1. เทคนิคการตีกลองยาวขั้นพื้นฐาน การตีกลองยาวขั้นสูง |
|
นายชิต พาอิ่ม |
|
|
2. 123 |
|
123 |
|
|
3. 123 |
|
123 |
|
|
4. 123 |
|
${802721082+919218695} |
|
|
5. 123 |
|
123 |
|
|
6. 123 |
|
123 |
|
|
7. 123 |
|
123 |
|
|
8. ../../../../../../../../../../../../../../../../../../etc/passwd |
|
123 |
|
|
9. |
|
123 |
|
|
10. 123 |
|
123 |
|
|
11. 123 |
|
123 |
|
|
12. .\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\Windows\win.ini |
|
123 |
|
|
13. %u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216Windows%u2216win%u002eini |
|
123 |
|
|
14. 123 |
|
123 |
|
|
15. 123 |
|
123 |
|
|
16. %u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215Windows%u2215win%u002eini |
|
123 |
|
|
17. 123 |
|
123 |
|
|
18. 123 |
|
123 |
|
|
19. 123 |
|
123 |
|
|
20. 123 |
|
123 |
|
|
21. 123 |
|
123 |
|
|
22. 123 |
|
123 |
|
|
23. 123 |
|
123 |
|
|
24. 123 |
|
123 |
|
|
25. 123 |
|
123 |
|
|
26. 123 |
|
123 |
|
|
27. 123 |
|
123 |
|
|
28. 123 |
|
123 |
|
|
29. 123 |
|
123 |
|
|
30. 123 |
|
123 |
|
|
31. 123 |
|
123 |
|
|
32. 123 |
|
/*1*/{{852891972+862833719}} |
|
|
33. 123 |
|
123 |
|
|
34. 123 |
|
123 |
|
|
35. 123 |
|
123 |
|
|
36. ${868229089+833011689} |
|
123 |
|
|
37. 123 |
|
123 |
|
|
38. 123 |
|
123 |
|
|
39. 123 |
|
123 |
|
|
40. 123 |
|
123 |
|
|
41. 123 |
|
123 |
|
|
42. 123
expr 961317049 + 911764839
|
|
123 |
|
|
43. 123 |
|
123 |
|
|
44. 123 |
|
123 |
|
|
45. 123 |
|
123 |
|
|
46. 123 |
|
123 |
|
|
47. 123 |
|
123 |
|
|
48. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fwindows%2fwin%2eini |
|
123 |
|
|
49. 123 |
|
123 |
|
|
50. 123 |
|
123 |
|
|
51. 123 |
|
123 |
|
|
52. 123 |
|
123 |
|
|
53. .\..\..\..\..\..\..\windows/win.ini |
|
123 |
|
|
54. 123 |
|
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1423573677'))) |
|
|
55. 123 |
|
123?'"\( |
|
|
56. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cWindows%5cwin%2eini |
|
123 |
|
|
57. 123 |
|
123'"\( |
|
|
58. 123 |
|
123 |
|
|
59. 123 |
|
123 |
|
|
60. ./../../../../../../../../../../../../../../../../../../Windows/win.ini |
|
123 |
|
|
61. 123 |
|
123 |
|
|
62. 123 |
|
123 |
|
|
63. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fWindows%2fwin%2eini |
|
123 |
|
|
64. 123 |
|
123 |
|
|
65. 123 |
|
123 |
|
|
66. ./../../../../../../Windows/win.ini |
|
123 |
|
|
67. 123 |
|
123 |
|
|
68. 123'and/**/extractvalue(1,concat(char(126),md5(1330956781)))and' |
|
123 |
|
|
69. 123 |
|
123 |
|
|
70. WEB-INF/web.xml |
|
123 |
|
|
71. 123 |
|
123 |
|
|
72. 123"and/**/extractvalue(1,concat(char(126),md5(1476706640)))and" |
|
123 |
|
|
73. 123 |
|
123 |
|
|
74. 123 |
|
123 |
|
|
75. 123 |
|
123 |
|
|
76. 123 |
|
123 |
|
|
77. 123 |
|
123 |
|
|
78. 123 |
|
123 |
|
|
79. 123 |
|
123 |
|
|
80. 123 |
|
123 |
|
|
81. 123 |
|
123 |
|
|
82. 123 |
|
123 |
|
|
83. 123 |
|
123 |
|
|
84. 123 |
|
123 |
|
|
85. 123 |
|
123 |
|
|
86. 123 |
|
123 |
|
|
87. 123 |
|
123 |
|
|
88. 123 |
|
123 |
|
|
89. 123 |
|
123 |
|
|
90. 123 |
|
123 |
|
|
91. 123 |
|
123 |
|
|
92. 123 |
|
123 |
|
|
93. 123 |
|
123 |
|
|
