DEF",
249 | "
test",
250 | "
test",
251 | "
test",
252 | "
test",
253 | "
test",
254 | "
test",
255 | "
test",
256 | "
test",
257 | "
test",
258 | "
test",
259 | "
test",
260 | "
test",
261 | "
test",
262 | "
test",
263 | "
test",
264 | "
test",
265 | "
test",
266 | "
test",
267 | "
test",
268 | "
test",
269 | "
test",
270 | "
test",
271 | "
test",
272 | "
test",
273 | "
test",
274 | "
test",
275 | "
test",
276 | "
test",
277 | "
test",
278 | "
test",
279 | "
test",
280 | "
test",
281 | "
test",
282 | "
test",
283 | "
test",
284 | "
test",
285 | "
test",
286 | "
test",
287 | "
test",
288 | "
test",
289 | "
test",
290 | "
test",
291 | "
test",
292 | "
test",
293 | "
test",
294 | "
test",
295 | "
test",
296 | "
test",
297 | "
test",
298 | "
test",
299 | "
test",
300 | "
test",
301 | "
test",
302 | "
test",
303 | "
test",
304 | "
test",
305 | "
test",
306 | "`"'>

",
307 | "`"'>

",
308 | "`"'>

",
309 | "`"'>

",
310 | "`"'>

",
311 | "`"'>

",
312 | "`"'>

",
313 | "`"'>

",
314 | "`"'>

",
315 | "`"'>

",
316 | ""`'>",
317 | ""`'>",
318 | ""`'>",
319 | ""`'>",
320 | ""`'>",
321 | ""`'>",
322 | ""`'>",
323 | ""`'>",
324 | ""`'>",
325 | ""`'>",
326 | ""`'>",
327 | ""`'>",
328 | ""`'>",
329 | ""`'>",
330 | ""`'>",
331 | ""`'>",
332 | ""`'>",
333 | ""`'>",
334 | ""`'>",
335 | ""`'>",
336 | ""`'>",
337 | ""`'>",
338 | ""`'>",
339 | ""`'>",
340 | ""`'>",
341 | ""`'>",
342 | ""`'>",
343 | ""`'>",
344 | ""`'>",
345 | ""`'>",
346 | ""`'>",
347 | ""`'>",
348 | ""`'>",
349 | ""`'>",
350 | ""`'>",
351 | ""`'>",
352 | ""`'>",
353 | "
![]()
",
354 | "
![]()
",
355 | "
![]()
",
356 | "
![]()
",
357 | "
![]()
",
358 | "
![]()
",
359 | "
![]()
",
360 | "
![]()
",
361 | "
![]()
",
362 | "
![]()
",
363 | "
![]()
",
364 | "
![]()
",
365 | "
![]()
",
366 | "
![]()
",
367 | "
![]()
",
368 | "
![]()
",
369 | "
![]()
",
370 | "
![]()
",
371 | "
![]()
",
372 | "
![]()
",
373 | "
![]()
",
374 | "
![]()
",
375 | "
")
",
376 | "
")
",
377 | "
")
",
378 | "
")
",
379 | "
")
",
380 | "
![]()
",
381 | "

",
382 | "

",
383 | "

",
384 | "

",
385 | "

",
386 | "

