package main
import (
"regexp"
"fmt"
)
func main() {
var re = regexp.MustCompile(`(?mi)<{1}\w+[\w\s\'\"\=]*(on[^=-\s]+)=["']([\S\w\d]*|[\S\w\d ]*)["']>{1}`)
var str = `<video><source onerror="alert(1)"> <img onerror="alert(shouldMatch)">
onerror="shouldnt match"
<img alt="" onerror="alert(2>4)">
<img onerror="alert(2<4)"><img onerror="alert(2<4)">
<img onerror="alert(!@#$%^&*() <> ""''?|\/}{][=-_)">
<img onerror="alert()">
<img onerror="(function{}())">
<img onerror="">
<img onerror="asdasdasd(){}((({}0123><456789!@#$%^&*()_+qwertyuiop[]asdfghjkl;'\/.,mnbvcxz\|ZXCVBNM<>?|":LKJHGFDSAQWERTYUIOP{}\`\`~~">
<asd><img onerror="(function{}())">
<img diabled alt="asd" onerror="(function{}())"> `
for i, match := range re.FindAllString(str, -1) {
fmt.Println(match, "found at index", i)
}
}
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Golang, please visit: https://golang.org/pkg/regexp/