• Stars
    star
    46,104
  • Rank 268 (Top 0.01 %)
  • Language
    Python
  • License
    MIT License
  • Created over 9 years ago
  • Updated 8 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Big List of Naughty Strings

The Big List of Naughty Strings is an evolving list of strings which have a high probability of causing issues when used as user-input data. This is intended for use in helping both automated and manual QA testing; useful for whenever your QA engineer walks into a bar.

Why Test Naughty Strings?

Even multi-billion dollar companies with huge amounts of automated testing can't find every bad input. For example, look at what happens when you try to Tweet a zero-width space (U+200B) on Twitter:

Although this is not a malicious error, and typical users aren't Tweeting weird unicode, an "internal server error" for unexpected input is never a positive experience for the user, and may in fact be a symptom of deeper string-validation issues. The Big List of Naughty Strings is intended to help reveal such issues.

Usage

blns.txt consists of newline-delimited strings and comments which are preceded with #. The comments divide the strings into sections for easy manual reading and copy/pasting into input forms. For those who want to access the strings programmatically, a blns.json file is provided containing an array with all the comments stripped out (the scripts folder contains a Python script used to generate the blns.json).

Contributions

Feel free to send a pull request to add more strings, or additional sections. However, please do not send pull requests with very-long strings (255+ characters), as that makes the list much more difficult to view.

Likewise, please do not send pull requests which compromise manual usability of the file. This includes the EICAR test string, which can cause the file to be flagged by antivirus scanners, and files which alter the encoding of blns.txt. Also, do not send a null character (U+0000) string, as it changes the file format on GitHub to binary and renders it unreadable in pull requests. Finally, when adding or removing a string please update all files when you perform a pull request.

Disclaimer

The Big List of Naughty Strings is intended to be used for software you own and manage. Some of the Naughty Strings can indicate security vulnerabilities, and as a result using such strings with third-party software may be a crime. The maintainer is not responsible for any negative actions that result from the use of the list.

Additionally, the Big List of Naughty Strings is not a fully-comprehensive substitute for formal security/penetration testing for your service.

Library / Packages

Various implementations of the Big List of Naughty Strings have made it to various package managers. Those are maintained by outside parties, but can be found here:

Library Link
Node https://www.npmjs.com/package/blns
Node https://www.npmjs.com/package/big-list-of-naughty-strings
.NET https://github.com/SimonCropp/NaughtyStrings
PHP https://github.com/mattsparks/blns-php
C++ https://github.com/eliabieri/blnscpp

Please open a PR to list others.

Maintainer/Creator

Max Woolf (@minimaxir)

Social Media Discussions

License

MIT

More Repositories

1

textgenrnn

Easily train your own text-generating neural network of any size and complexity on any text dataset with a few lines of code.
Python
4,941
star
2

hacker-news-undocumented

Some of the hidden norms about Hacker News not otherwise covered in the Guidelines and the FAQ.
3,616
star
3

simpleaichat

Python package for easily interfacing with chat apps, with robust features and minimal code complexity.
Python
3,463
star
4

gpt-2-simple

Python package to easily retrain OpenAI's GPT-2 text-generating model on new texts
Python
3,402
star
5

facebook-page-post-scraper

Data scraper for Facebook Pages, and also code accompanying the blog post How to Scrape Data From Facebook Page Posts for Statistical Analysis
Python
2,116
star
6

person-blocker

Automatically "block" people in images (like Black Mirror) using a pretrained neural network.
Python
2,022
star
7

automl-gs

Provide an input CSV and a target field to predict, generate a model + code to run it.
Python
1,845
star
8

aitextgen

A robust Python tool for text-based AI training and generation using GPT-2.
Python
1,831
star
9

stylecloud

Python package + CLI to generate stylistic wordclouds, including gradients and icon shapes!
Python
825
star
10

gpt-3-experiments

Test prompts for OpenAI's GPT-3 API and the resulting AI-generated texts.
Python
702
star
11

video-to-gif-osx

A set of utilities that allow the user to easily convert video files to very-high-quality GIFs on OS X.
Shell
395
star
12

copy-syntax-highlight-osx

Copy Syntax Highlight for OS X is an OS X service which copies the selected text to the clipboard, with proper syntax highlighting for the given language.
381
star
13

gpt-2-cloud-run

Text-generation API via GPT-2 for Cloud Run
HTML
313
star
14

reactionrnn

Python module + R package to predict the reactions to a given text using a pretrained recurrent neural network.
Python
299
star
15

gpt-2-keyword-generation

Method to encode text for GPT-2 to generate text based on provided keywords
Python
260
star
16

download-tweets-ai-text-gen

Python script to download public Tweets from a given Twitter account into a format suitable for AI text generation.
Python
220
star
17

tweet-generator

Train a neural network optimized for generating tweets based off of any number of Twitter users.
Python
218
star
18

char-embeddings

A repository containing 300D character embeddings derived from the GloVe 840B/300D dataset, and uses these embeddings to train a deep learning model to generate Magic: The Gathering cards using Keras
Python
214
star
19