",
387 | "
XXX",
388 | "
</script>)
",
389 | "
![javascript:alert(1)//"]()
",
390 | "
",
391 | "
",
392 | "",
393 | "",
394 | "",
395 | "",
396 | "
">",
397 | "
",
398 | "
",
399 | "
",
400 | "
",
401 | "
",
402 | "
",
403 | "
",
404 | "
",
405 | "
",
406 | "
",
407 | "
",
408 | "perl -e 'print "
";' > out",
409 | "
",
410 | "",
411 | "",
412 | "",
413 | "<",
414 | "",
424 | "1;DROP TABLE users",
425 | "1'; DROP TABLE users-- 1",
426 | "' OR 1=1 -- 1",
427 | "' OR '1'='1",
428 | " ",
429 | "%",
430 | "_",
431 | "-",
432 | "--",
433 | "--version",
434 | "--help",
435 | "$USER",
436 | "/dev/null; touch /tmp/blns.fail ; echo",
437 | "`touch /tmp/blns.fail`",
438 | "$(touch /tmp/blns.fail)",
439 | "@{[system "touch /tmp/blns.fail"]}",
440 | "eval("puts 'hello world'")",
441 | "System("ls -al /")",
442 | "`ls -al /`",
443 | "Kernel.exec("ls -al /")",
444 | "Kernel.exit(1)",
445 | "%x('ls -al /')",
446 | "]>
&xxe;",
447 | "$HOME",
448 | "$ENV{'HOME'}",
449 | "%d",
450 | "%s%s%s%s%s",
451 | "{0}",
452 | "%*.*s",
453 | "%@",
454 | "%n",
455 | "File:///",
456 | "../../../../../../../../../../../etc/passwd%00",
457 | "../../../../../../../../../../../etc/hosts",
458 | "() { 0; }; touch /tmp/blns.shellshock1.fail;",
459 | "() { _; } >_[$($())] { touch /tmp/blns.shellshock2.fail; }",
460 | "<<< %s(un='%s') = %u",
461 | "+++ATH0",
462 | "CON",
463 | "PRN",
464 | "AUX",
465 | "CLOCK$",
466 | "NUL",
467 | "A:",
468 | "ZZ:",
469 | "COM1",
470 | "LPT1",
471 | "LPT2",
472 | "LPT3",
473 | "COM2",
474 | "COM3",
475 | "COM4",
476 | "DCC SEND STARTKEYLOGGER 0 0 0",
477 | "Scunthorpe General Hospital",
478 | "Penistone Community Church",
479 | "Lightwater Country Park",
480 | "Jimmy Clitheroe",
481 | "Horniman Museum",
482 | "shitake mushrooms",
483 | "RomansInSussex.co.uk",
484 | "http://www.cum.qc.ca/",
485 | "Craig Cockburn, Software Specialist",
486 | "Linda Callahan",
487 | "Dr. Herman I. Libshitz",
488 | "magna cum laude",
489 | "Super Bowl XXX",
490 | "medieval erection of parapets",
