#pragma once // clang-format off const std::string naughty_strings[] = { // sourced from // https://raw.githubusercontent.com/minimaxir/big-list-of-naughty-strings/master/blns.txt // Reserved Strings // // Strings which may be used elsewhere in code "undefined", "undef", "null", "NULL", "(null)", "nil", "NIL", "true", "false", "True", "False", "TRUE", "FALSE", "None", "hasOwnProperty", "\\", "\\\\", // Numeric Strings // // Strings which can be interpreted as numeric "0", "1", "1.00", "$1.00", "1/2", "1E2", "1E02", "1E+02", "-1", "-1.00", "-$1.00", "-1/2", "-1E2", "-1E02", "-1E+02", "1/0", "0/0", "-2147483648/-1", "-9223372036854775808/-1", "-0", "-0.0", "+0", "+0.0", "0.00", "0..0", ".", "0.0.0", "0,00", "0,,0", ",", "0,0,0", "0.0/0", "1.0/0.0", "0.0/0.0", "1,0/0,0", "0,0/0,0", "--1", "-", "-.", "-,", "99999999999999999999999999999999999999999999999999999999999999999999999999" "9999999999999999999999", "NaN", "Infinity", "-Infinity", "INF", "1#INF", "-1#IND", "1#QNAN", "1#SNAN", "1#IND", "0x0", "0xffffffff", "0xffffffffffffffff", "0xabad1dea", "123456789012345678901234567890123456789", "1,000.00", "1 000.00", "1'000.00", "1,000,000.00", "1 000 000.00", "1'000'000.00", "1.000,00", "1 000,00", "1'000,00", "1.000.000,00", "1 000 000,00", "1'000'000,00", "01000", "08", "09", "2.2250738585072011e-308", // Special Characters // // ASCII punctuation. All of these characters may need to be escaped in // some // contexts. Divided into three groups based on (US-layout) keyboard // position. ",./;'[]\\-=", "<>?:\"{}|_+", "!@#$%^&*()`~", // Non-whitespace C0 controls: U+0001 through U+0008, U+000E through U+001F, // and U+007F (DEL) // Often forbidden to appear in various text-based file formats (e.g. XML), // or reused for internal delimiters on the theory that they should never // appear in input. // The next line may appear to be blank or mojibake in some viewers. "", // Non-whitespace C1 controls: U+0080 through U+0084 and U+0086 through // U+009F. // Commonly misinterpreted as additional graphic characters. // The next line may appear to be blank, mojibake, or dingbats in some // viewers. "ᅡタᅡチᅡツᅡテᅡトᅡニᅡヌᅡネᅡノᅡハᅡヒᅡフᅡヘᅡホᅡマᅡミᅡムᅡメᅡモᅡヤᅡユᅡヨᅡラᅡリᅡルᅡレᅡロᅡワᅡンᅡ゙ᅡ゚", // Whitespace: all of the characters with category Zs, Zl, or Zp (in Unicode // version 8.0.0), plus U+0009 (HT), U+000B (VT), U+000C (FF), U+0085 (NEL), // and U+200B (ZERO WIDTH SPACE), which are in the C categories but are // often // treated as whitespace in some contexts. // This file unfortunately