magic-the-gifening

A Twitter bot which tweets Magic: the Gathering cards with appropriate GIFs superimposed onto them.
Python
212
star
20

system-dashboard

Minimalist Win/OSX/Linux System Dashboard using Flask and Freeboard
HTML
200
star
21

imgmaker

Create high-quality images programmatically with easily-hackable templates.
Python
175
star
22

ctrl-gce

Set up the CTRL text-generating model on Google Compute Engine with just a few console commands.
Shell
151
star
23

ai-generated-pokemon-rudalle

Python script to preprocess images of all Pokémon to finetune ruDALL-E
Python
138
star
24

imgbeddings

Python package to generate image embeddings with CLIP without PyTorch/TensorFlow
Python
134
star
25

mtg-gpt-2-cloud-run

Code and UI for running a Magic card text generator API via GPT-2
HTML
120
star
26

get-all-hacker-news-submissions-comments

Simple Python scripts to download all Hacker News submissions and comments and store them in a PostgreSQL database.
Python
119
star
27

hacker-news-gpt-2

Dump of generated texts from GPT-2 trained on Hacker News titles
117
star
28

facebook-ad-library-scraper

A Python scraper for the Facebook Ad Library, using the official Facebook Ad Library API.
Python
114
star
29

reddit-bigquery

Code + Jupyter notebook for analyzing and visualizing Reddit Data quickly and easily
R
112
star
30

optillusion-animation

Python code to submit rotated images to the Cloud Vision API + R code for visualizing it
Python
99
star
31

chatgpt_api_test

Demos utilizing the ChatGPT API
Jupyter Notebook
96
star
32

gpt-3-client

A client for OpenAI's GPT-3 API for ad hoc testing of prompt without using the web interface.
Python
90
star
33

stable-diffusion-negative-prompt

Jupyter Notebooks for experimenting with negative prompting with Stable Diffusion 2.0.
Jupyter Notebook
87
star
34

stylistic-word-clouds

Python scripts for creating stylistic word clouds
Python
85
star
35

gpt3-blog-title-optimizer

Python code for building a GPT-3 based technical blog post optimizer.
Jupyter Notebook
83
star
36

amazon-spark

R Code + R Notebook for analyzing millions of Amazon reviews using Apache Spark
HTML
83
star
37

twcloud

Python package + CLI to generate wordclouds of Twitter tweets.
Python
76
star
38

twitter-cloud-run

A (relatively) minimal configuration app to run Twitter bots on a schedule that can scale to unlimited bots.
Python
76
star
39

deep-learning-cpu-gpu-benchmark

Repository to benchmark the performance of Cloud CPUs vs. Cloud GPUs on TensorFlow and Google Compute Engine.
HTML
67
star
40

get-profile-data-of-repo-stargazers

This repository contains a script used to get the GitHub profile information of all the people who've Stared a given GitHub repository
Python
67
star
41

icon-image

Python script to quickly generate a Font Awesome icon imposed on a background for steering AI image generation.
Python
53
star
42

gpt-j-6b-experiments

Test prompts for GPT-J-6B and the resulting AI-generated texts
53
star
43

ml-data-generator

Python script to generate fake datasets optimized for testing machine learning/deep learning workflows
Python
51
star
44

hacker-news-download-all-stories

Download *ALL* the submissions from Hacker News
Python
51
star
45

clickbait-cluster

Code + Jupyter Notebooks for Visualizing Clusters of Clickbait Headlines Using Spark, Word2vec, and Plotly
HTML
47
star
46

keras-cntk-docker

Docker container for keras + cntk intended for nvidia-docker
Python
42
star
47

foursquare-venue-scraper

A Foursquare data scraper that gathers all venues within a specified geographic area.
Python
39
star
48

interactive-facebook-reactions

Jupyter notebook + Code for processing Facebook Reactions data and making Interactive Charts
HTML
38
star
49

youtube-video-scraper

Tools for scraping YouTube video metadata (mostly for training AI on video titles)
Python
38
star
50

nyc-taxi-notebook

R Code + Jupyter notebook for analyzing and visualizing NYC Taxi data
R
31
star
51

sdxl-experiments

Jupyter Notebooks for experimenting with Stable Diffusion XL 1.0
Jupyter Notebook
30
star
52

yelp-review-analysis

Repository containing script on how I processed and charted Yelp data.
R
29
star
53

langchain-problems

Demos of some issues with LangChain.
Jupyter Notebook
29
star
54

subreddit-generator

Train a neural network optimized for generating Reddit subreddit posts
Python
28
star
55

predict-reddit-submission-success

Repository w/ Jupyter + R Notebooks for creating a model to predict the success of Reddit submissions with Keras.
HTML
28
star
56

autotweet-from-googlesheet

A minimal proof-of-concept Python script to tweet human-curated Tweets on a schedule.
Python
27
star
57

tritonize

Convert images to a styled, minimal representation, quickly with NumPy
Python
27
star
58