491 | "evaluate",
492 | "mocha",
493 | "expression",
494 | "Arsenal canal",
495 | "classic",
496 | "Tyson Gay",
497 | "Dick Van Dyke",
498 | "basement",
499 | "If you're reading this, you've been in a coma for almost 20 years now. We're trying a new technique. We don't know where this message will end up in your dream, but we hope it works. Please wake up, we miss you.",
500 | "Roses are [0;31mred[0m, violets are [0;34mblue. Hope you enjoy terminal hue",
501 | "But now...[20Cfor my greatest trick...[8m",
502 | "The quick brown fox... [Beeeep]",
503 | "Powerلُلُصّبُلُلصّبُررً ॣ ॣh ॣ ॣ冗",
504 | "🏳0🌈️",
505 | "జ్ఞా"
506 | ]
507 |
--------------------------------------------------------------------------------
/src/test/resources/naughty_strings.json:
--------------------------------------------------------------------------------
1 | [
2 | "",
3 | "undefined",
4 | "undef",
5 | "null",
6 | "NULL",
7 | "(null)",
8 | "nil",
9 | "NIL",
10 | "true",
11 | "false",
12 | "True",
13 | "False",
14 | "TRUE",
15 | "FALSE",
16 | "None",
17 | "hasOwnProperty",
18 | "\\",
19 | "\\\\",
20 | "0",
21 | "1",
22 | "1.00",
23 | "$1.00",
24 | "1/2",
25 | "1E2",
26 | "1E02",
27 | "1E+02",
28 | "-1",
29 | "-1.00",
30 | "-$1.00",
31 | "-1/2",
32 | "-1E2",
33 | "-1E02",
34 | "-1E+02",
35 | "1/0",
36 | "0/0",
37 | "-2147483648/-1",
38 | "-9223372036854775808/-1",
39 | "-0",
40 | "-0.0",
41 | "+0",
42 | "+0.0",
43 | "0.00",
44 | "0..0",
45 | ".",
46 | "0.0.0",
47 | "0,00",
48 | "0,,0",
49 | ",",
50 | "0,0,0",
51 | "0.0/0",
52 | "1.0/0.0",
53 | "0.0/0.0",
54 | "1,0/0,0",
55 | "0,0/0,0",
56 | "--1",
57 | "-",
58 | "-.",
59 | "-,",
60 | "999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999",
61 | "NaN",
62 | "Infinity",
63 | "-Infinity",
64 | "INF",
65 | "1#INF",
66 | "-1#IND",
67 | "1#QNAN",
68 | "1#SNAN",
69 | "1#IND",
70 | "0x0",
71 | "0xffffffff",
72 | "0xffffffffffffffff",
73 | "0xabad1dea",
74 | "123456789012345678901234567890123456789",
75 | "1,000.00",
