mirror of
https://ghproxy.net/https://github.com/CaptainCore/captaincore.git
synced 2026-07-30 13:27:00 +08:00
227 lines
7.1 KiB
JSON
227 lines
7.1 KiB
JSON
{
|
|
"known_safe_inline_vars": [
|
|
"var OPDashboardPixels",
|
|
"window.wsf_form_json_config",
|
|
"window.Parameters = window.Parameters",
|
|
"window._currentDevice",
|
|
"var aysPopupOptions",
|
|
"var wc_cart_fragments_params",
|
|
"var wc_add_to_cart_params",
|
|
"var wc_checkout_params",
|
|
"var wc_country_select_params",
|
|
"var wc_address_i18n_params",
|
|
"var wc_single_product_params",
|
|
"var woocommerce_params",
|
|
"var wc_order_attribution",
|
|
"wp.apiFetch.use( wp.apiFetch.createNonceMiddleware",
|
|
"wcSettings",
|
|
"wcBlocksMiddlewareConfig",
|
|
"var wpApiSettings",
|
|
"var wpcf7",
|
|
"var flatsomeVars",
|
|
"var ElementorProFrontendConfig",
|
|
"var elementorFrontendConfig"
|
|
],
|
|
"known_safe_domains": [
|
|
"cdn.usefathom.com",
|
|
"fd.cleantalk.org",
|
|
"cdn.jsdelivr.net",
|
|
"cdnjs.cloudflare.com",
|
|
"ajax.googleapis.com",
|
|
"fonts.googleapis.com",
|
|
"fonts.gstatic.com",
|
|
"unpkg.com",
|
|
"code.jquery.com",
|
|
"www.google-analytics.com",
|
|
"www.googletagmanager.com",
|
|
"connect.facebook.net",
|
|
"stats.wp.com",
|
|
"stats.wordpress.com",
|
|
"s.w.org",
|
|
"s0.wp.com",
|
|
"s1.wp.com",
|
|
"s2.wp.com",
|
|
"c0.wp.com",
|
|
"i0.wp.com",
|
|
"i1.wp.com",
|
|
"i2.wp.com",
|
|
"widgets.wp.com",
|
|
"platform.twitter.com",
|
|
"www.google.com",
|
|
"apis.google.com",
|
|
"maps.googleapis.com",
|
|
"www.gstatic.com",
|
|
"use.fontawesome.com",
|
|
"kit.fontawesome.com",
|
|
"ka-f.fontawesome.com",
|
|
"stackpath.bootstrapcdn.com",
|
|
"maxcdn.bootstrapcdn.com",
|
|
"cdn.shopify.com",
|
|
"js.stripe.com",
|
|
"checkout.stripe.com",
|
|
"www.paypal.com",
|
|
"www.paypalobjects.com",
|
|
"js.hcaptcha.com",
|
|
"www.recaptcha.net",
|
|
"www.google.com",
|
|
"challenges.cloudflare.com",
|
|
"static.cloudflareinsights.com",
|
|
"cdn.amplitude.com",
|
|
"cdn.segment.com",
|
|
"snap.licdn.com",
|
|
"sc-static.net",
|
|
"static.hotjar.com",
|
|
"script.hotjar.com",
|
|
"cdn.cookielaw.org",
|
|
"consent.cookiebot.com",
|
|
"js.hs-scripts.com",
|
|
"js.hs-analytics.net",
|
|
"js.hsforms.net",
|
|
"cdn.heapanalytics.com",
|
|
"cdn.optimizely.com",
|
|
"widget.intercom.io",
|
|
"js.intercomcdn.com",
|
|
"cdn.trustindex.io",
|
|
"cdn.callrail.com",
|
|
"use.typekit.net",
|
|
"pagead2.googlesyndication.com",
|
|
"translate.google.com",
|
|
"maps.google.com",
|
|
"player.vimeo.com",
|
|
"www.youtube.com",
|
|
"assets.pinterest.com",
|
|
"cdn-cookieyes.com",
|
|
"cdn.calltrk.com",
|
|
"script.crazyegg.com",
|
|
"static.ctctcdn.com",
|
|
"cdn.elementor.com",
|
|
"static.getclicky.com",
|
|
"static.addtoany.com",
|
|
"s7.addthis.com",
|
|
"tools.luckyorange.com",
|
|
"cdn.userway.org",
|
|
"wsv3cdn.audioeye.com",
|
|
"js.hscta.net",
|
|
"cdn.amcharts.com",
|
|
"sky.blackbaudcdn.net",
|
|
"tag.simpli.fi",
|
|
"crm.zoho.com",
|
|
"api.bloomerang.co",
|
|
"my.hellobar.com",
|
|
"tag.brandcdn.com",
|
|
"fonts.bunny.net",
|
|
"js-ap1.hs-scripts.com",
|
|
"js-eu1.hs-scripts.com",
|
|
"js-na1.hs-scripts.com",
|
|
"static.hsappstatic.net",
|
|
"netdna.bootstrapcdn.com",
|
|
"securepubads.g.doubleclick.net",
|
|
"hb.wpmucdn.com",
|
|
"resources.infolinks.com",
|
|
"js.adsrvr.org",
|
|
"www.idxhome.com",
|
|
"secure.gravatar.com",
|
|
"cq-logs.cheq-platform.com",
|
|
"obseu.bmccfortress.com"
|
|
],
|
|
"signatures": [
|
|
{
|
|
"id": "obfuscated-eval",
|
|
"name": "Obfuscated eval/base64",
|
|
"severity": "critical",
|
|
"type": "inline-pattern",
|
|