keras-cntk-benchmark

Code for Benchmarking CNTK performance on Keras vs. TensorFlow
Python
26
star
59

frames-to-gif-osx

An application that allows the user to easily convert frames to very-high-quality GIFs on OS X.
26
star
60

minimaxir.github.io

Blog Posts and Theme for https://minimaxir.com
HTML
25
star
61

ggplot-tutorial

Repository for ggplot2 tutorial
R
24
star
62

legaladvice-gpt2

Dump of generated texts from GPT-2 trained on /r/legaladvice subreddit titles
23
star
63

chatgpt-structured-data

Demos of ChatGPT's function calling/structured data support.
Jupyter Notebook
22
star
64

sf-arrests-when-where

R Code + Jupyter notebook for replicating analysis of when and where arrests in San Francisco occur.
R
22
star
65

pokemon-3d

Code + Visualizations processing and visualizing Pokémon data in 3D
HTML
21
star
66

reddit-gpt-2-cloud-run

Reddit title generator API based on GPT-2
HTML
20
star
67

facebook-keyword-regression-analysis

Regression Analysis for Facebook keywords.
R
20
star
68

chatgpt-tips-analysis

Jupyter Notebooks for testing the impact of tip incentives for ChatGPT
Jupyter Notebook
20
star
69

stylecloud-examples

Examples of stylistic word clouds generated via the stylecloud Python package
Python
19
star
70

stack-overflow-survey

Code + Visualizations for processing 2016 Stack Overflow Survey Data
Jupyter Notebook
19
star
71

get-heart-rate-csv

A small Python script to get the heart rate data generated from an Apple Watch in a CSV form
Python
19
star
72

get-bars-from-foursquare

A quick pair of Python scripts to retrieve all bars within a given area, then retrieve metadata and process it.
Python
19
star
73

subreddit-related

Code and visualizations for related/similar subreddits
Jupyter Notebook
19
star
74

ai-generated-magic-cards

Tools for encoding Magic: The Gathering cards into a form suitable for AI text generation
Python
17
star
75

tensorflow-multiprocess-ray

Proof of concept on how to use TensorFlow for prediction tasks in a multiprocess setting.
Python
17
star
76

pokemon-ai

A text-generating AI to generate Pokémon names.
Python
17
star
77

reddit-comment-length

R code needed to reproduce Relationship between Reddit Comment Score and Comment Length for 1.66 Billion Comments visualization
R
17
star
78

mtg-card-creator-api

Code for running a Magic card image generator API
Python
16
star
79

automl-gs-examples

Examples + Visualizations of datasets modeled using automl-gs
Python
16
star
80

reddit-graph

Jupyter notebook + Code for reproducing Reddit Subreddit graphs
Jupyter Notebook
16
star
81

ncaa-basketball

R Code + R Notebook on how to process and visualize NCAA basketball data.
R
16
star
82

pokemon-embeddings

Jupyter Notebooks and an R Notebook for encoding Pokémon embeddings and creating data visualizations.
Jupyter Notebook
16
star
83

sfba-compensation

Jupyter notebook + Code for scraping AngelList data and making an interactive chart of SFBA salaries/equity
HTML
14
star
84

resetera-gpt-2

Scraper of ResetEra threads and posts to get them into a format suitable for feeding them into GPT-2.
Python
14
star
85

get-data-from-photos-from-instagram-tags

Processes data from images which are tagged with the specified Instagram tag.
Python
13
star
86

hacker-news-comment-analysis

Code used for analysis of Hacker News comments.
R
13
star
87

char-tsne-visualization

Visualizations of character embeddings from derived character vectors.
HTML
13
star
88

imdb-data-analysis

R Code + R Notebook on how to process and visualize the official IMDb datasets.
12
star
89

hn-heatmaps

Code and data necessary to reproduce heatmaps relating HN Submission time to submission score.
R
12
star
90

sf-crimes-covid

Spot checking impact of SF shelter-in-places on crime reporting.
12
star
91

imgur-decline

R Code + R Notebook for analyzing the decline of Imgur on Reddit.
HTML
11
star
92

gpt-2-fanfiction

Experiments with generating GPT-2 fanfiction on specified topics.
11
star
93

notebooks

This GitHub Repository stores my R Notebooks, allowing GitHub Pages to serve the R Notebooks on my website
HTML
11
star
94

all-marvel-comics-characters

Creates a .csv of all Marvel Comics Characters + Statistics via the Marvel API
Python
10
star
95

movie-gender

Data and code for analyzing Movie Lead Gender.
Jupyter Notebook
10
star
96

online-class-charts

Code needed to reproduce data analysis and charts for MIT/Harvard Online Course Data
R
9
star
97

ggplot2-web

R Code + R Notebook on how to make high quality data visualizations on the web with ggplot2.
HTML
9
star
98

reddit-subreddit-keywords

Code + Jupyter notebook for analyzing and visualizing means and medians of keywords in the top Reddit Subreddits.
R
8
star
99

reddit-mean-score

Quick data visualization for Reddit Mean Submission Score by Subreddit
8
star
100

sf-arrests-predict

R Code + R Notebook for predicting arrest types in San Francisco.
HTML
8
star