76 | "1 000.00",
77 | "1'000.00",
78 | "1,000,000.00",
79 | "1 000 000.00",
80 | "1'000'000.00",
81 | "1.000,00",
82 | "1 000,00",
83 | "1'000,00",
84 | "1.000.000,00",
85 | "1 000 000,00",
86 | "1'000'000,00",
87 | "01000",
88 | "08",
89 | "09",
90 | "2.2250738585072011e-308",
91 | ",./;'[]\\-=",
92 | "<>?:\"{}|_+",
93 | "!@#$%^&*()`~",
94 | "\u0001\u0002\u0003\u0004\u0005\u0006\u0007\b\u000e\u000f\u0010\u0011\u0012\u0013\u0014\u0015\u0016\u0017\u0018\u0019\u001a\u001b\u001c\u001d\u001e\u001f",
95 | "",
96 | "\t\u000b\f
",
97 | "",
98 | "",
99 | "�",
100 | "Ω≈ç√∫˜µ≤≥÷",
101 | "åß∂ƒ©˙∆˚¬…æ",
102 | "œ∑´®†¥¨ˆøπ“‘",
103 | "¡™£¢∞§¶•ªº–≠",
104 | "¸˛Ç◊ı˜Â¯˘¿",
105 | "ÅÍÎÏ˝ÓÔÒÚÆ☃",
106 | "Œ„´‰ˇÁ¨ˆØ∏”’",
107 | "`⁄€‹›fifl‡°·‚—±",
108 | "⅛⅜⅝⅞",
109 | "ЁЂЃЄЅІЇЈЉЊЋЌЍЎЏАБВГДЕЖЗИЙКЛМНОПРСТУФХЦЧШЩЪЫЬЭЮЯабвгдежзийклмнопрстуфхцчшщъыьэюя",
110 | "٠١٢٣٤٥٦٧٨٩",
111 | "⁰⁴⁵",
112 | "₀₁₂",
113 | "⁰⁴⁵₀₁₂",
114 | "ด้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็ ด้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็ ด้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็็้้้้้้้้็็็็็้้้้้็็็็",
115 | "'",
116 | "\"",
117 | "''",
118 | "\"\"",
119 | "'\"'",
120 | "\"''''\"'\"",
121 | "\"'\"'\"''''\"",
122 | "
",
123 | "
",
124 | "
",
125 | "
",
126 | "田中さんにあげて下さい",
127 | "パーティーへ行かないか",
128 | "和製漢語",
129 | "部落格",
130 | "사회과학원 어학연구소",
131 | "찦차를 타고 온 펲시맨과 쑛다리 똠방각하",
132 | "社會科學院語學研究所",
133 | "울란바토르",
134 | "𠜎𠜱𠝹𠱓𠱸𠲖𠳏",
135 | "表ポあA鷗ŒéB逍Üߪąñ丂㐀𠀀",
136 | "Ⱥ",
137 | "Ⱦ",
138 | "ヽ༼ຈل͜ຈ༽ノ ヽ༼ຈل͜ຈ༽ノ",
139 | "(。◕ ∀ ◕。)",
140 | "`ィ(´∀`∩",
141 | "__ロ(,_,*)",
142 | "・( ̄∀ ̄)・:*:",
143 | "゚・✿ヾ╲(。◕‿◕。)╱✿・゚",
144 | ",。・:*:・゜’( ☻ ω ☻ )。・:*:・゜’",
145 | "(╯°□°)╯︵ ┻━┻)",
146 | "(ノಥ益ಥ)ノ ┻━┻",
147 | "┬─┬ノ( º _ ºノ)",
148 | "( ͡° ͜ʖ ͡°)",
149 | "😍",
150 | "👩🏽",
151 | "👾 🙇 💁 🙅 🙆 🙋 🙎 🙍",
152 | "🐵 🙈 🙉 🙊",
153 | "❤️ 💔 💌 💕 💞 💓 💗 💖 💘 💝 💟 💜 💛 💚 💙",
154 | "✋🏿 💪🏿 👐🏿 🙌🏿 👏🏿 🙏🏿",
155 | "🚾 🆒 🆓 🆕 🆖 🆗 🆙 🏧",
156 | "0️⃣ 1️⃣ 2️⃣ 3️⃣ 4️⃣ 5️⃣ 6️⃣ 7️⃣ 8️⃣ 9️⃣ 🔟",
157 | "🇺🇸🇷🇺🇸 🇦🇫🇦🇲🇸",
158 | "🇺🇸🇷🇺🇸🇦🇫🇦🇲",
159 | "🇺🇸🇷🇺🇸🇦",
