当前位置:网站首页>A simple reflective XSS operation and idea
A simple reflective XSS operation and idea
2022-06-28 16:18:00 【Full stack programmer webmaster】
Hello everyone , I meet you again , I'm your friend, Quan Jun .
xss It's similar yeah html Code injection , Splicing malicious code to obtain cookie etc.
There are three types , They are reflective 、 Storage and dom type Reflection type is not stored in the database , Have an impact on yourself The storage type is stored in the database , It has an impact on visitors
1. Enter the range and see the input box , Insert js label Enter... In the input box :< script>alert(1)</ script > Click on the search
Statement not executed , Instead, it is searched as text , This is clearly not what we want to see , spot f12 View reasons Then click on the sentence we want to see , Right click edit as html Look at the code
Obviously here Label symbol <> The filtered 2. Figure out how to bypass the filter execution xss You can try to execute with events xss,alert() The input box triggers a pop-up window sentence :alert(1) The statement here also does not execute
Look at the code , There are double quotation marks
3. Closed double quotes sentence :”alert(1)//
Double quotes are filtered
4. Use a symbol instead of double quotes to close Try closing with single quotation marks , Because sometimes ,html For operability, some automatic completion will be carried out sentence :”alert(1)//
Statement executed successfully , Pop up window flag
Publisher : Full stack programmer stack length , Reprint please indicate the source :https://javaforall.cn/132883.html Link to the original text :https://javaforall.cn
边栏推荐
猜你喜欢

抖音实战~我关注的博主列表、关注、取关

Slim gain (sgain) introduction and code implementation -- missing data filling based on generated countermeasure network

10年测试经验,在35岁的生理年龄面前,一文不值

北京有哪些牛逼的中小型公司?

Among US private server setup

No win32/com in vs2013 help document

Coding Devops helps Sinochem information to build a new generation of research efficiency platform and drive the new future of "online Sinochem"

Super automation and the future of network security

IPDK — Overview

among us私服搭建
随机推荐
Navicat 15 for MySQL
零钱兑换(动态规划)
物联网云融合安全指南
昨日元宇宙|Meta “元宇宙”部门一季度亏损29.6亿美元,六福珠宝发行数字藏品
【推荐系统】多任务学习之ESMM模型(更新ing)
AI落地的新范式,就“藏”在下一场软件基础设施的重大升级里
软件测试员的悲哀竟是...自己的技术能力不能满足大厂要求?
QT interface library
【Hot100】4. 寻找两个正序数组的中位数
REDIS00_ Explain redis Conf configuration file
ID卡复制教程(使用T5577卡复制4100卡)
WPF 视频硬解码渲染播放(无空域)(支持4K、8K、高帧率视频)
Visual Studio 2010 compilation qt5.6.3
【高并发基础】MySQL 不同事务隔离级别下的并发隐患及解决方案
北京有哪些牛逼的中小型公司?
如何查询数据库中一个表中的所有数据呢?
Tongziping, partner of Tongchuang Weiye: "what should yuan universe invest in?"
Azure Kinect Microsoft camera unity development summary
Visual Studio 2010 configuring and using qt5.6.3
The future of platform as code is kubernetes extension