I'm looking for exhaustive list(s) of web attack strings, which includes as many possible injection strings as possible, including SQLis , XSS, XPATH injections, SSIs, etc. Preferably encoded in various formats. Anyone knows where to find these?

有帮助吗?

解决方案

The FuzzDB seems to be the answer http://code.google.com/p/fuzzdb/

许可以下: CC-BY-SA归因
不隶属于 StackOverflow
scroll top