How to use Special Character Dataset Generator
- List the categories you want, one per line (or "all").
- Choose whether to include the very long strings.
- Press Generate and copy the value column into your inputs.
Special Character Dataset Generator features
- Over 170 curated strings in 18 categories: SQL, HTML/XSS, JSON, path, control characters, RTL/bidi, zero-width, homoglyphs, emoji, long, whitespace, numeric, format strings, template injection, shell, LDAP/NoSQL, XML/XXE and Unicode oddities
- A note for every string explaining what it exercises
- Display column with invisible characters shown as \uXXXX
- Optional very long strings up to 65,536 characters
- Category filter and warnings for unknown category names
- JSON, CSV, SQL, XML, JSON Lines or table output
Special Character Dataset Generator example
SQL and RTL cases
Input:
Categories: sql, rtlOutput:
category,value,note
sql,' OR '1'='1,Classic tautology
sql,"'; DROP TABLE users; --",Stacked query
rtl,invoice\u202Efdp.exe,RLO file-name spoof (shows as invoiceexe.pdf)Frequently asked questions about Special Character Dataset Generator
What is a naughty string?
An input that tends to break software: SQL and HTML metacharacters, JSON escapes, path traversal, control characters, bidi overrides, zero-width characters, homoglyphs, emoji sequences, very long strings and more.
How should I use the catalogue?
Copy the value column into form fields, API payloads or file names and check that the application escapes, rejects or stores each one correctly; the note column explains the expected risk.
What does the display column show?
The same string with invisible characters written as \uXXXX so you can see NUL bytes, bidi controls and zero-width characters in the preview.
Can I filter by category?
Yes — list the categories you need (sql, html, json, path, control, rtl, zero-width, homoglyph, emoji, long, whitespace, numeric, format, template, command, ldap, xml, unicode) or write "all".