94. 123 |
|
123 |
|
|
95. 123 |
|
123 |
|
|
96. 123 |
|
123 |
|
|
97. 123 |
|
123 |
|
|
98. 123 |
|
123 |
|
|
99. 123 |
|
123 |
|
|
100. 123 |
|
123 |
|
|
101. 123/**/and(select+1/**/from/**/pg_sleep(0))>0/**/ |
|
123 |
|
|
102. 123 |
|
123 |
|
|
103. 123 |
|
123 |
|
|
104. ..\..\..\..\..\..\windows/win.ini |
|
123 |
|
|
105. 123 |
|
123 |
|
|
106. 123'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('t',3)='t |
|
123 |
|
|
107. 123 |
|
123 |
|
|
108. 123 |
|
123 |
|
|
109. 123 |
|
123 |
|
|
110. 123 |
|
123 |
|
|
111. 123 |
|
123 |
|
|
112. 123|expr 990285666 + 900124775 |
|
123 |
|
|
113. 123 |
|
123 |
|
|
114. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows/win%2eini |
|
123 |
|
|
115. <%- 802183459+988240552 %> |
|
123 |
|
|
116. 123 |
|
123 |
|
|
117. 123 |
|
123 |
|
|
118. 123 |
|
123 |
|
|
119. 123 |
|
123 |
|
|
120. 123 |
|
123 |
|
|
121. 123 |
|
123 |
|
|
122. 123 |
|
123 |
|
|
123. ../../../../../../windows/win.ini 123 |
|
123 |
|
|
124. 123 |
|
123 |
|
|
125. %u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215windows%u2215win%u002eini |
|
123 |
|
|
126. 123 |
|
123 |
|
|
127. 123 |
|
expr 821680366 + 815216271 |
|
|
128. 123 |
|
123 |
|
|
129. 123 |
|
123 |
|
|
130. 123 |
|
123 |
|
|
131. 123 |
|
123 |
|
|
132. 123 |
|
123 |
|
|
133. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows/win.ini 123 |
|
123 |
|
|
134. 123 |
|
123 |
|
|
135. 123 |
|
123 |
|
|
136. 123 |
|
123 |
|
|
137. 123 |
|
123 |
|
|
138. 123 |
|
123 |
|
|
139. 123 |
|
123 |
|
|
140. 123 |
|
123 |
|
|
141. 123 |
|
123 |
|
|
142. 123 |
|
123 |
|
|
143. ..\..\..\..\..\..\windows/win.ini 123 |
|
123 |
|
|
144. 123 |
|
123 |
|
|
145. 123 |
|
123 |
|
|
146. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows/win%2eini |
|
123 |
|
|
147. 123 |
|
123 |
|
|
148. 123 |
|
123 |
|
|
149. 123 |
|
123 |
|
|
150. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows/win%2eini |
|
123 |
|
|
151. ../../../../../../../../../../../../../../../../../../windows/win.ini |
|
123 |
|
|
152. ../../../../../../../../../../../../../../../../../../windows/win.ini 123 |
|
123 |
|
|
153. 123 |
|
(select*from(select+sleep(0)union/**/select+1)a) |
|
|
154. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fwindows%2fwin%2eini |
|
123 |
|
|
155. 123 |
|
123'and(select*from(select+sleep(0))a/**/union/**/select+1)=' |
|
|
156. 123 |
|
123'/**/and(select'1'from/**/pg_sleep(0))::text>'0 |
|
|
157. %u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215windows%u2215win%u002eini |
|
123 |
|
|
158. 123 |
|
123/**/and(select+1)>0waitfor/**/delay'0:0:3'/**/ |
|
|
159. 123 |
|
123'and(select+1)>0waitfor/**/delay'0:0:0 |
|
|
160. 123 |
|
123"and/**/extractvalue(1,concat(char(126),md5(1628614471)))and" |
|
|
161. 123 |
|
123'and(select+1)>0waitfor/**/delay'0:0:3 |
|
|
162. 123 |
|
extractvalue(1,concat(char(126),md5(1653283107))) |
|
|
163. 123 |
|
123/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('a',0) |
|
|
164. 123 |
|
123'and(select'1'from/**/cast(md5(1958994292)as/**/int))>'0 |
|
|
