using System;
using System.Text.RegularExpressions;
public class Example
{
public static void Main()
{
string pattern = @"<{1}\w+[\w\s\'\""\=]*(on[^=-\s]+)=[""']([\S\w\d]*|[\S\w\d ]*)[""']>{1}";
string input = @"<video><source onerror=""alert(1)""> <img onerror=""alert(shouldMatch)"">
onerror=""shouldnt match""
<img alt="" onerror=""alert(2>4)"">
<img onerror=""alert(2<4)""><img onerror=""alert(2<4)"">
<img onerror=""alert(!@#$%^&*() <> ""''?|\/}{][=-_)"">
<img onerror=""alert()"">
<img onerror=""(function{}())"">
<img onerror="">
<img onerror=""asdasdasd(){}((({}0123><456789!@#$%^&*()_+qwertyuiop[]asdfghjkl;'\/.,mnbvcxz\|ZXCVBNM<>?|"":LKJHGFDSAQWERTYUIOP{}``~~"">
<asd><img onerror=""(function{}())"">
<img diabled alt=""asd"" onerror=""(function{}())""> ";
RegexOptions options = RegexOptions.Multiline | RegexOptions.IgnoreCase;
foreach (Match m in Regex.Matches(input, pattern, options))
{
Console.WriteLine("'{0}' found at index {1}.", m.Value, m.Index);
}
}
}
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for C#, please visit: https://msdn.microsoft.com/en-us/library/system.text.regularexpressions.regex(v=vs.110).aspx