160 | "123",
161 | "١٢٣",
162 | "ثم نفس سقطت وبالتحديد،, جزيرتي باستخدام أن دنو. إذ هنا؟ الستار وتنصيب كان. أهّل ايطاليا، بريطانيا-فرنسا قد أخذ. سليمان، إتفاقية بين ما, يذكر الحدود أي بعد, معاملة بولندا، الإطلاق عل إيو.",
163 | "בְּרֵאשִׁית, בָּרָא אֱלֹהִים, אֵת הַשָּׁמַיִם, וְאֵת הָאָרֶץ",
164 | "הָיְתָהtestالصفحات التّحول",
165 | "﷽",
166 | "ﷺ",
167 | "مُنَاقَشَةُ سُبُلِ اِسْتِخْدَامِ اللُّغَةِ فِي النُّظُمِ الْقَائِمَةِ وَفِيم يَخُصَّ التَّطْبِيقَاتُ الْحاسُوبِيَّةُ، ",
168 | "test",
169 | "test",
170 | "
test
",
171 | "testtest",
172 | "test",
173 | "Ṱ̺̺̕o͞ ̷i̲̬͇̪͙n̝̗͕v̟̜̘̦͟o̶̙̰̠kè͚̮̺̪̹̱̤ ̖t̝͕̳̣̻̪͞h̼͓̲̦̳̘̲e͇̣̰̦̬͎ ̢̼̻̱̘h͚͎͙̜̣̲ͅi̦̲̣̰̤v̻͍e̺̭̳̪̰-m̢iͅn̖̺̞̲̯̰d̵̼̟͙̩̼̘̳ ̞̥̱̳̭r̛̗̘e͙p͠r̼̞̻̭̗e̺̠̣͟s̘͇̳͍̝͉e͉̥̯̞̲͚̬͜ǹ̬͎͎̟̖͇̤t͍̬̤͓̼̭͘ͅi̪̱n͠g̴͉ ͏͉ͅc̬̟h͡a̫̻̯͘o̫̟̖͍̙̝͉s̗̦̲.̨̹͈̣",
174 | "̡͓̞ͅI̗̘̦͝n͇͇͙v̮̫ok̲̫̙͈i̖͙̭̹̠̞n̡̻̮̣̺g̲͈͙̭͙̬͎ ̰t͔̦h̞̲e̢̤ ͍̬̲͖f̴̘͕̣è͖ẹ̥̩l͖͔͚i͓͚̦͠n͖͍̗͓̳̮g͍ ̨o͚̪͡f̘̣̬ ̖̘͖̟͙̮c҉͔̫͖͓͇͖ͅh̵̤̣͚͔á̗̼͕ͅo̼̣̥s̱͈̺̖̦̻͢.̛̖̞̠̫̰",
175 | "̗̺͖̹̯͓Ṯ̤͍̥͇͈h̲́e͏͓̼̗̙̼̣͔ ͇̜̱̠͓͍ͅN͕͠e̗̱z̘̝̜̺͙p̤̺̹͍̯͚e̠̻̠͜r̨̤͍̺̖͔̖̖d̠̟̭̬̝͟i̦͖̩͓͔̤a̠̗̬͉̙n͚͜ ̻̞̰͚ͅh̵͉i̳̞v̢͇ḙ͎͟-҉̭̩̼͔m̤̭̫i͕͇̝̦n̗͙ḍ̟ ̯̲͕͞ǫ̟̯̰̲͙̻̝f ̪̰̰̗̖̭̘͘c̦͍̲̞͍̩̙ḥ͚a̮͎̟̙͜ơ̩̹͎s̤.̝̝ ҉Z̡̖̜͖̰̣͉̜a͖̰͙̬͡l̲̫̳͍̩g̡̟̼̱͚̞̬ͅo̗͜.̟",
176 | "̦H̬̤̗̤͝e͜ ̜̥̝̻͍̟́w̕h̖̯͓o̝͙̖͎̱̮ ҉̺̙̞̟͈W̷̼̭a̺̪͍į͈͕̭͙̯̜t̶̼̮s̘͙͖̕ ̠̫̠B̻͍͙͉̳ͅe̵h̵̬͇̫͙i̹͓̳̳̮͎̫̕n͟d̴̪̜̖ ̰͉̩͇͙̲͞ͅT͖̼͓̪͢h͏͓̮̻e̬̝̟ͅ ̤̹̝W͙̞̝͔͇͝ͅa͏͓͔̹̼̣l̴͔̰̤̟͔ḽ̫.͕",
177 | "Z̮̞̠͙͔ͅḀ̗̞͈̻̗Ḷ͙͎̯̹̞͓G̻O̭̗̮",
178 | "˙ɐnbᴉlɐ ɐuƃɐɯ ǝɹolop ʇǝ ǝɹoqɐl ʇn ʇunpᴉpᴉɔuᴉ ɹodɯǝʇ poɯsnᴉǝ op pǝs 'ʇᴉlǝ ƃuᴉɔsᴉdᴉpɐ ɹnʇǝʇɔǝsuoɔ 'ʇǝɯɐ ʇᴉs ɹolop ɯnsdᴉ ɯǝɹo˥",
179 | "00˙Ɩ$-",
180 | "The quick brown fox jumps over the lazy dog",
181 | "𝐓𝐡𝐞 𝐪𝐮𝐢𝐜𝐤 𝐛𝐫𝐨𝐰𝐧 𝐟𝐨𝐱 𝐣𝐮𝐦𝐩𝐬 𝐨𝐯𝐞𝐫 𝐭𝐡𝐞 𝐥𝐚𝐳𝐲 𝐝𝐨𝐠",
182 | "𝕿𝖍𝖊 𝖖𝖚𝖎𝖈𝖐 𝖇𝖗𝖔𝖜𝖓 𝖋𝖔𝖝 𝖏𝖚𝖒𝖕𝖘 𝖔𝖛𝖊𝖗 𝖙𝖍𝖊 𝖑𝖆𝖟𝖞 𝖉𝖔𝖌",
183 | "𝑻𝒉𝒆 𝒒𝒖𝒊𝒄𝒌 𝒃𝒓𝒐𝒘𝒏 𝒇𝒐𝒙 𝒋𝒖𝒎𝒑𝒔 𝒐𝒗𝒆𝒓 𝒕𝒉𝒆 𝒍𝒂𝒛𝒚 𝒅𝒐𝒈",
184 | "𝓣𝓱𝓮 𝓺𝓾𝓲𝓬𝓴 𝓫𝓻𝓸𝔀𝓷 𝓯𝓸𝔁 𝓳𝓾𝓶𝓹𝓼 𝓸𝓿𝓮𝓻 𝓽𝓱𝓮 𝓵𝓪𝔃𝔂 𝓭𝓸𝓰",
185 | "𝕋𝕙𝕖 𝕢𝕦𝕚𝕔𝕜 𝕓𝕣𝕠𝕨𝕟 𝕗𝕠𝕩 𝕛𝕦𝕞𝕡𝕤 𝕠𝕧𝕖𝕣 𝕥𝕙𝕖 𝕝𝕒𝕫𝕪 𝕕𝕠𝕘",
186 | "𝚃𝚑𝚎 𝚚𝚞𝚒𝚌𝚔 𝚋𝚛𝚘𝚠𝚗 𝚏𝚘𝚡 𝚓𝚞𝚖𝚙𝚜 𝚘𝚟𝚎𝚛 𝚝𝚑𝚎 𝚕𝚊𝚣𝚢 𝚍𝚘𝚐",
187 | "⒯⒣⒠ ⒬⒰⒤⒞⒦ ⒝⒭⒪⒲⒩ ⒡⒪⒳ ⒥⒰⒨⒫⒮ ⒪⒱⒠⒭ ⒯⒣⒠ ⒧⒜⒵⒴ ⒟⒪⒢",
188 | "",
189 | "<script>alert('123');</script>",
190 | "

",
191 | "