cannot express strings containing // U+0000, U+000A, or U+000D (NUL, LF, CR). // The next line may appear to be blank or mojibake in some viewers. // The next line may be flagged for \"trailing whitespace\" in some viewers. " ", " ᅡナ " "£レタ¬タタ¬タチ¬タツ¬タテ¬タト¬タナ¬タニ¬タヌ¬タネ¬タノ¬タハ¬タヒ¬タᄄ¬タᄅ¬タᆵ¬チ゚ ̄タタ", // Unicode additional control characters: all of the characters with // general category Cf (in Unicode 8.0.0). // The next line may appear to be blank or mojibake in some viewers. "ᅡᆳ￘タ￘チ￘ツ￘テ￘ト￘ナ￘ワᅴンᅵマ£ᅠホ¬" "タ" "ヒ" "¬" "タ" "フ" "¬" "タ" "ヘ" "¬" "タ" "ホ" "¬" "タ" "マ" "¬" "タ" "ᆰ" "¬" "タ" "ᆱ" "¬" "タ" "ᆲ" "¬" "タᆳ¬タᆴ¬チᅠ¬チᄀ¬チᄁ¬チᆪ¬チᄂ¬チᆭ¬" "チ" "ᄃ" "¬" "チ" "ᄄ" "¬" "チ" "ᄅ" "¬" "チ" "ᆰ" "¬" "チ" "ᆱ" "¬" "チ" "ᆲ" "¬" "チ" "ᆳ" "¬" "チ" "ᆴ" "¬" "チ" "ᆵ" "￯" "ᄏ" "﾿￯" "﾿ᄍ￯﾿ᄎ￯﾿ᄏ￰ムツᄑ￰ロᄇᅠ￰ロᄇᄀ￰ロᄇᄁ" "￰" "ロ" "ᄇ" "ᆪ" "￰" "ン" "ナ" "ᄈ" "￰" "ン" "ナ" "ᄡ" "￰" "ン" "ナ" "ᄉ" "￰" "ン" "ナ" "ᄊ" "￰ンナᄋ￰ンナᄌ￰ンナᄍ￰ンナᄎ￳ᅠタチ￳ᅠタᅠ" "￳" "ᅠ" "タ" "ᄀ" "￳" "ᅠ" "タ" "ᄁ" "￳" "ᅠ" "タ" "ᆪ" "￳" "ᅠ" "タ" "ᄂ" "￳ᅠ" "タᆬ￳ᅠタᆭ￳ᅠタᄃ￳ᅠタᄄ￳ᅠタᄅ￳ᅠタᆰ￳ᅠ" "タ" "ᆱ" "￳" "ᅠ" "タ" "ᆲ" "￳" "ᅠ" "タ" "ᆳ" "￳" "ᅠ" "タ" "ᆴ" "￳ᅠタᆵ￳ᅠタᄚ￳ᅠタᄆ￳ᅠタᄇ￳ᅠタᄈ￳ᅠタᄡ" "￳" "ᅠ" "タ" "ᄉ" "￳" "ᅠ" "タ" "ᄊ" "￳" "ᅠ" "タ" "ᄋ" "￳ᅠタᄌ" "￳ᅠタᄍ￳ᅠタᄎ￳ᅠタᄏ￳ᅠタᄐ￳ᅠタᄑ￳ᅠタᄒ" "￳" "ᅠ" "タ" "﾿" "￳" "ᅠ" "チ" "タ" "￳" "ᅠ" "チ" "チ" "￳ᅠチツ￳ᅠチテ￳ᅠチト￳ᅠチナ￳ᅠチニ￳ᅠチヌ" "￳" "ᅠ" "チ" "ネ" "￳" "ᅠ" "チ" "ノ" "￳" "ᅠ" "チ" "ハ" "￳ᅠチヒ" "￳ᅠチフ￳ᅠチヘ￳ᅠチホ￳ᅠチマ￳ᅠチミ￳ᅠチム" "￳" "ᅠ" "チ" "メ" "￳" "ᅠ" "チ" "モ" "￳" "ᅠ" "チ" "ヤ" "￳ᅠチユ￳ᅠチヨ￳ᅠチラ￳ᅠチリ￳ᅠチル￳ᅠチレ" "￳" "ᅠ" "チ" "ロ" "￳" "ᅠ" "チ" "ワ" "￳" "ᅠ" "チ" "ン" "￳ᅠヂ" "￳ᅠチ゚￳ᅠチᅠ￳ᅠチᄀ￳ᅠチᄁ￳ᅠチᆪ￳ᅠチᄂ" "￳" "ᅠ" "チ" "ᆬ" "￳" "ᅠ" "チ" "ᆭ" "￳" "ᅠ" "チ" "ᄃ" "￳ᅠチᄄ￳ᅠチᄅ￳ᅠチᆰ￳ᅠチᆱ￳ᅠチᆲ￳ᅠチᆳ" "￳" "ᅠ" "チ" "ᆴ" "￳" "ᅠ" "チ" "ᆵ" "￳" "ᅠ" "チ" "ᄚ" "￳ᅠチᄆ" "￳ᅠチᄇ￳ᅠチᄈ￳ᅠチᄡ￳ᅠチᄉ￳ᅠチᄊ￳ᅠチᄋ" "￳" "ᅠ" "チ" "ᄌ" "￳" "ᅠ" "チ" "ᄍ" "￳" "ᅠ" "チ" "ᄎ" "￳ᅠチᄏ￳ᅠチᄐ￳ᅠチᄑ￳ᅠチᄒ￳ᅠチ" "﾿", // \"Byte order marks\", U+FEFF and U+FFFE, each on its own line. // The next two lines may appear to be blank or mojibake in some viewers. "￯ᄏ﾿", "￯﾿ᄒ", // Unicode Symbols // // Strings which contain common unicode symbols (e.g. smart quotes) "ᅫᄅ¬ノネᅢᄃ¬ネレ¬ネᆱᅨワᅡᄉ¬ノᄂ¬ノᆬᅢᄋ", "ᅢᆬᅢ゚¬ネツᅥメᅡ례ル¬ネニᅨレᅡᆲ¬タᆭᅢᆭ", "ᅤモ¬ネムᅡᄡᅡᆴ¬タᅠᅡᆬᅡ뗴ニᅢ죄タ¬タ" "ワ" "¬" "タ" "リ", "ᅡᄀ¬ト깏ᅡᄁ¬ネ゙ᅡ다ᄊ¬タ깕ᅡᄎ¬タモ¬ノ" "ᅠ", "ᅡ졔ロᅢヌ¬ラハᅣ몌ワᅢツᅡᆵᅨリᅡ﾿", "ᅢナᅢヘᅢホᅢマᅨンᅢモᅢヤ￯ᆪ﾿ᅢメᅢレᅢニ¬" "リ" "テ", "ᅤメ¬ダᅡᄡ¬タᄚᅨヌᅢチᅡ뗴ニᅢリ¬ネマ¬タン¬タル", "`¬チト¬ツᆲ¬タᄍ¬タᄎ￯ᆲチ￯ᆲツ¬タ가ᄚᅡ" "ᄋ" "¬" "タ" "レ" "¬" "タ" "ヤ" "ᅡ" "ᄆ", "¬ナロ¬ナワ¬ナン¬ナ゙", "￐チ￐ツ￐テ￐ト￐ナ￐ニ￐ヌ￐ネ￐ノ￐ハ￐ヒ￐フ" "￐" "ヘ" "￐" "ホ" "￐" "マ" "￐" "ミ" "￐" "ム" "￐" "メ" "￐モ￐ヤ￐ユ￐ヨ￐ラ￐リ￐ル￐レ￐ロ￐ワ￐ン￐゙" "￐" "゚" "￐" "ᅠ" "￐" "ᄀ" "￐" "ᄁ" "￐" "ᆪ" "￐" "ᄂ" "￐ᆬ￐ᆭ" "￐ᄃ￐ᄄ￐ᄅ￐ᆰ￐ᆱ￐ᆲ￐ᆳ￐ᆴ￐ᆵ￐ᄚ￐ᄆ￐ᄇ" "￐" "ᄈ" "￐" "ᄡ" "￐" "ᄉ" "￐" "ᄊ" "￐" "ᄋ" "￐" "ᄌ" "￐ᄍ￐ᄎ￐ᄏ￐ᄐ￐ᄑ￐ᄒ￐﾿￑タ￑チ￑ツ￑テ￑ト" "￑" "ナ" "￑" "ニ" "￑" "ヌ" "￑" "ネ" "￑" "ノ" "￑" "ハ" "￑ヒ￑フ" "￑ヘ￑ホ￑マ", "￙ᅠ￙ᄀ￙ᄁ￙ᆪ￙ᄂ￙ᆬ￙ᆭ￙ᄃ￙ᄄ￙ᄅ", // Unicode