8000 update 933160.ra · Issue #3021 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

update 933160.ra #3021

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
Tracked by #2621
fzipi opened this issue Nov 21, 2022 · 4 comments
Closed
Tracked by #2621

update 933160.ra #3021

fzipi opened this issue Nov 21, 2022 · 4 comments
Assignees
Milestone

Comments

@fzipi
Copy link
Member
fzipi commented Nov 21, 2022

These must be addressed as a group:

Rule 933160

~220 words which are common in PHP code, but have a higher chance to cause false positives in natural language or other contexts.

Examples: 'chr', 'eval'.

To mitigate false positives, a regexp looks for PHP function syntax, e.g. 'eval()'.

Regexp is generated from function names in regex-assembly/933160.ra

@fzipi fzipi mentioned this issue Nov 21, 2022
34 tasks
@fzipi fzipi added this to the CRS v4.0.0 milestone Nov 21, 2022
@dune73
Copy link
Member
dune73 commented Nov 21, 2022

Not sure what we have to do here. Doing the list update?

@fzipi
Copy link
Member Author
fzipi commented Nov 21, 2022

We need to review all PHP functions and redo the classification in the 4 groups. Documenting the process, the decisions on why some words are in PLX, and maybe converge to something that can be done in an automated way.

@fzipi
Copy link
Member Author
fzipi commented Dec 28, 2022

From the list of PHP functions, I'm doing a selection of words that don't have an underscore and are English words (will use @theMiddleBlue's script for this).

@M4tteoP
Copy link
Member
M4tteoP commented Sep 19, 2023

Closing as completed via #3273

@M4tteoP M4tteoP closed this as completed Sep 19, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants
0