165. ..\..\..\..\..\..\Windows\win.ini 123 |
|
123 |
|
|
166. ../../../../../../../../../../../../../../../../../../Windows/win.ini |
|
123 |
|
|
167. 123 |
|
123 |
|
|
168. 123 |
|
123 |
|
|
169. 123 |
|
123 |
|
|
170. 123 |
|
123 |
|
|
171. ../../../../../../../../../../../../../../../../../../Windows/win.ini 123 |
|
123 |
|
|
172. 123 |
|
123 |
|
|
173. 123 |
|
123 |
|
|
174. 123 |
|
123 |
|
|
175. ../../../../../../Windows/win.ini |
|
123 |
|
|
176. 123 |
|
123 |
|
|
177. 123 |
|
123 |
|
|
178. ../../../../../../Windows/win.ini 123 |
|
123 |
|
|
179. 123 |
|
123 |
|
|
180. 123 |
|
123 |
|
|
181. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fWindows%2fwin%2eini |
|
123 |
|
|
182. 123 |
|
123 |
|
|
183. WEB-INF/web.xml;123 |
|
123 |
|
|
184. extractvalue(1,concat(char(126),md5(1576270894))) |
|
123 |
|
|
185. 123 |
|
123 |
|
|
186. ../WEB-INF/web.xml |
|
123 |
|
|
187. 123'and(select'1'from/**/cast(md5(1511011799)as/**/int))>'0 |
|
123 |
|
|
188. 123 |
|
123 |
|
|
189. ../WEB-INF/web.xml;123 |
|
123 |
|
|
190. 123/**/and/**/cast(md5('1273905756')as/**/int)>0 |
|
123 |
|
|
191. 123 |
|
123 |
|
|
192. ../../WEB-INF/web.xml;123 |
|
123 |
|
|
193. ../../../../WEB-INF/web.xml |
|
123 |
|
|
194. ../../../../WEB-INF/web.xml;123 |
|
123 |
|
|
195. 123 |
|
123 |
|
|
196. 123 |
|
123 |
|
|
197. 123 |
|
123 |
|
|
198. 123 |
|
123 |
|
|
199. 123 |
|
123 |
|
|
200. 123 |
|
123 |
|
|
201. 123 |
|
123 |
|
|
202. 123 |
|
123 |
|
|
203. 123 |
|
123 |
|
|
204. 123 |
|
123 |
|
|
205. 123 |
|
123 |
|
|
206. 123 |
|
123 |
|
|
207. 123 |
|
123 |
|
|
208. 123 |
|
123 |
|
|
209. 123 |
|
123 |
|
|
210. 123 |
|
123 |
|
|
211. 123 |
|
123 |
|
|
212. 123 |
|
123 |
|
|
213. 123 |
|
123 |
|
|
214. 123 |
|
123 |
|
|
215. 123 |
|
123 |
|
|
216. 123 |
|
123 |
|
|
217. 123 |
|
123 |
|
|
218. 123 |
|
123 |
|
|
219. 123 |
|
123 |
|
|
220. 123 |
|
123 |
|
|
221. 123 |
|
123 |
|
|
222. 123 |
|
123 |
|
|
223. 123 |
|
123 |
|
|
224. 123 |
|
123 |
|
|
225. 123 |
|
123
expr 839853085 + 839661813
|
|
|
226. 123 |
|
123/**/and/**/0=DBMS_PIPE.RECEIVE_MESSAGE('e',2) |
|
|
227. 123 |
|
123"and/**/extractvalue(1,concat(char(126),md5(1457600777)))and" |
|
|
228. 123 |
|
123 |
|
|
229. 123 |
|
123 |
|
|
230. 123/**/and(select+1/**/from/**/pg_sleep(0))>0/**/ |
|
123 |
|
|
231. 123 |
|
123 |
|
|
232. 123 |
|
123 |
|
|
233. 123 |
|
123 |
|
|
234. 123 |
|
123 |
|
|
235. 123 |
|
123 |
|
|
236. 123 |
|
123 |
|
|
237. 123 |
|
123 |
|
|
238. 123 |
|
123 |
|
|
239. 123 |
|
123 |
|
|
240. 123 |
|
123 |
|
|
241. 123 |
|
123 |
|
|
242. 123 |
|
123 |
|
|
243. 123 |
|
123 |
|
|
244. 123 |
|
123 |
|
|
245. 123 |
|
123 |
|
|
246. 123 |
|
123 |
|
|
247. 123 |
|
123 |
|
|
248. 123 |
|
123 |
|
|
249. 123 |
|
123 |
|
|
250. 123 |
|
123 |
|
|
251. 123 |
|
123 |
|
|
252. 123 |
|
123 |
|
|
253. 123 |
|
123 |
|
|
254. 123 |
|
123 |
|
|
255. 123 |
|
123 |
|
|
256. 123 |
|
123 |
|
|
257. 123 |
|
123 |
|
|
258. 123 |
|
123 |
|
|
259. 123 |
|
123 |
|
|
260. 123 |
|
123 |
|
|
261. 123 |
|
123 |
|
|
262. 123 |
|
123 |
|
|
263. 123 |
|