Subscript/Superscript/Accents // // Strings which contain unicode subscripts/superscripts; can cause // rendering issues "¬チᄚ¬チᄡ¬チᄉ", "¬ツタ¬ツチ¬ツツ", "¬チᄚ¬チᄡ¬チᄉ¬ツタ¬ツチ¬ツツ", "¢ᄌヤ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢" "ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ" "¢ᄍノ¢" "ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ" "¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢" "ᄍヌ¢ᄍヌ" "¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ " "¢ᄌヤ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢" "ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ" "¢ᄍノ¢" "ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ" "¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢" "ᄍヌ¢ᄍヌ" "¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ " "¢ᄌヤ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢" "ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ" "¢ᄍノ¢" "ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ" "¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢" "ᄍヌ¢ᄍヌ" "¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍノ¢ᄍヌ¢ᄍヌ¢ᄍヌ¢ᄍヌ", // Quotation Marks // // Strings which contain misplaced quotation marks; can cause encoding // errors "'", "\"", "''", "\"\"", "'\"'", "\"''''\"'\"", "\"'\"'\"''''\"", "", "", "", "", // Two-Byte Characters // // Strings which contain two-byte characters: can cause rendering issues or // character-length issues "￧ヤᄚ¦ᄌᆳ ̄チユ ̄ツモ ̄チᆱ ̄チツ ̄チメ ̄チᆭ" "¦" "ᄌ" "ヒ" " ̄" "チ" "ユ" " ̄" "チ" "ト", " ̄テム ̄テᄐ ̄テニ ̄ツᆪ ̄テᄐ ̄チᄌ│ᄀフ ̄チヒ ̄チᆰ ̄チト ̄チヒ", "¥メフ│ᆪᄑ₩ᄐᄁ│ᆰ゙", "←テᄄ│ミᄑ₩ᅠᄐ", "↓ツᆲ■レフ↑ᄈᄐ■ユル↓ロミ ↓ヨᄡ■ユル↓ラᄚ↑ᄉᆲ↓ニフ", "↓ᄚᆭ↓ᄚᄄ→ᆬᄐ ■テタ↑ᄈᅠ ↓リᄄ " "■ホᄇ↓ヒワ→ᄃᄄ↑ᄈᄐ " "↓ムロ→ヒᄂ→ᆭᆲ " "→リᅠ→ᄚᄅ↑ᄚチ■ユリ", "￧ᄂᄒ₩ワテ￧ᄃム¥ᆳᄌ←ルᄁ│ᆰ゙¥ᆳᄌ￧ᅠヤ" "￧" "ᄅ" "ᄊ" "₩" "ノ" "タ", "↓レᄌ→゙タ→ᄚヤ■ニᅠ→ᆬᄡ", "￰ᅠワホ￰ᅠワᄆ￰ᅠンᄍ￰ᅠᄆモ￰ᅠᄆᄌ￰ᅠᄇヨ" "￰" "ᅠ" "ᄈ" "マ", // Changing length when lowercased // // Characters which increase in length (2 to 3 bytes) when lowercased // Credit: https://twitter.com/jifa/status/625776454479970304 "￈ᄎ", "￈ᄒ", // Japanese Emoticons // // Strings which consists of Japanese-style emoticons which are popular on // the web " ̄テᄑ¢ᄐᄐ¢ᄎネ￙トᅪワ¢ᄎネ¢ᄐᄑ￯ᄒノ " " ̄テᄑ¢ᄐᄐ¢ᄎネ￙トᅪワ¢ᄎネ¢ᄐᄑ￯ᄒノ", "(￯ᄑᄀ¬ラユ ¬ネタ ¬ラユ￯ᄑᄀ)", "￯ᄑタ￯ᄑᄄ(ᅡᄡ¬ネタ￯ᄑタ¬ネᄅ", "__￯ᄒロ(,_,*)", " ̄テᄏ(￯﾿ᆪ¬ネタ￯﾿ᆪ) ̄テᄏ:*:", "￯ᄒ゚￯ᄑᆬ¬ワ﾿ ̄テᄒ¬ユᄇ(" "￯ᄑᄀ¬ラユ¬タ﾿¬ラユ￯ᄑᄀ)" "¬ユᄆ¬ワ﾿￯ᄑᆬ￯ᄒ゚", ", ̄タツ ̄テᄏ:*: ̄テᄏ ̄ツワ¬タル( ¬リᄏ ᅬノ ¬リᄏ ) ̄タツ ̄テᄏ:*: ̄テᄏ ̄ツワ¬タル", "(¬ユᆵᅡᄚ¬ヨ가ᄚ￯ᄐノ¬ユᆵ￯ᄌᄉ " "¬ヤᄏ¬ヤチ¬ヤᄏ)", "(￯ᄒノ¢ᄇᆬ￧ロハ¢ᄇᆬ￯ᄐノ￯ᄒノ￯ᄏ﾿ " "¬ヤᄏ¬ヤチ¬ヤᄏ", "¬ヤᆲ¬ヤタ¬ヤᆲ ̄テホ( ᅡᄎ _ ᅡᄎ ̄テホ)", "( ᅪ가ᄚ ᅪワᅧヨ ᅪ가ᄚ)", // Emoji // // Strings which contain Emoji; should be the same behavior as two-byte // characters, but not always "￰゚リヘ", "￰゚ムᄅ￰゚マᄑ", "￰゚ムᄒ ￰゚ルヌ ￰゚メチ ￰゚ルナ ￰゚ルニ " "￰゚ルヒ " "￰゚ルホ " "￰゚ルヘ", "￰゚ミᄉ ￰゚ルネ ￰゚ルノ ￰゚ルハ", "¬ンᄂ￯ᄌマ ￰゚メヤ ￰゚メフ ￰゚メユ ￰゚メ゙ " "￰゚メモ " "￰゚メラ " "￰゚メヨ " "￰゚メリ " "￰゚メン " "￰゚メ゚ ￰゚メワ ￰゚メロ ￰゚メレ " "￰゚メル", "¬ワヒ￰゚マ﾿ ￰゚メᆰ￰゚マ﾿ ￰゚ムミ￰゚マ﾿ " "￰゚ルフ￰゚マ﾿ " "￰゚ムマ￰゚マ﾿ " "￰゚ルマ￰゚マ﾿", "￰゚レᄒ ￰゚ニメ ￰゚ニモ ￰゚ニユ ￰゚ニヨ " "￰゚ニラ " "￰゚ニル " "￰゚マᄃ", "0￯ᄌマ¬テᆪ 1￯ᄌマ¬テᆪ 2￯ᄌマ¬テᆪ " "3￯ᄌマ¬テᆪ " "4￯ᄌマ¬テᆪ " "5￯ᄌマ¬テᆪ " "6￯ᄌマ¬テᆪ 7￯ᄌマ¬テᆪ 8￯ᄌマ¬テᆪ " "9￯ᄌマ¬テᆪ " "￰゚ヤ゚", // Regional Indicator Symbols // // Regional Indicator Symbols can be displayed differently across // fonts, and have a number of special behaviors "￰゚ヌᄎ￰゚ヌᄌ￰゚ヌᄋ￰゚ヌᄎ￰゚ヌᄌ " "￰゚ヌᆭ￰゚ヌᆱ￰゚ヌᆭ￰゚ヌᄇ￰゚ヌᄌ", "￰゚ヌᄎ￰゚ヌᄌ￰゚ヌᄋ￰゚ヌᄎ￰゚ヌᄌ￰゚ヌᆭ" "￰" "゚" "ヌ" "ᆱ" "￰" "゚" "ヌ" "ᆭ" "￰" "゚" "ヌ" "ᄇ", "￰゚ヌᄎ￰゚ヌᄌ￰゚ヌᄋ￰゚ヌᄎ￰゚ヌᄌ￰゚ヌᆭ", // Unicode Numbers // // Strings which contain unicode numbers; if the code is localized, it // should see the input as numeric "￯ᄐム￯ᄐメ￯ᄐモ", "￙ᄀ￙ᄁ￙ᆪ", // Right-To-Left Strings // // Strings which contain text that should be rendered RTL if possible (e.g. // Arabic, Hebrew) "￘ᆱ￙ナ ￙ニ￙チ￘ᄈ ￘ᄈ￙ツ￘ᄋ￘ᆰ " "￙ネ￘ᄄ￘ᄃ￙ト￘ᆰ￘ᆳ￘ᆵ￙ハ￘ᆵ￘フ, " "￘ᆲ￘ᄇ￙ハ￘ᄆ￘ᆰ￙ハ " "￘ᄄ￘ᄃ￘ᄈ￘ᆰ￘ᆴ￘ᆵ￘ᄃ￙ナ ￘ᆪ￙ニ " "￘ᆵ￙ニ￙ネ. ￘ᆬ￘ᄚ ￙ヌ￙ニ￘ᄃ￘゚ " "￘ᄃ￙ト￘ᄈ￘ᆰ￘ᄃ￘ᄆ " "￙ネ￘ᆰ￙ニ￘ᄉ￙ハ￘ᄄ ￙テ￘ᄃ￙ニ. " "￘ᆪ￙ヌ￙ム￙ト " "￘ᄃ￙ハ￘ᄋ￘ᄃ￙ト￙ハ￘ᄃ￘フ " "￘ᄄ￘ᄆ￙ハ￘ᄋ￘ᄃ￙ニ￙ハ￘ᄃ-" "￙チ￘ᄆ￙ニ￘ᄈ￘ᄃ " "￙ツ￘ᆵ " "￘ᆪ￘ᆴ￘ᄚ. ￘ᄈ￙ト￙ハ￙ナ￘ᄃ￙ニ￘フ " "￘ᆬ￘ᆰ￙チ￘ᄃ￙ツ￙ハ￘ᄅ " "￘ᄄ￙ハ￙ニ " "￙ナ￘ᄃ, ￙ハ￘ᄚ￙テ￘ᄆ " "￘ᄃ￙ト￘ᆳ￘ᆵ￙ネ￘ᆵ " "￘ᆪ￙ハ " "￘ᄄ￘ᄍ￘ᆵ, ￙ナ￘ᄍ￘ᄃ￙ナ￙ト￘ᄅ " "￘ᄄ￙ネ￙ト￙ニ￘ᆵ￘ᄃ￘フ " "￘ᄃ￙ト￘ᆬ￘ᄋ￙ト￘ᄃ￙ツ ￘ᄍ￙ト " "￘ᆬ￙ハ￙ネ.", "ᅲムᅱᄚᅱ튜뛰슈ミᅲ뤼ᄡᅲチᅲルᅲᆰ, ᅲムᅱ쥐튜뛰쥬ミ ᅲミᅱ뮤ワᅱ쮸ヤᅱᄡᅲルᅲン, ᅲミᅱ슑 " "ᅲヤᅱ유뤼쥐튜チᅲ゙ᅱ유ルᅱᄡᅲン, ᅲユᅱᄚᅲミᅱ슑 ᅲヤᅱ쥬ミᅱ쥬뛰쓙", "ᅲヤᅱ쥬ルᅱᄚᅲᆰᅱ쥬ヤtest￘ᄃ￙ト￘ᄉ￙チ￘" "ᆳ" "￘" "ᄃ" "￘" "ᆰ" " " "￘ᄃ￙ト￘ᆰ￙ム￘ᆳ￙ネ￙ト", "￯ᄋᄑ", "￯ᄋᄎ", "￙ナ￙マ￙ニ￙ホ￘ᄃ￙ツ￙ホ￘ᄡ￙ホ￘ᄅ￙マ " "￘ᄈ￙マ￘ᄄ￙マ￙ト￙ミ " "￘ᄃ￙ミ￘ᄈ￙メ￘ᆰ￙ミ￘ᆴ￙メ￘ᆵ￙ホ￘ᄃ￙ナ" "￙" "ミ" " " "￘ᄃ￙ト￙ト￙ム￙マ￘ᄎ￙ホ￘ᄅ￙ミ ￙チ￙ミ￙ハ " "￘ᄃ￙ト￙ニ￙ム￙マ￘ᄌ￙マ￙ナ￙ミ " "￘ᄃ￙ト￙メ￙ツ￙ホ￘ᄃ￘ᆭ￙ミ￙ナ￙ホ￘ᄅ￙ミ " "￙ネ￙ホ￙チ￙ミ￙ハ￙ナ " "￙ハ￙ホ￘ᆴ￙マ￘ᄉ￙ム￙ホ " "￘ᄃ￙ト￘ᆰ￙ム￙ホ￘ᄋ￙メ￘ᄄ￙ミ￙ハ￙ツ￙ホ" "￘" "ᄃ" "￘" "ᆰ" "￙" "マ" " " "￘ᄃ￙ト￙メ￘ᆳ￘ᄃ￘ᄈ￙マ￙ネ￘ᄄ￙ミ￙ハ￙ム" "￙" "ホ" "￘" "ᄅ" "￙" "マ" "￘" "フ" " ", // Trick Unicode // // Strings which contain unicode with unusual properties (e.g. // Right-to-left override) (c.f. // http://www.unicode.org/charts/PDF/U2000.pdf) "¬タᆰ¬タᆰtest¬タᆰ", "¬タᆱtest¬タᆱ", "¬タᄅtest¬タᄅ", "test¬チᅠtest¬タᆱ", "¬チᆭtest¬チᄃ", // Zalgo Text // // Strings which contain \"corrupted\" text. The corruption will not appear // in non-HTML text, however. (via http://www.eeemo.net) "£ᄍᄚᅩ초초ユoᅪ゙ " "ᅩᄋiᅩ볿ᅪヌᅩᆰᅪルnᅩンᅩラᅪユvᅩ゚ᅩワᅩリᅩᆭᅪ゚oᅩ쏘ルᅩᄚᅩ" "ᅠ" "k" "ᅢ" "ᄄ" "ᅪ" "レ" "ᅩ" "ᆴ" "ᅩ" "ᄎ" "ᅩ" "ᆰ" "ᅩ" "ᄍ" "ᅩ" "ᄆ" "ᅩ" "ᄂ" " " "ᅩヨtᅩンᅪユᅩ뽃ᅩ콝ᅪ゙hᅩ톼モᅩ볺ᅩ뽀リᅩᄇeᅪヌᅩᆪᅩᄚᅩᆭᅩᆲᅪホ " "ᅩ꼬토코모リhᅪレᅪホᅪルᅩワᅩᆪᅩ봐ナiᅩᆭᅩ볷ᅩᄚᅩᄂvᅩ콰ヘeᅩ촔ᅩ뽉ᅩᄚ-" "mᅩᄁiᅪナnᅩヨᅩ초゙ᅩ봂ᅩᄚdᅩ소토゚ᅪルᅩ로토リᅩᄈ " "ᅩ゙ᅩᆬᅩ모뽌rᅩロᅩラᅩリeᅪルpᅪᅠrᅩ토" "゙" "ᅩ" "ᄏ" "ᅩ" "ᆳ" "ᅩ" "ラ" "e" "ᅩ" "ᄎ" "ᅩ" "ᅠ" "ᅩ" "ᆪ" "ᅪ" "゚" "s" "ᅩ" "リ" "ᅪ" "ヌ" "ᅩ" "ᄈ" "ᅪ" "ヘ" "ᅩ" "ン" "ᅪ" "ノ" "e" "ᅪ" "ノ" "ᅩ" "ᆬ" "ᅩ" "ᆵ" "ᅩ" "゙" "ᅩ" "ᄇ" "ᅪ" "レ" "ᅩ" "ᆲᅪワᅦ쫇ᅪホᅪホᅩ゚ᅩヨᅪヌᅩᄂtᅪヘᅩᆲᅩ놔モᅩ톬ᅪリᅪナiᅩᆰᅩᄆnᅪ" "ᅠ" "g" "ᅩ" "ᄡ" "ᅪ" "ノ" " " "ᅪマᅪノᅪナcᅩᆲᅩ゚hᅪᄀaᅩᆱᅩ콢ᅪリoᅩᆱᅩ゚ᅩヨᅪヘᅩルᅩンᅪノsᅩラᅩᆭᅩᄇ.ᅩ또쫘ネᅩᆪ", "ᅩ과モᅩ゙ᅪナIᅩラᅩリᅩᆭᅪンnᅪヌᅪヌᅪルvᅩᆴᅩᆱokᅩ볾ᅩルᅪネiᅩヨᅪルᅩᆳᅩ쪼" "ᅠ" "ᅩ" "゙" "n" "ᅩ" "ᄀ" "ᅩ" "ᄏ" "ᅩ" "ᆴ" "ᅩ" "ᆪ" "ᅩ" "ᄎ" "g" "ᅩ" "ᄇ" "ᅪ" "ネ" "ᅪ" "ル" "ᅩ" "ᆳ" "ᅪルᅩᆲᅪホ ᅩᄚtᅪヤᅩᆭhᅩ゙ᅩᄇeᅩ꼬ᄂ " "ᅪヘᅩᆲᅩ봐ヨfᅩᄡᅩリᅪユᅩᆪᅢ똬ヨ£ᄎ쫁ᅩᄅlᅪヨᅪヤᅪレiᅪモᅪレᅩᆭᅪ" "ᅠ" "n" "ᅪ" "ヨ" "ᅪ" "ヘ" "ᅩ" "ラ" "ᅪ" "モ" "ᅩ" "ᄈ" "ᅩ" "ᆴ" "g" "ᅪ" "ヘ" " " "ᅩᄄoᅪレᅩᆰᅪᄀfᅩリᅩᆪᅩᆲ " "ᅩヨᅩリᅪヨᅩ゚ᅪルᅩᆴcᅭノᅪヤᅩᆱᅪヨᅪモᅪヌᅪヨᅪナhᅩ소녻ᅪレᅪヤᅢ고ラᅩ톼ユᅪナoᅩ톣ᅩᆬsᅩ뫄ネᅩ초ヨᅩᆭᅩ콰ᄁ." "ᅩロᅩヨᅩ゙ᅩᅠᅩᆱᅩᄚ", "ᅩラᅩ촤ヨᅩ쫊ᅪモ£ᄍᆴᅩ놔ヘᅩᆬᅪヌᅪネhᅩ보チeᅪマᅪモᅩ토ラᅩルᅩ톣ᅪヤ " "ᅪヌᅩワᅩ모ᅠᅪモᅪヘᅪナNᅪユᅪᅠeᅩラᅩᄆzᅩ" "リ" "ᅩ" "ン" "ᅩ" "ワ" "ᅩ" "ᄎ" "ᅪ" "ル" "p" "ᅩ" "ᄂ" "ᅩ" "ᄎ" "ᅩ" "ᄍ" "ᅪ" "ヘ" "ᅩ" "ᆵ" "ᅪ" "レ" "e" "ᅩ" "ᅠ" "ᅩ" "ᄏ" "ᅩ" "ᅠ" "ᅪ" "ワ" "r" "ᅩ" "ᄄ" "ᅩ" "ᄂ" "ᅪ" "ヘ" "ᅩ" "ᄎ" "ᅩヨᅪヤᅩヨᅩヨdᅩᅠᅩ゚ᅩᆳᅩᆲᅩンᅪ゚iᅩᆭᅪヨ" "ᅩ" "ᄅ" "ᅪ" "モ" "ᅪ" "ヤ" "ᅩ" "ᄂ" "a" "ᅩ" "ᅠ" "ᅩ" "ラ" "ᅩ" "ᆲ" "ᅪ" "ノ" "ᅩ" "ル" "n" "ᅪ" "レ" "ᅪ" "ワ" " " "ᅩ코゙ᅩᄚᅪレᅪナhᅩ솨ノiᅩ뽀゙vᅩ꽈ヌ£ᄌルᅪホᅪ゚-ᅭノᅩᆳᅩ로톼ヤmᅩ놄ᅩᆱiᅪユᅪヌᅩンᅩᆭnᅩラᅪル£ᄌヘᅩ゚ " "ᅩᆵᅩ봐ユᅪ゙ᅦᆱᅩ゚ᅩᆵᅩᄚᅩ봐ルᅩ코ンf " "ᅩᆰᅩᄚᅩᄚᅩラᅩヨᅩᆳᅩリᅪリcᅩᆭᅪヘᅩ보゙ᅪヘᅩ로ル£ᄌᆬᅪレaᅩᆴᅪホᅩ゚ᅩルᅪワᅥ고로쫘ホsᅩᄂ.ᅩンᅩン " "ᅭノZᅩ고ヨᅩワᅪヨᅩᄚᅩᆪᅪノᅩワaᅪヨᅩᄚᅪルᅩᆲᅪᄀlᅩ볾ᅩ뽜ヘᅩᄅgᅩ고゚ᅩ토뫄レᅩ゙ᅩᆲᅪナoᅩラᅪワ.ᅩ゚", "ᅩᆭHᅩᆲᅩ노ラᅩ놔ンeᅪワ ᅩワᅩᆬᅩンᅩ콰ヘᅩ゚ᅩチwᅩユhᅩヨᅩᆵᅪモoᅩンᅪルᅩヨᅪホᅩ몵 " "ᅭノᅩ초ルᅩ゙ᅩ゚ᅪネWᅩ오톬aᅩ촑ᅪヘᅣᆵᅪネᅪユᅩᆳᅪルᅩᆵᅩワtᅩ쏘톭sᅩリᅪルᅪヨᅩユ " "ᅩᅠᅩᆱᅩᅠBᅩ콰ヘᅪルᅪノᅩ뽜ナeᅩᄉhᅩ소" "ᆲ" "ᅪ" "ヌ" "ᅩ" "ᆱ" "ᅪ" "ル" "i" "ᅩ" "ᄍ" "ᅪ" "モ" "ᅩ" "ᄈ" "ᅩ" "ᄈ" "ᅩ" "ᆴ" "ᅪ" "ホ" "ᅩ" "ᆱ" "ᅩ" "ユ" "n" "ᅪ" "゚" "d" "ᅩ" "ᄡ" "ᅩ" "ᆰ" "ᅩ" "ワ" "ᅩ" "ヨ" " " "ᅩᄚᅪノᅩ롸ヌᅪルᅩ봐゙ᅪナTᅪヨᅩ톼モᅩᆰᅪᄁhᅪマᅪモᅩᆴᅩᄏeᅩᆲᅩンᅩ゚ᅪナ " "ᅩ노쪼ンWᅪルᅩ゙ᅩンᅪヤᅪヌᅪンᅪナaᅪマᅪモᅪヤᅩ쪼톣lᅩᄡᅪヤᅩᄚᅩ노゚ᅪヤ£ᄌ폶.ᅪユ", "Zᅩᆴᅩ゙ᅩᅠᅪルᅪヤᅪナ£ᄌタᅩラᅩ゙ᅪネᅩ코" "ラ" "£" "ᄌ" "ᄊ" "ᅪ" "ル" "ᅪ" "ホ" "ᅩ" "ᆵ" "ᅩ" "ᄍ" "ᅩ" "゙" "ᅪ" "モ" "G" "ᅩ" "ᄏ" "O" "ᅩ" "ᆳ" "ᅩ" "ラ" "ᅩ" "ᆴ", // Unicode Upsidedown // // Strings which contain unicode with an \"upsidedown\" effect (via // http://www.upsidedowntext.com) "ᅨル￉ミnb£ᄡノl￉ミ ￉ミuᅥテ￉ミ￉ᆵ ᅦン￉ᄍolop " "ᅧヌᅦン " "ᅦン￉ᄍoq￉ミl " "ᅧヌn " "ᅧヌunp£ᄡノp£ᄡノ￉ヤu£ᄡノ ￉ᄍod￉ᆵᅦンᅧヌ " "po￉ᆵsn£ᄡノᅦン " "op " "pᅦンs " "'ᅧヌ£ᄡノlᅦン " "ᅥテu£ᄡノ￉ヤs£ᄡノd£ᄡノp￉ミ " "￉ᄍnᅧヌᅦンᅧヌ￉ヤᅦンsuo￉ヤ " "'ᅧヌᅦン￉ᆵ￉ミ " "ᅧヌ£ᄡノs " "￉ᄍolop ￉ᆵnsd£ᄡノ " "￉ᆵᅦン￉ᄍoᅨᆬ", "00ᅨルᅥヨ$-", // Unicode font // // Strings which contain bold/italic/etc. versions of normal characters "￯ᄐᄡ￯ᄑネ￯ᄑナ ￯ᄑム￯ᄑユ￯ᄑノ￯ᄑテ￯ᄑヒ " "￯ᄑツ￯ᄑメ￯ᄑマ￯ᄑラ￯ᄑホ " "￯ᄑニ￯ᄑマ￯ᄑリ ￯ᄑハ￯ᄑユ￯ᄑヘ￯ᄑミ￯ᄑモ " "￯ᄑマ￯ᄑヨ￯ᄑナ￯ᄑメ " "￯ᄑヤ￯ᄑネ￯ᄑナ " "￯ᄑフ￯ᄑチ￯ᄑレ￯ᄑル ￯ᄑト￯ᄑマ￯ᄑヌ", "￰ンミモ￰ンミᄀ￰ンミ゙ " "￰ンミᆰ￰ンミᆴ￰ンミᄁ￰ンミワ￰ンミᄂ " "￰ンミロ￰ンミᆱ￰ンミᄄ￰ンミᄚ￰ンミᄃ " "￰ンミ゚￰ンミᄄ￰ンミᄆ " "￰ンミᆪ￰ンミᆴ￰ンミᆭ￰ンミᄅ￰ンミᆲ " "￰ンミᄄ￰ンミᆵ￰ンミ゙￰ンミᆱ " "￰ンミᆳ￰ンミᄀ￰ンミ゙ " "￰ンミᆬ￰ンミレ￰ンミᄈ￰ンミᄇ " "￰ンミン￰ンミᄄ￰ンミᅠ", "￰ンユ﾿￰ンヨヘ￰ンヨハ " "￰ンヨヨ￰ンヨレ￰ンヨホ￰ンヨネ￰ンヨミ " "￰ンヨヌ￰ンヨラ￰ンヨヤ￰ンヨワ￰ンヨモ " "￰ンヨヒ￰ンヨヤ￰ンヨン " "￰ンヨマ￰ンヨレ￰ンヨメ￰ンヨユ￰ンヨリ " "￰ンヨヤ￰ンヨロ￰ンヨハ￰ンヨラ " "￰ンヨル￰ンヨヘ￰ンヨハ " "￰ンヨム￰ンヨニ￰ンヨ゚￰ンヨ゙ " "￰ンヨノ￰ンヨヤ￰ンヨフ", "￰ンムᄏ￰ンメノ￰ンメニ " "￰ンメメ￰ンメヨ￰ンメハ￰ンメト￰ンメフ " "￰ンメテ￰ンメモ￰ンメミ￰ンメリ￰ンメマ " "￰ンメヌ￰ンメミ￰ンメル " "￰ンメヒ￰ンメヨ￰ンメホ￰ンメム￰ンメヤ " "￰ンメミ￰ンメラ￰ンメニ￰ンメモ " "￰ンメユ￰ンメノ￰ンメニ " "￰ンメヘ￰ンメツ￰ンメロ￰ンメレ " "￰ンメナ￰ンメミ￰ンメネ", "￰ンモᆪ￰ンモᄆ￰ンモᆴ " "￰ンモᄎ￰ンモᄒ￰ンモᄇ￰ンモᆲ￰ンモᄡ " "￰ンモᆱ￰ンモᄏ￰ンモᄌ￰ンヤタ￰ンモᄋ " "￰ンモᆵ￰ンモᄌ￰ンヤチ " "￰ンモᄈ￰ンモᄒ￰ンモᄊ￰ンモᄍ￰ンモᄐ " "￰ンモᄌ￰ンモ﾿￰ンモᆴ￰ンモᄏ " "￰ンモᄑ￰ンモᄆ￰ンモᆴ " "￰ンモᄉ￰ンモᆰ￰ンヤテ￰ンヤツ " "￰ンモᆳ￰ンモᄌ￰ンモᄚ", "￰ンユヒ￰ンユル￰ンユヨ " "￰ンユᄁ￰ンユᆭ￰ンユレ￰ンユヤ￰ンユワ " "￰ンユモ￰ンユᆪ￰ンユᅠ￰ンユᄄ￰ンユ゚ " "￰ンユラ￰ンユᅠ￰ンユᄅ " "￰ンユロ￰ンユᆭ￰ンユ゙￰ンユᄀ￰ンユᄂ " "￰ンユᅠ￰ンユᄃ￰ンユヨ￰ンユᆪ " "￰ンユᆬ￰ンユル￰ンユヨ " "￰ンユン￰ンユメ￰ンユᆱ￰ンユᆰ " "￰ンユユ￰ンユᅠ￰ンユリ", "￰ンレテ￰ンレム￰ンレホ " "￰ンレレ￰ンレ゙￰ンレメ￰ンレフ￰ンレヤ " "￰ンレヒ￰ンレロ￰ンレリ￰ンレᅠ￰ンレラ " "￰ンレマ￰ンレリ￰ンレᄀ " "￰ンレモ￰ンレ゙￰ンレヨ￰ンレル￰ンレワ " "￰ンレリ￰ンレ゚￰ンレホ￰ンレロ " "￰ンレン￰ンレム￰ンレホ " "￰ンレユ￰ンレハ￰ンレᆪ￰ンレᄁ " "￰ンレヘ￰ンレリ￰ンレミ", "¬メᆵ¬メᆪ¬メᅠ ¬メᆲ¬メᄚ¬メᄂ¬メ゙¬メᆭ " "¬メン¬メᆳ¬メᆰ¬メᄇ¬メᄅ " "¬メᄀ¬メᆰ¬メᄈ " "¬メᆬ¬メᄚ¬メᄄ¬メᆱ¬メᆴ " "¬メᆰ¬メᄆ¬メᅠ¬メᆳ " "¬メᆵ¬メᆪ¬メᅠ " "¬メᄃ¬メワ¬メᄉ¬メᄡ " "¬メ゚¬メᆰ¬メᄁ", // Script Injection // // Strings which attempt to invoke a benign script injection; shows // vulnerability to XSS "", "<script>alert('123');</script>", "", "", "\">", "'>", ">", "", "< / script >< script >alert(123)< / script >", " onfocus=JaVaSCript:alert(123) autofocus", "\" onfocus=JaVaSCript:alert(123) autofocus", "' onfocus=JaVaSCript:alert(123) autofocus", "￯ᄐワscript￯ᄐ゙alert(123)￯ᄐワ/script￯ᄐ゙", "ript>alert(123)ript>", "-->", "\";alert(123);t=\"", "';alert(123);t='", "JavaSCript:alert(123)", ";alert(123);", "src=JaVaSCript:prompt(132)", "\"><\\x3Cscript>javascript:alert(1)", "'`\"><\\x00script>javascript:alert(1)", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "ABC
DEF", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "test", "`\"'>", "`\"'>", "`\"'>", "`\"'>", "`\"'>", "`\"'>", "`\"'>", "`\"'>", "`\"'>", "`\"'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "\"`'>", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "", "XXX", "javascript:alert(1)\"` `>", "", "", "<a href=http://foo.bar/#x=`y></a><img alt=\"`><img src=x:x " "onerror=javascript:alert(1)></a>\">", "<!--[if]><script>javascript:alert(1)</script -->", "<!