Re: a simple rule for detecting Microsoft executables

2004-11-07 Thread Theo Van Dinter
On Sun, Nov 07, 2004 at 10:04:58AM +0100, Francesco Potorti` wrote: > >ewww! $name="foo.com"; > > > >congrats, you just FPed. :) > > No, I didn't :-) > > You missed the meta rule: > meta ms_executable (__h_exename_q && !__b_exename_q) Ok, that one didn't FP, fine. :P I just don'

Re: a simple rule for detecting Microsoft executables

2004-11-07 Thread Francesco Potorti`
>> full __h_exename_q >> /\bname=("?).+?\.(?:bas|bat|cmd|com|cpl|exe|js|jse|msi|mst|pcd|pif|reg|scr|sct|vb|vbe|vbs|wsc|wsf|wsh|xsl)\1[[:blank:]]*(?:;|$)/mi >> rawbody __b_exename_q >> /\bname=("?).+?\.(?:bas|bat|cmd|com|cpl|exe|js|jse|msi|mst|pcd|pif|reg|scr|sct|vb|vbe|vbs|

Re: a simple rule for detecting Microsoft executables

2004-11-07 Thread Theo Van Dinter
On Sun, Nov 07, 2004 at 01:45:51AM +0100, Francesco Potorti` wrote: > full __h_exename_q > /\bname=("?).+?\.(?:bas|bat|cmd|com|cpl|exe|js|jse|msi|mst|pcd|pif|reg|scr|sct|vb|vbe|vbs|wsc|wsf|wsh|xsl)\1[[:blank:]]*(?:;|$)/mi > rawbody __b_exename_q > /\bname=("?).+?\.(?:bas|ba

a simple rule for detecting Microsoft executables

2004-11-07 Thread Francesco Potorti`
full __h_exename_q /\bname=("?).+?\.(?:bas|bat|cmd|com|cpl|exe|js|jse|msi|mst|pcd|pif|reg|scr|sct|vb|vbe|vbs|wsc|wsf|wsh|xsl)\1[[:blank:]]*(?:;|$)/mi rawbody __b_exename_q /\bname=("?).+?\.(?:bas|bat|cmd|com|cpl|exe|js|jse|msi|mst|pcd|pif|reg|scr|sct|vb|vbe|vbs|wsc|wsf|wsh|