big-list-of-naughty-strings icon indicating copy to clipboard operation
big-list-of-naughty-strings copied to clipboard

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Results 103 big-list-of-naughty-strings issues
Sort by recently updated
recently updated
newest added

Maybe add the shell shock bash code injection string: () { :;}; echo vulnerable There might be a lot of more such strings for many different languages/environments.

https://github.com/minimaxir/big-list-of-naughty-strings/blob/8a115584931e0aef2965d8f2b6ab212a08a93a4c/blns.txt#L572 http://ruby-doc.org/core-2.4.0/Kernel.html#method-i-system

I'd like to test that a round-trip for my JSON library does not produce any deviation. I have a pretty printer where I can adjust the indention. The problem I...

I think it may be useful to include a [recommended ZWJ sequence](http://unicode.org/emoji/charts/emoji-zwj-sequences.html), especially one of the longer ones. For example, 👩‍👩‍👧‍👦 is ideally displayed as one 'family' character, but is...

https://en.wikipedia.org/wiki/EICAR_test_file standard string that is interpreted as virus by anti-virus software: X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

Unicode has special rules about lowercasing characters http://www.unicode.org/Public/UNIDATA/SpecialCasing.txt and this can result in a string growing. When doing the reverse the strings don't appear to shrink (Java/Python). You can see...

…Scunthorpe Problem words (Nwankwo Kanu, former soccer player for Arsenal, planet Uranus and Scottish village Twatt)

Added a string which identifies a remote code execution vulnerability when the string is exported for Excel. (Opens the calculator if vulnerable)