--[if<img src=x onerror=javascript:alert(1)//]> -->", "<script src=\"/\%(jscript)s\"></script>", "<script src=\"\\%(jscript)s\"></script>", "<IMG \"\"\"><SCRIPT>alert(\"XSS\")</SCRIPT>\">", "<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>", "<IMG SRC=# onmouseover=\"alert('xxs')\">", "<IMG SRC= onmouseover=\"alert('xxs')\">", "<IMG onmouseover=\"alert('xxs')\">", "<IMG " "SRC=javascript:a&#" "108;ert('XSS')>", "<IMG " "SRC=javascr&#" "0000105pt:aler&#" "0000116&#" "0000040'XSS')>", "<IMG " "SRC=javascript:al&#" "x65rt('XSS')>", "<IMG SRC=\"jav ascript:alert('XSS');\">", "<IMG SRC=\"jav ascript:alert('XSS');\">", "<IMG SRC=\"jav ascript:alert('XSS');\">", "<IMG SRC=\"jav ascript:alert('XSS');\">", "perl -e 'print \"<IMG SRC=java\0script:alert(\"XSS\")>\";' > out", "<IMG SRC=\"  javascript:alert('XSS');\">", "<SCRIPT/XSS SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>", "<BODY onload!#$%&()*~+-_.,:;?@[/|\\]^`=alert(\"XSS\")>", "<SCRIPT/SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>", "<<SCRIPT>alert(\"XSS\");//<</SCRIPT>", "<SCRIPT SRC=http://ha.ckers.org/xss.js?< B >", "<SCRIPT SRC=//ha.ckers.org/.j>", "<IMG SRC=\"javascript:alert('XSS')\"", "<iframe src=http://ha.ckers.org/scriptlet.html <", "\\\";alert('XSS');//", "<u oncopy=alert()> Copy me</u>", "<i onwheel=alert(1)> Scroll over me </i>", "<plaintext>", "http://a/%%30%30", "</textarea><script>alert(123)</script>", // SQL Injection // // Strings which can cause a SQL injection if inputs are not sanitized "1;DROP TABLE users", "1'; DROP TABLE users-- 1", "' OR 1=1 -- 1", "' OR '1'='1", " ", "%", "_", // Server Code Injection // // Strings which can cause user to run code on server as a privileged user //(c.f. https://news.ycombinator.com/item?id=7665153) "-", "--", "--version", "--help", "$USER", "/dev/null; touch /tmp/blns.fail ; echo", "`touch /tmp/blns.fail`", "$(touch /tmp/blns.fail)", "@{[system \"touch /tmp/blns.fail\"]}", // Command Injection (Ruby) // // Strings which can call system commands within Ruby/Rails applications "eval(\"puts 'hello world'\")", "System(\"ls -al /\")", "`ls -al /`", "Kernel.exec(\"ls -al /\")", "Kernel.exit(1)", "%x('ls -al /')", // XXE Injection (XML) // // String which can reveal system files when parsed by a badly configured // XML parser "<?xml version=\"1.0\" encoding=\"ISO-8859-1\"?