HN Hall of Fame Weekly email

Naughty Strings: A list of strings likely to cause issues as user-input data

Screenshot of github.com captured 2026-07-20
Page preview · captured 2026-07-20

Resurfaced independently across 7 calendar years, with breakout response in 4 of them.

submissions
12
submitters
12
observed span
2015–2026
peak thread · 146 comments
937 pts
latest 20+ return · 2026-02-21
24 pts

Submission timeline

2007–2026

One slot for every year since HN launched. Height is that year's peak points; orange marks a 100+ point or 50+ comment breakout. Select a bar to open its strongest thread.

First comments on top threads

HN comment order

Creator/Maintainer of the repo here. I apologize for the lack of updates to the BLNS. (since I'm free today and this is on the HN front page, I'll do a cleanup pass). Even though it's a GitHub repository with 12.3k stars, there's not much to say or improve on what is effectively a .txt file based around a good idea (I recently removed mentions of my maintainership of the BLNS from my resume for that reason, despite its crazy popularity).

Big lists of previous comments: https://news.ycombinator.com/item?id=13406119 https://news.ycombinator.com/item?id=10035008

dang·780-point thread·

Most of what I do involves the messy world of text, and I think this is a great resource. I wish the software I depended on tested against it. I can think of a few more cases that I've seen cause havoc: - U+FEFF in the middle of a string (people are used to seeing it at the beginning of a string, because Microsoft, but elsewhere it may be more surprising) - U+0 (it's encoded as the null byte!) -…

rspeer·514-point thread·

Solid list for a quick SQL injection and XSS reference with lots of examples. Even unicode/accents/two-byte characters etc are super useful to check handling on all the way from the front-end to the persistent storage solution (DB, etc). Lost it laughing at "Human Injection" section: > # Strings which may cause human to reinterpret worldview > If you're reading this, you've been in a coma for almost 20 years now. We're trying a new technique. We don't know where this…

The first top-level comment from each of the four biggest threads, in HN’s own order. Excerpts are shortened; open a comment for full context.

Breakout years
4

100+ points or 50+ comments

Total points
2711

reference only — not used in Hall rules or ranking

Total comments
468

reference only — not used in Hall rules or ranking

Every submission

DateTitle as submittedByPointsComments
2015-08-10Show HN: Big List of Naughty Strings for testing user-input dataFirst breakoutminimaxir51479
2017-01-15Naughty Strings: A list of strings likely to cause issues as user-input dataBest threadcaseysoftware937144
2018-08-23Big List of Naughty Stringstosh50
2018-10-08Big List of Naughty Stringsgolanggeek40
2018-11-09The Big List of Naughty StringsLinuxBender60
2018-11-16Big List of Naughty StringsHall inductionpmoriarty780146
2020-05-24The Big List of Naughty Stringspolm2340992
2022-03-05The Big List of Naughty Stringsgraderjs30
2023-06-13The Big List of Naughty Stringsspiffytech40
2023-09-07The Big List of Naughty Stringssys42590222
2026-02-12Big List of Naughty Strings (2021)l1am031
2026-02-21The Big List of Naughty StringsLatest 20+ point returnshirian244