re = /<{1}\w+[\w\s\'\"\=]*(on[^=-\s]+)=["']([\S\w\d]*|[\S\w\d ]*)["']>{1}/mi
str = '<video><source onerror="alert(1)"> <img onerror="alert(shouldMatch)">
onerror="shouldnt match"
<img alt="" onerror="alert(2>4)">
<img onerror="alert(2<4)"><img onerror="alert(2<4)">
<img onerror="alert(!@#$%^&*() <> ""\'\'?|\\/}{][=-_)">
<img onerror="alert()">
<img onerror="(function{}())">
<img onerror="">
<img onerror="asdasdasd(){}((({}0123><456789!@#$%^&*()_+qwertyuiop[]asdfghjkl;\'\\/.,mnbvcxz\\|ZXCVBNM<>?|":LKJHGFDSAQWERTYUIOP{}``~~">
<asd><img onerror="(function{}())">
<img diabled alt="asd" onerror="(function{}())"> '
# Print the match result
str.scan(re) do |match|
puts match.to_s
end
Please keep in mind that these code samples are automatically generated and are not guaranteed to work. If you find any syntax errors, feel free to submit a bug report. For a full regex reference for Ruby, please visit: http://ruby-doc.org/core-2.2.0/Regexp.html