[{"id":1,"actions":[{"type":"INSPECT"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/phar:\\/\\//i"},{"type":"FUNCTION","name":"getPostParams","args":[]}]},"right_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/phar:\\/\\//i"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}},"level":null},{"id":2,"actions":[{"type":"INSPECT"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"greaterThan","args":[{"type":"NUMBER","value":0},{"type":"FUNCTION","name":"matchCount","args":[{"type":"STRING","value":"/(^|;|{|})O:+?\\+*[0-9]+:\"WP_Theme\"/i"},{"type":"FUNCTION","name":"getPostParams","args":[]}]}]},"right_operand":{"type":"FUNCTION","name":"greaterThan","args":[{"type":"NUMBER","value":0},{"type":"FUNCTION","name":"matchCount","args":[{"type":"STRING","value":"/(^|;|{|})O:+?\\+*[0-9]+:\"WP_Theme\"/i"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}]}},"level":null},{"id":4,"actions":[{"type":"INSPECT"},{"type":"BLOCK"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/(^|\\/|\\\\)(\\.\\.?(\\\\|\\/)+)+wp\\-config\\.php/i"},{"type":"FUNCTION","name":"getPostParams","args":[]}]},"right_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/(^|\\/|\\\\)(\\.\\.?(\\\\|\\/)+)+wp\\-config\\.php/i"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}},"level":null},{"id":5,"actions":[{"type":"INSPECT"},{"type":"BLOCK"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/\\.(p(h(pt?|t(ml?)?|ar)[0-9]?|l|y)|(j|a)sp|aspx|sh|shtml|html?|cgi|htaccess|user\\.ini)($|\\.)/i"},{"type":"FUNCTION","name":"getFileNames","args":[]}]},"level":null},{"id":6,"actions":[{"type":"INSPECT"},{"type":"BLOCK"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/^\\/(?:\\.\\/)*(?:var|home|usr|mnt|media|etc|tmp|dev|proc)\\//i"},{"type":"FUNCTION","name":"getPostParams","args":[]}]},"right_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/^\\/(?:\\.\\/)*(?:var|home|usr|mnt|media|etc|tmp|dev|proc)\\//i"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}},"level":null},{"id":7,"actions":[{"type":"INSPECT"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/<\\!(?:DOCTYPE|ENTITY)\\s+(?:%\\s*)?\\w+\\s+SYSTEM/i"},{"type":"FUNCTION","name":"getPostParams","args":[]}]},"right_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/<\\!(?:DOCTYPE|ENTITY)\\s+(?:%\\s*)?\\w+\\s+SYSTEM/i"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}},"level":null},{"id":8,"actions":[{"type":"INSPECT"},{"type":"BLOCK"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/(^|\\/|\\\\)\\.\\.(\\\\|\\/)/"},{"type":"FUNCTION","name":"getPostParams","args":[]}]},"right_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/(^|\\/|\\\\)\\.\\.(\\\\|\\/)/"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}},"level":null},{"id":10,"actions":[{"type":"INSPECT"},{"type":"BLOCK"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"FUNCTION","name":"match","args":[{"type":"CONST","value":"BVFW::XSSREGEX"},{"type":"FUNCTION","name":"getGetParams","args":[]}]},"level":null},{"id":11,"actions":[{"type":"INSPECT"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"FUNCTION","name":"match","args":[{"type":"CONST","value":"BVFW::XSSREGEX"},{"type":"FUNCTION","name":"getHeaders","args":[]}]},"level":null},{"id":12,"actions":[{"type":"INSPECT"},{"type":"BLOCK"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/union(\\s|\\/\\*.