import java.util.regex.Matcher;
import java.util.regex.Pattern;
public class Example {
public static void main(String[] args) {
final String regex = "<{1}\\w+[\\w\\s\\'\\\"\\=]*(on[^=-\\s]+)=[\"']([\\S\\w\\d]*|[\\S\\w\\d ]*)[\"']>{1}";
final String string = "<video><source onerror=\"alert(1)\"> <img onerror=\"alert(shouldMatch)\"> \n\n"
+ "onerror=\"shouldnt match\"\n\n"
+ "<img alt=\"\" onerror=\"alert(2>4)\"> \n\n"
+ "<img onerror=\"alert(2<4)\"><img onerror=\"alert(2<4)\">\n\n"
+ "<img onerror=\"alert(!@#$%^&*() <> \"\"''?|\\/}{][=-_)\">\n\n"
+ "<img onerror=\"alert()\"> \n"
+ "<img onerror=\"(function{}())\"> \n"
+ "<img onerror=\"\">\n\n"
+ "<img onerror=\"asdasdasd(){}((({}0123><456789!@#$%^&*()_+qwertyuiop[]asdfghjkl;'\\/.,mnbvcxz\\|ZXCVBNM<>?|\":LKJHGFDSAQWERTYUIOP{}``~~\">\n\n"
+ "<asd><img onerror=\"(function{}())\">\n"
+ "<img diabled alt=\"asd\" onerror=\"(function{}())\"> ";
final Pattern pattern = Pattern.compile(regex, Pattern.MULTILINE | Pattern.CASE_INSENSITIVE);
final Matcher matcher = pattern.matcher(string);
while (matcher.find()) {
System.out.println("Full match: " + matcher.group(0));
for (int i = 1; i <= matcher.groupCount(); i++) {
System.out.println("Group " + i + ": " + matcher.group(i));
}
}
}
}
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Java, please visit: https://docs.oracle.com/javase/7/docs/api/java/util/regex/Pattern.html