123 |
|
|
264. 123 |
|
123 |
|
|
265. 123 |
|
123 |
|
|
266. 123 |
|
123 |
|
|
267. 123 |
|
123 |
|
|
268. 123 |
|
ncuwuzawzaykvivngduw |
|
|
269. 123 |
|
123 |
|
|
270. 123 |
|
123 |
|
|
271. 123 |
|
123 |
|
|
272. 123 |
|
123/**/and+2=7 |
|
|
273. 123 |
|
|
|
|
274. 123 |
|
123 |
|
|
275. 123 |
|
123 |
|
|
276. 123 |
|
123"and"a"="a |
|
|
277. 123 |
|
123 |
|
|
278. 123 |
|
123 |
|
|
279. 123 |
|
123 |
|
|
280. 123 |
|
(select*from(select+sleep(0)union/**/select+1)a) |
|
|
281. 123 |
|
123 |
|
|
282. 123 |
|
123|expr 822344073 + 802655304 |
|
|
283. 123 |
|
123 |
|
|
284. 123 |
|
123 |
|
|
285. 123 |
|
|
|
|
286. 123 |
|
123 |
|
|
287. 123 |
|
123 |
|
|
288. 123 |
|
123 |
|
|
289. 123 |
|
123 |
|
|
290. 123 |
|
123 |
|
|
291. 123 |
|
123 |
|
|
292. 123 |
|
123 |
|
|
293. 123 |
|
123 |
|
|
294. 123 |
|
123 |
|
|
295. |
|
123 |
|
|
296. 123$(expr 828482351 + 813674377) |
|
123 |
|
|
297. 123 |
|
123 |
|
|
298. 123 |
|
123 |
|
|
299. 123 |
|
123 |
|
|
300. '+(44643*41208)+' |
|
123 |
|
|
301. 123 |
|
${908324650+848803123} |
|
|
302. 123&set /A 873760162+810597424 |
|
123 |
|
|
303. 123 |
|
'-var_dump(md5(763690079))-' |
|
|
304. 123 |
|
123 |
|
|
305. 123 |
|
123 |
|
|
306. 123 |
|
123 |
|
|
307. ${862355497+892935186} |
|
123 |
|
|
308. 123 |
|
123 |
|
|
309. 123 |
|
123 |
|
|
310. expr 999066789 + 999201112 |
|
123 |
|
|
311. 123 |
|
123 |
|
|
312. 123 |
|
123 |
|
|
313. 123 |
|
123 |
|
|
314. 123 |
|
123 |
|
|
315. 123 |
|
123 |
|
|
316. 123 |
|
123 |
|
|
317. 123 |
|
123 |
|
|
318. 123 |
|
123 |
|
|
319. 123 |
|
123 |
|
|
320. 123 |
|
123 |
|
|
321. 123 |
|
123 |
|
|
322. 123 |
|
123 |
|
|
323. 123 |
|
123 |
|
|
324. 123 |
|
123 |
|
|
325. 123 |
|
123 |
|
|
326. 123 |
|
123 |
|
|
327. 123 |
|
123 |
|
|
328. 123 |
|
123 |
|
|
329. 123 |
|
123 |
|
|
330. 123 |
|
123 |
|
|
331. 123 |
|
123 |
|
|
332. 123 |
|
123 |
|
|
333. 123 |
|
123 |
|
|
334. 123 |
|
123 |
|
|
335. /*1*/{{856446507+950551818}} |
|
123 |
|
|
336. ${935407507+855896184} |
|
123 |
|
|
337. 123 |
|
123 |
|
|
338. 123 |
|
123'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('p',0)='p |
|
|
339. 123'and(select*from(select+sleep(2))a/**/union/**/select+1)=' |
|
123 |
|
|
340. 123"and/**/extractvalue(1,concat(char(126),md5(1700562101)))and" |
|
123 |
|
|
341. 123 |
|
123 |
|
|
342. 123 |
|
123 |
|
|
343. 123 |
|
123 |
|
|
344. 123 |
|
123 |
|
|
345. 123 |
|
123 |
|
|
346. 123 |
|
123 |
|
|
347. |
|
123 |
|
|
348. 123 |
|
123 |
|
|
349. 123 |
|
123 |
|
|
350. 123 |
|
123 |
|
|
351. 123 |
|
<%- 833543525+913721793 %> |
|
|
352. 123 |
|
123 |
|
|
353. 123 |
|
123'and/**/extractvalue(1,concat(char(126),md5(1641489568)))and' |
|
|
354. 123 |
|
123/**/and/**/3=DBMS_PIPE.RECEIVE_MESSAGE('i',0) |
|
|
355. #set($c=903891078+996578821)${c}$c |
|
123 |
|
|
356. 123/**/and+4=4 |
|
123 |
|
|
357. 123 |
|
123 |
|
|
358. 123 |
|
123&set /A 836092077+844966289 |
|
|
359. <%- 980520252+961597676 %> |
|
123 |
|
|
360. 123 |
|
123 |
|
|
361. 123 |
|
123 |
|
|
362. 123 |
|
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1891212334'))) |