*\\*\\/)(all(\\s|\\/\\*.*\\*\\/)|)select/ix"},{"type":"FUNCTION","name":"getPostParams","args":[]}]},"right_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/union(\\s|\\/\\*.*\\*\\/)(all(\\s|\\/\\*.*\\*\\/)|)select/ix"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}},"level":null},{"id":13,"actions":[{"type":"INSPECT"},{"type":"BLOCK"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/order(\\s|\\/\\*.*\\*\\/)by(\\s|\\/\\*.*\\*\\/).*(\\-\\-.|#)/i"},{"type":"FUNCTION","name":"getPostParams","args":[]}]},"right_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/order(\\s|\\/\\*.*\\*\\/)by(\\s|\\/\\*.*\\*\\/).*(\\-\\-.|#)/i"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}},"level":null},{"id":14,"actions":[{"type":"INSPECT"},{"type":"BLOCK"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/information_schema/ix"},{"type":"FUNCTION","name":"getPostParams","args":[]}]},"right_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/information_schema/ix"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}},"level":null},{"id":15,"actions":[{"type":"INSPECT"},{"type":"BLOCK"}],"min_rule_engine_ver":0.1,"rule_logic":{"type":"OR","left_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/(\\s|\\.)(wp_ybjn_actionscheduler_actions|wp_ybjn_actionscheduler_claims|wp_ybjn_actionscheduler_groups|wp_ybjn_actionscheduler_logs|wp_ybjn_bv_activities_store|wp_ybjn_bv_fw_requests|wp_ybjn_bv_ip_store|wp_ybjn_bv_lp_requests|wp_ybjn_cf7dbplugin_st|wp_ybjn_cf7dbplugin_submits|wp_ybjn_commentmeta|wp_ybjn_comments|wp_ybjn_facetwp_index|wp_ybjn_gf_draft_submissions|wp_ybjn_gf_entry|wp_ybjn_gf_entry_meta|wp_ybjn_gf_entry_notes|wp_ybjn_gf_form|wp_ybjn_gf_form_meta|wp_ybjn_gf_form_revisions|wp_ybjn_gf_form_view|wp_ybjn_links|wp_ybjn_ms_snippets|wp_ybjn_options|wp_ybjn_pmxe_exports|wp_ybjn_pmxe_google_cats|wp_ybjn_pmxe_posts|wp_ybjn_pmxe_templates|wp_ybjn_pmxi_files|wp_ybjn_pmxi_hash|wp_ybjn_pmxi_history|wp_ybjn_pmxi_images|wp_ybjn_pmxi_imports|wp_ybjn_pmxi_posts|wp_ybjn_pmxi_templates|wp_ybjn_postmeta|wp_ybjn_posts|wp_ybjn_search_filter_cache|wp_ybjn_search_filter_term_results|wp_ybjn_seopress_significant_keywords|wp_ybjn_snippets|wp_ybjn_term_relationships|wp_ybjn_term_taxonomy|wp_ybjn_termmeta|wp_ybjn_terms|wp_ybjn_usermeta|wp_ybjn_users|wp_ybjn_wfblockediplog|wp_ybjn_wfblocks7|wp_ybjn_wfconfig|wp_ybjn_wfcrawlers|wp_ybjn_wffilechanges|wp_ybjn_wffilemods|wp_ybjn_wfhits|wp_ybjn_wfhoover|wp_ybjn_wfissues|wp_ybjn_wfknownfilelist|wp_ybjn_wflivetraffichuman|wp_ybjn_wflocs|wp_ybjn_wflogins|wp_ybjn_wfls_2fa_secrets|wp_ybjn_wfls_settings|wp_ybjn_wfnotifications|wp_ybjn_wfpendingissues|wp_ybjn_wfreversecache|wp_ybjn_wfsnipcache|wp_ybjn_wfstatus|wp_ybjn_wftrafficrates|wp_ybjn_woocommerce_order_itemmeta|wp_ybjn_woocommerce_order_items|wp_ybjn_wpfm_backup|wp_ybjn_wpgmza|wp_ybjn_wpgmza_categories|wp_ybjn_wpgmza_category_maps|wp_ybjn_wpgmza_circles|wp_ybjn_wpgmza_maps|wp_ybjn_wpgmza_polygon|wp_ybjn_wpgmza_polylines|wp_ybjn_wpgmza_rectangles|wp_ybjn_wpr_rocket_cache|wp_ybjn_wpr_rucss_used_css|wp_ybjn_wpsc_also_bought|wp_ybjn_wpsc_cart_contents|wp_ybjn_wpsc_cart_item_meta|wp_ybjn_wpsc_checkout_forms|wp_ybjn_wpsc_claimed_stock|wp_ybjn_wpsc_coupon_codes|wp_ybjn_wpsc_currency_list|wp_ybjn_wpsc_download_status|wp_ybjn_wpsc_meta|wp_ybjn_wpsc_product_rating|wp_ybjn_wpsc_purchase_logs|wp_ybjn_wpsc_purchase_meta|wp_ybjn_wpsc_region_tax|wp_ybjn_wpsc_submited_form_data|wp_ybjn_wpsc_visitor_meta|wp_ybjn_wpsc_visitors|wp_ybjn_wpsetts)(\\b|\\.|\\-\\-\\s|#)/i"},{"type":"FUNCTION","name":"getPostParams","args":[]}]},"right_operand":{"type":"FUNCTION","name":"match","args":[{"type":"STRING","value":"/(\\s|\\.)(wp_ybjn_actionscheduler_actions|wp_ybjn_actionscheduler_claims|wp_ybjn_actionscheduler_groups|wp_ybjn_actionscheduler_logs|wp_ybjn_bv_activities_store|wp_ybjn_bv_fw_requests|wp_ybjn_bv_ip_store|wp_ybjn_bv_lp_requests|wp_ybjn_cf7dbplugin_st|wp_ybjn_cf7dbplugin_submits|wp_ybjn_commentmeta|wp_ybjn_comments|wp_ybjn_facetwp_index|wp_ybjn_gf_draft_submissions|wp_ybjn_gf_entry|wp_ybjn_gf_entry_meta|wp_ybjn_gf_entry_notes|wp_ybjn_gf_form|wp_ybjn_gf_form_meta|wp_ybjn_gf_form_revisions|wp_ybjn_gf_form_view|wp_ybjn_links|wp_ybjn_ms_snippets|wp_ybjn_options|wp_ybjn_pmxe_exports|wp_ybjn_pmxe_google_cats|wp_ybjn_pmxe_posts|wp_ybjn_pmxe_templates|wp_ybjn_pmxi_files|wp_ybjn_pmxi_hash|wp_ybjn_pmxi_history|wp_ybjn_pmxi_images|wp_ybjn_pmxi_imports|wp_ybjn_pmxi_posts|wp_ybjn_pmxi_templates|wp_ybjn_postmeta|wp_ybjn_posts|wp_ybjn_search_filter_cache|wp_ybjn_search_filter_term_results|wp_ybjn_seopress_significant_keywords|wp_ybjn_snippets|wp_ybjn_term_relationships|wp_ybjn_term_taxonomy|wp_ybjn_termmeta|wp_ybjn_terms|wp_ybjn_usermeta|wp_ybjn_users|wp_ybjn_wfblockediplog|wp_ybjn_wfblocks7|wp_ybjn_wfconfig|wp_ybjn_wfcrawlers|wp_ybjn_wffilechanges|wp_ybjn_wffilemods|wp_ybjn_wfhits|wp_ybjn_wfhoover|wp_ybjn_wfissues|wp_ybjn_wfknownfilelist|wp_ybjn_wflivetraffichuman|wp_ybjn_wflocs|wp_ybjn_wflogins|wp_ybjn_wfls_2fa_secrets|wp_ybjn_wfls_settings|wp_ybjn_wfnotifications|wp_ybjn_wfpendingissues|wp_ybjn_wfreversecache|wp_ybjn_wfsnipcache|wp_ybjn_wfstatus|wp_ybjn_wftrafficrates|wp_ybjn_woocommerce_order_itemmeta|wp_ybjn_woocommerce_order_items|wp_ybjn_wpfm_backup|wp_ybjn_wpgmza|wp_ybjn_wpgmza_categories|wp_ybjn_wpgmza_category_maps|wp_ybjn_wpgmza_circles|wp_ybjn_wpgmza_maps|wp_ybjn_wpgmza_polygon|wp_ybjn_wpgmza_polylines|wp_ybjn_wpgmza_rectangles|wp_ybjn_wpr_rocket_cache|wp_ybjn_wpr_rucss_used_css|wp_ybjn_wpsc_also_bought|wp_ybjn_wpsc_cart_contents|wp_ybjn_wpsc_cart_item_meta|wp_ybjn_wpsc_checkout_forms|wp_ybjn_wpsc_claimed_stock|wp_ybjn_wpsc_coupon_codes|wp_ybjn_wpsc_currency_list|wp_ybjn_wpsc_download_status|wp_ybjn_wpsc_meta|wp_ybjn_wpsc_product_rating|wp_ybjn_wpsc_purchase_logs|wp_ybjn_wpsc_purchase_meta|wp_ybjn_wpsc_region_tax|wp_ybjn_wpsc_submited_form_data|wp_ybjn_wpsc_visitor_meta|wp_ybjn_wpsc_visitors|wp_ybjn_wpsetts)(\\b|\\.|\\-\\-\\s|#)/i"},{"type":"FUNCTION","name":"getGetParams","args":[]}]}},"level":null}]