><!DOCTYPE foo [ <!ELEMENT " "foo ANY ><!ENTITY xxe SYSTEM \"file:///etc/passwd\" >]><foo>&xxe;</foo>", // Unwanted Interpolation // // Strings which can be accidentally expanded into different strings if // evaluated in the wrong context, e.g. used as a printf format string or // via // Perl or // shell eval. Might expose sensitive data from the program doing the // interpolation, or might just represent the wrong string. "$HOME", "$ENV{'HOME'}", "%d", "%s", "{0}", "%*.*s", "File:///", // File Inclusion // // Strings which can cause user to pull in files that should not be a part // of a web server "../../../../../../../../../../../etc/passwd%00", "../../../../../../../../../../../etc/hosts", // Known CVEs and Vulnerabilities // // Strings that test for known vulnerabilities "() { 0; }; touch /tmp/blns.shellshock1.fail;", "() { _; } >_[$($())] { touch /tmp/blns.shellshock2.fail; }", "<<< %s(un='%s') = %u", "+++ATH0", // MSDOS/Windows Special Filenames // // Strings which are reserved characters in MSDOS/Windows "CON", "PRN", "AUX", "CLOCK$", "NUL", "A:", "ZZ:", "COM1", "LPT1", "LPT2", "LPT3", "COM2", "COM3", "COM4", // IRC specific strings // // Strings that may occur on IRC clients that make security products freak // out "DCC SEND STARTKEYLOGGER 0 0 0", // Scunthorpe Problem // // Innocuous strings which may be blocked by profanity filters //(https://en.wikipedia.org/wiki/Scunthorpe_problem) "Scunthorpe General Hospital", "Penistone Community Church", "Lightwater Country Park", "Jimmy Clitheroe", "Horniman Museum", "shitake mushrooms", "RomansInSussex.co.uk", "http://www.cum.qc.ca/", "Craig Cockburn, Software Specialist", "Linda Callahan", "Dr. Herman I. Libshitz", "magna cum laude", "Super Bowl XXX", "medieval erection of parapets", "evaluate", "mocha", "expression", "Arsenal canal", "classic", "Tyson Gay", "Dick Van Dyke", "basement", // Human injection // // Strings which may cause human to reinterpret worldview "If you're reading this, you've been in a coma for almost 20 years now. " "We're trying a new technique. We don't know where this message will end " "up in your " "dream, but we hope it works. Please wake up, we miss you.", // Terminal escape codes // // Strings which punish the fools who use cat/type on this file "Roses are red, violets are blue. Hope you enjoy " "terminal hue", "But now...for my greatest trick...", "The quick brown fox... [Beeeep]", // iOS Vulnerabilities // // Strings which crashed iMessage in various versions of iOS "Power￙ト￙マ￙ト￙マ￘ᄉ￙ム￘ᄄ￙マ￙ト￙マ￙ト￘" "ᄉ" "￙" "ム" "￘" "ᄄ" "￙" "マ" "￘" "ᄆ" "￘" "ᄆ" "￙ヒ ¢ᆬᆪ ¢ᆬᆪh ¢ᆬᆪ " "¢ᆬᆪ¥ニラ", "￰゚マᄈ0￰゚フネ￯ᄌマ"}; // clang-format on