 932380 doesn't. I think @fzipi might just have forgotten to do the second renaming?

@franbuehler
Copy link
Contributor
franbuehler commented Mar 20, 2023

@theseion :
Ah, sorry, I commented the wrong issue.
I renamed 932115 to 932380 in #3170.
I thought that was the plan. But now it seems that the CI tests are failing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants
0