|
|
363. 123'and'u'='p |
|
123 |
|
|
364. 123 |
|
123'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1608771273')))>'0 |
|
|
365. 123 |
|
123 |
|
|
366. 123"and"p"="p |
|
123 |
|
|
367. 123 |
|
123?'"\( |
|
|
368. 123 |
|
123 |
|
|
369. 123"and"v"="t |
|
123 |
|
|
370. 123 |
|
123'"\( |
|
|
371. (select*from(select+sleep(0)union/**/select+1)a) |
|
123 |
|
|
372. (select*from(select+sleep(2)union/**/select+1)a) |
|
123 |
|
|
373. 123 |
|
123 |
|
|
374. 123 |
|
123 |
|
|
375. 123/**/and(select+1/**/from/**/pg_sleep(2))>0/**/ |
|
123 |
|
|
376. 123'and(select'1'from/**/cast(md5(1360908197)as/**/int))>'0 |
|
123 |
|
|
377. 123'/**/and(select'1'from/**/pg_sleep(0))::text>'0 |
|
123 |
|
|
378. 123 |
|
123 |
|
|
379. 123'/**/and(select'1'from/**/pg_sleep(2))::text>'0 |
|
123 |
|
|
380. 123/**/and/**/cast(md5('1833790466')as/**/int)>0 |
|
123 |
|
|
381. 123/**/and(select+1)>0waitfor/**/delay'0:0:2'/**/ |
|
123 |
|
|
382. convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1050582305'))) |
|
123 |
|
|
383. 123'and(select+1)>0waitfor/**/delay'0:0:0 |
|
123 |
|
|
384. 123 |
|
123 |
|
|
385. 123'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1180617028')))>'0 |
|
123 |
|
|
386. 123'and(select+1)>0waitfor/**/delay'0:0:2 |
|
123 |
|
|
387. 123/**/and/**/1=DBMS_PIPE.RECEIVE_MESSAGE('b',0) |
|
123 |
|
|
388. 123/**/and/**/0=DBMS_PIPE.RECEIVE_MESSAGE('i',2) |
|
123 |
|
|
389. 123'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('z',0)='z |
|
123 |
|
|
390. 123'"\( |
|
123 |
|
|
391. 123'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('u',2)='u |
|
123 |
|
|
392. 123 |
|
123 |
|
|
393. 123 |
|
123 |
|
|
394. 123 |
|
123 |
|
|
395. 123 |
|
123 |
|
|
396. 123 |
|
123 |
|
|
397. 123 |
|
123 |
|
|
398. 123 |
|
123 |
|
|
399. 123 |
|
123 |
|
|
400. 123 |
|
123 |
|
|
401. 123 |
|
123 |
|
|
402. 123 |
|
123 |
|
|
403. 123 |
|
123 |
|
|
404. 123 |
|
123 |
|
|
405. 123 |
|
123 |
|
|
406. 123/**/and+0=7 |
|
123 |
|
|
407. 123 |
|
123 |
|
|
408. 123 |
|
123 |
|
|
409. 123 |
|
123 |
|
|
410. 123 |
|
123 |
|
|
411. 123 |
|
123 |
|
|
412. 123 |
|
123 |
|
|
413. 2 |
|
1 |
|
|
414. ncuwuzawzaykvivngduw |
|
123 |
|
|
415. 123 |
|
123 |
|
|
416. 123 |
|
123 |
|
|
417. 123 |
|
123 |
|
|
418. 123 |
|
123 |
|
|
419. 123 |
|
123 |
|
|
420. 123 |
|
123 |
|
|
421. 123 |
|
123 |
|
|
422. 123 |
|
123/**/and+2=2 |
|
|
423. 123 |
|
123 |
|
|
424. 123 |
|
123 |
|
|
425. 123 |
|
123 |
|
|
426. 123 |
|
123'and'd'='d |
|
|
427. 123 |
|
123 |
|
|
428. 123 |
|
123 |
|
|
429. 123 |
|
123 |
|
|
430. 123 |
|
123 |
|
|
431. 123 |
|
123"and"b"="c |
|
|
432. 123 |
|
123 |
|
|
433. 123 |
|
123 |
|
|
434. 123 |
|
(select*from(select+sleep(2)union/**/select+1)a) |
|
|
435. 123 |
|
123 |
|
|
436. 123 |
|
123 |
|
|
437. 123 |
|
123'and(select*from(select+sleep(0))a/**/union/**/select+1)=' |
|
|
438. 123 |
|
123 |
|
|
439. 123 |
|
123 |
|
|
440. 123 |
|
123 |
|
|
441. 123 |
|
123"and(select*from(select+sleep(0))a/**/union/**/select+1)=" |
|
|
442. 123 |
|
123 |
|
|
443. 123 |