"patterns": ["eval\\s*\\(\\s*atob\\s*\\(", "eval\\s*\\(\\s*String\\.fromCharCode", "eval\\s*\\(\\s*unescape\\s*\\("]
|
|
},
|
|
{
|
|
"id": "document-write-unescape",
|
|
"name": "Document.write with unescape",
|
|
"severity": "critical",
|
|
"type": "inline-pattern",
|
|
"patterns": ["document\\.write\\s*\\(\\s*unescape\\s*\\("]
|
|
},
|
|
{
|
|
"id": "ip-address-source",
|
|
"name": "IP Address Script Source",
|
|
"severity": "high",
|
|
"type": "src-pattern",
|
|
"patterns": ["https?://\\d+\\.\\d+\\.\\d+\\.\\d+"]
|
|
},
|
|
{
|
|
"id": "crypto-miner",
|
|
"name": "Cryptocurrency Miner",
|
|
"severity": "critical",
|
|
"type": "src-domain",
|
|
"domains": ["coinhive.com", "coin-hive.com", "jsecoin.com", "cryptoloot.pro", "crypto-loot.com", "monerominer.rocks", "2giga.link"]
|
|
},
|
|
{
|
|
"id": "known-malware-domains",
|
|
"name": "Known Malware Domain",
|
|
"severity": "critical",
|
|
"type": "src-domain",
|
|
"domains": ["statfrede.com", "top-developer.com", "blackbeatle.xyz", "danmarkshusraad.com", "greekdemo.com", "linistat.info", "ducky-bsc.xyz", "duckybsc.com", "fbanalyt.com", "eggnework.com", "sideown.com", "football2026.life", "pizzaonline.life", "linearprocesshost.com"]
|
|
},
|
|
{
|
|
"id": "seo-spam-redirect",
|
|
"name": "SEO Spam Redirect Script",
|
|
"severity": "critical",
|
|
"type": "inline-pattern",
|
|
"patterns": ["window\\.location\\.href\\s*=.*(\\.xyz|\\.top|\\.tk|\\.ml|\\.ga|\\.cf)"]
|
|
},
|
|
{
|
|
"id": "hidden-iframe",
|
|
"name": "Hidden iframe injection",
|
|
"severity": "high",
|
|
"type": "inline-pattern",
|
|
"patterns": ["<iframe[^>]*style\\s*=\\s*[\"'][^\"']*display\\s*:\\s*none", "<iframe[^>]*width\\s*=\\s*[\"']?[01][\"']?[^>]*height\\s*=\\s*[\"']?[01][\"']?"]
|
|
},
|
|
{
|
|
"id": "base64-long-string",
|
|
"name": "Long base64 encoded string",
|
|
"severity": "high",
|
|
"type": "inline-pattern",
|
|
"patterns": ["(?:eval|Function|document\\.write|setTimeout|setInterval)\\s*\\([^)]*['\"][A-Za-z0-9+/=]{200,}['\"]"]
|
|
},
|
|
{
|
|
"id": "char-table-obfuscation",
|
|
"name": "Character table obfuscation",
|
|
"severity": "critical",
|
|
"type": "inline-pattern",
|
|
"patterns": ["\\[e\\[\\d+\\],e\\[\\d+\\],e\\[\\d+\\],e\\[\\d+\\].*\\.join\\(", "\\[e\\[\\d+\\]\\]\\[\\[e\\[\\d+\\],e\\[\\d+\\]"]
|
|
},
|
|
{
|
|
"id": "fetch-textcontent-inject",
|
|
"name": "Fetch and inject script via textContent",
|
|
"severity": "critical",
|
|
"type": "inline-pattern",
|
|
"patterns": ["fetch\\s*\\(.*\\.then.*\\.textContent\\s*=\\s*t", "\\.textContent\\s*=\\s*t;[^}]*appendChild"]
|
|
},
|
|
{
|
|
"id": "fetch-atob-payload",
|
|
"name": "Fetch with base64 decoded URL",
|
|
"severity": "critical",
|
|
"type": "inline-pattern",
|
|
"patterns": ["fetch\\s*\\(\\s*atob\\s*\\(\\s*[\"'][a-zA-Z0-9+/=]+[\"']\\s*\\)"]
|
|
},
|
|
{
|
|
"id": "array-join-method-construction",
|
|
"name": "Array join method name construction",
|
|
"severity": "critical",
|
|
"type": "inline-pattern",
|
|
"patterns": ["\\]\\s*\\.join\\s*\\(\\s*[\"'][\"']\\s*\\)\\s*\\]\\s*\\(", "\\[\\[\\w\\[\\d+\\],\\w\\[\\d+\\]"]
|
|
},
|
|
{
|
|
"id": "xor-encrypted-exfil",
|
|
"name": "XOR encrypted data exfiltration",
|
|
"severity": "critical",
|
|
"type": "inline-pattern",
|
|
"patterns": ["charCodeAt.*\\^.*charCodeAt.*send\\(", "(?s)String\\.fromCharCode\\s*\\(.*\\^.*XMLHttpRequest"]
|
|
},
|
|
{
|
|
"id": "fake-payment-form",
|
|
"name": "Fake payment form overlay",
|
|
"severity": "critical",
|
|
"type": "inline-pattern",
|
|
"patterns": ["(?s)(card.?number|cc.?number|cvv|cvc|card.?expir).*position\\s*:\\s*fixed", "(?s)position\\s*:\\s*(fixed|absolute).*z.?index\\s*:\\s*\\d{5,}.*(card|payment|checkout|billing)"]
|
|
}
|
|
]
|
|
}
|