|
123 |
|
|
444. 123 |
|
123/**/and(select+1/**/from/**/pg_sleep(2))>0/**/ |
|
|
445. 123 |
|
123 |
|
|
446. 123 |
|
123'/**/and(select'1'from/**/pg_sleep(0))::text>'0 |
|
|
447. 123 |
|
123 |
|
|
448. 123 |
|
123 |
|
|
449. 123 |
|
123 |
|
|
450. 123 |
|
123 |
|
|
451. 123 |
|
123 |
|
|
452. 123 |
|
123 |
|
|
453. 123 |
|
123 |
|
|
454. 123 |
|
123 |
|
|
455. 123 |
|
123 |
|
|
456. 123 |
|
123 |
|
|
457. 123 |
|
123 |
|
|
458. 123 |
|
123 |
|
|
459. 123 |
|
123 |
|
|
460. 123 |
|
123 |
|
|
461. 123 |
|
123 |
|
|
462. 123 |
|
123 |
|
|
463. 123 |
|
123 |
|
|
464. 123 |
|
123 |
|
|
465. 123 |
|
123 |
|
|
466. 123 |
|
123 |
|
|
467. 123 |
|
123 |
|
|
468. 123 |
|
${(926541795+808439410)?c} |
|
|
469. 123 |
|
123 |
|
|
470. 123 |
|
123 |
|
|
471. 123 |
|
123 |
|
|
472. 123 |
|
123/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/ |
|
|
473. 123 |
|
123 |
|
|
474. 123 |
|
123/**/and(select+1)>0waitfor/**/delay'0:0:2'/**/ |
|
|
475. 123 |
|
123'and(select+1)>0waitfor/**/delay'0:0:0 |
|
|
476. 123 |
|
123'and(select+1)>0waitfor/**/delay'0:0:2 |
|
|
477. 123 |
|
123'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('o',2)='o |
|
|
478. 123 |
|
extractvalue(1,concat(char(126),md5(1107859498))) |
|
|
479. 123 |
|
123$(expr 817270258 + 901536098) |
|
|
480. 123 |
|
123'and(select'1'from/**/cast(md5(1543626628)as/**/int))>'0 |
|
|
481. 123 |
|
123/**/and/**/cast(md5('1597166062')as/**/int)>0 |
|
|
482. 123'and'u'='u |
|
123 |
|
|
483. 123'and/**/extractvalue(1,concat(char(126),md5(1661141730)))and' |
|
123 |
|
|
484. 123 |
|
123 |
|
|
485. 123"and(select*from(select+sleep(0))a/**/union/**/select+1)=" |
|
123 |
|
|
486. 123"and(select*from(select+sleep(2))a/**/union/**/select+1)=" |
|
123 |
|
|
487. extractvalue(1,concat(char(126),md5(1200107575))) |
|
123 |
|
|
488. 123/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/ |
|
123 |
|
|
489. 123?'"\( |
|
123 |
|
|
490. 123 |
|
123 |
|
|
491. 123 |
|
123 |
|
|
492. 123 |
|
123 |
|
|
493. 123
expr 991255811 + 922737339
|
|
123 |
|
|
494. 123 |
|
123 |
|
|
495. 123 |
|
123 |
|
|
496. 123 |
|
123'and(select*from(select+sleep(2))a/**/union/**/select+1)=' |
|
|
497. 123 |
|
/*1*/{{865836678+811004844}} |
|
|
498. 123 |
|
123 |
|
|
499. 123 |
|
123"and(select*from(select+sleep(2))a/**/union/**/select+1)=" |
|
|
500. 123 |
|
${892952449+844009727} |
|
|
501. 123 |
|
123/**/and(select+1/**/from/**/pg_sleep(0))>0/**/ |
|
|
502. 123 |
|
123 |
|
|
503. 123 |
|
123 |
|
|
504. ./../../../../../../../../../../../../../../../../../../etc/passwd |
|
123 |
|
|
505. 123 |
|
${(901551622+842446425)?c} |
|
|
506. 123 |
|
123 |
|
|
507. |
|
123 |
|
|
508. 123 |
|
123 |
|
|
509. 123 |
|
123 |
|
|
510. 123 |
|
123'and'n'='x |
|
|
511. 123 |
|
${@var_dump(md5(449323439))}; |
|
|
512. 123 |
|
123 |
|
|
513. 123 |
|
123 |
|
|
514. 123 |
|
123 |
|
|
515. 123 |
|
123 |
|
|
516. 123 |
|
123 |
|
|
517. 123'and(select+1)>0waitfor/**/delay'0:0:0 |
|
123 |
|
|
518. 123 |
|
123 |
|
|
519. .\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows/win.ini |
|
123 |
|
|
520. 123 |
|
123 |
|
|
521. 123 |
|
123 |
|
|
522. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fwindows%2fwin%2eini |
|
123 |
|
|
523. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cWindows%5cwin%2eini |
|
123 |
|
|
524. ..\..\..\..\..\..\Windows\win.ini |
|
123 |
|
|
525. 123 |
|
123 |
|
|
526. 123?'"\( |
|
123 |
|
|
527. ../../../WEB-INF/web.xml;123 |
|
123 |
|
|
528. 123'"\( |
|
123 |
|
|
529. 123 |
|
123/**/and(select+1/**/from/**/pg_sleep(3))>0/**/ |
|
|
530. 123 |
|
123 |
|
|
531. 123'and(select*from(select+sleep(0))a/**/union/**/select+1)=' |
|
123 |
|
|
532. 123 |
|
123 |
|
|
533. 123 |
|
123 |
|
|
534. 123 |
|
123 |
|
|
535. 123 |
|
123 |
|
|
536. 123 |
|
123 |
|
|
537. 123 |
|
123 |
|
|
538. 123 |
|
123 |
|
|
539. 123 |
|
123 |
|
|
540. ./../../../../../../windows/win.ini |
|
123 |
|
|
541. ../../WEB-INF/web.xml |
|
123 |
|
|
542. convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1573721809'))) |
|
123 |
|
|
543. 123 |
|
123 |
|
|
544. 123 |
|
123 |
|
|
545. 123 |
|
123 |
|
|
546. 123 |
|
'+(40431*41034)+' |
|
|
547. 123 |
|
${851122404+949195584} |
|
|
548. 123 |
|
123 |
|
|
549. 123 |
|
123 |
|
|
550. 123 |
|
123 |
|
|
551. 123 |
|
123 |
|
|
552. 123 |
|
123 |
|
|
553. 123 |
|
123 |
|
|
554. 123 |
|
123 |
|
|
555. 123 |
|
123 |
|
|
556. 123 |
|
123 |
|
|
557. 123 |
|
123 |
|
|
558. 123 |
|
123 |
|
|
559. 123 |
|
123 |
|
|
560. 123 |
|
123 |
|
|
561. 123 |
|
123 |
|
|
562. 123 |
|
123 |
|
|
563. 123 |
|
123 |
|
|
564. 123|expr 820006721 + 841446682 |
|
123 |
|
|
565. 123 |
|
123 |
|
|
566. 123 |
|
123 |
|
|
567. 123 |
|
123 |
|
|
568. 123 |
|
'+(42111*43418)+' |
|
|
569. 123 |
|
123 |
|
|
570. 123 |
|
123 |
|
|
571. 123 |
|
123 |
|
|
572. 123 |
|
${@var_dump(md5(690967943))}; |
|
|
573. 123 |
|
123 |
|
|
574. ${@var_dump(md5(865698610))}; |
|
123 |
|
|
575. 123 |
|
123 |
|
|
576. 123 |
|
123 |
|
|
577. '-var_dump(md5(749540607))-' |
|
123 |
|
|
578. 123 |
|
123 |
|
|
579. 123 |
|
123 |
|
|
580. 123 |
|
123 |
|
|
581. 123 |
|
123 |
|
|
582. 123 |
|
123 |
|
|
583. 123 |
|
123 |
|
|
584. 123 |
|
123 |
|
|
585. 123 |
|
123 |
|
|
586. 123 |
|
123 |
|
|
587. 123 |
|
123 |
|
|
588. 123 |
|
123 |
|
|
589. 123 |
|
123 |
|
|
590. 123 |
|
123 |
|
|
591. 123 |
|
123 |
|
|
592. 123 |
|
123 |
|
|
593. 123 |
|
123 |
|
|
594. 123 |
|
123 |
|
|
595. 123 |
|
#set($c=901304692+876022175)${c}$c |
|
|
596. 123 |
|
123 |
|
|
597. ${(846316594+962768011)?c} |
|
123 |
|
|
598. 123 |
|
123 |
|
|
599. 123 |
|
123 |
|
|
600. 123 |
|
123 |
|
|
601. (select*from(select+sleep(3)union/**/select+1)a) |
|
123 |
|
|
602. 123 |
|
123 |
|
|
603. 123 |
|
expr 927007957 + 997761814 |
|
|
604. 123 |
|
sftrlyzxkncsfqrdjjzm |
|
|
605. 123 |
|
123 |
|
|
606. /etc/passwd 123 |
|
123 |
|
|
607. 123 |
|
123 |
|
|
608. %2fetc%2fpasswd |
|
123 |
|
|
609. %u2215etc%u2215passwd |
|
123 |
|
|
610. 123 |
|
123 |
|
|
611. 123'/**/and(select'1'from/**/pg_sleep(3))::text>'0 |
|
123 |
|
|
612. 123 |
|
123 |
|
|
613. '-var_dump(md5(808188048))-' |
|
123 |
|
|
614. %2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows/win%2eini |
|
123 |
|
|
615. 123 |
|
123 |
|
|
616. 123 |
|
123 |
|
|
617. 123 |
|
123 |
|
|
618. 123 |
|
123 |
|
|
619. 123 |
|
123 |
|
|
620. 123 |
|
123 |
|
|
621. %2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fwindows%2fwin%2eini |
|
123 |
|
|
622. 123 |
|
123 |
|
|
623. 123 |
|
123 |
|
|
624. 123 |
|
123 |
|
|
625. 123 |
|
123 |
|
|
626. 123 |
|
123 |
|
|
627. 123 |
|
123 |
|
|
628. ..\..\..\..\..\..\windows/win.ini |
|
123 |
|
|
629. 123 |
|
123 |
|
|
630. 123 |
|
123 |
|
|
631. ..\..\..\..\..\..\windows/win.ini 123 |
|
123 |
|
|
632. 123 |
|
123 |
|
|
633. 123 |
|
123 |
|
|
634. %u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216windows/win%u002eini |
|
123 |
|
|
635. 123 |
|
123 |
|
|
636. 123 |
|
123 |
|
|
637. sftrlyzxkncsfqrdjjzm |
|
123 |
|
|
638. 123 |
|
123 |
|
|
639. 123 |
|
123 |
|
|
640. 123 |
|
123 |
|
|
641. 123 |
|
123 |
|
|
642. 123'and(select+1)>0waitfor/**/delay'0:0:3 |
|
123 |
|
|
643. %u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216windows/win%u002eini |
|
123 |
|
|
644. expr 904944631 + 823440209 |
|
123 |
|
|
645. ../../../../../../../../../../../../../../../../../../windows/win.ini 123 |
|
123 |
|
|
646. 123 |
|
123 |
|
|
647. 123 |
|
123 |
|
|
648. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows/win.ini |
|
123 |
|
|
649. 123 |
|
123 |
|
|
650. 123 |
|
(select*from(select+sleep(3)union/**/select+1)a) |
|
|
651. 123 |
|
123"and(select*from(select+sleep(0))a/**/union/**/select+1)=" |
|
|
652. ../../../../../../windows/win.ini |
|
123 |
|
|
653. 123 |
|
123/**/and(select+1/**/from/**/pg_sleep(0))>0/**/ |
|
|
654. 123 |
|
123'/**/and(select'1'from/**/pg_sleep(3))::text>'0 |
|
|
655. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\Windows\win.ini |
|
123 |
|
|
656. 123 |
|
123'and/**/extractvalue(1,concat(char(126),md5(1466368582)))and' |
|
|
657. ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\Windows\win.ini 123 |
|
123 |
|
|
658. 123 |
|
123/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('o',3) |
|
|
659. 123 |
|
123'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('v',0)='v |
|
|
660. 123 |
|
123/**/and/**/cast(md5('1117662094')as/**/int)>0 |
|
|
661. 123 |
|
123'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('c',3)='c |
|
|
662. .\..\..\..\..\..\..\Windows\win.ini |
|
123 |
|
|
663. 123 |
|
123'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1799932186')))>'0 |
|
|
664. 123'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1940393018')))>'0 |
|
123 |
|
|
665. ../../../WEB-INF/web.xml |
|
123 |
|
|
666. ../../../../../../windows/win.ini 123 |
|
123 |
|
|
667. ../../../../../../../../../../../../../../../../../../etc/passwd 123 |
|
123 |
|
|
668. 123 |
|
123 |
|
|
669. ./../../../../../../../../../../../../../../../../../../windows/win.ini |
|
123 |
|
|
670. 123 |
|
123 |
|
|
671. 123 |
|
123 |
|
|
672. 123 |
|
123 |
|
|
673. 123 |
|
123 |
|
|
674. 123 |
|
123 |
|
|
675. 123 |
|
123 |
|
|
676. 123 |
|
123 |
|
|