当前位置:网站首页>XSS challenge (6-10) more detailed answers
XSS challenge (6-10) more detailed answers
2022-06-30 14:18:00 【Huaxi GG】
LEVEL 6

After capturing the package of this question, it is found that the keyword has been replaced ,script src on All replaced 
The words here , You can try to bypass the case “><iframe Src=javascript:alert(/xss/)”>
So neat , You can go through ( It did , I didn't cut it off -_-)
LEVEL 7
Conventional thinking , Clostridium input Build after tag script label ">
Find out script Deleted
Try double write bypass ">alert(/xss/)
LEVEL 8


f12 Found entered in url Has been inserted in the following links
So try it directly javascript:alert(/xss/)
Find out javascript Replaced , After many attempts , Find out src script And other fields are replaced
So the use of TAB Tab bypass %09
js You can insert tabs in the links of the code without affecting the operation
payload: javascr%09ipt:alert(/xss/)
LEVEL 9

Compared with the last one , Added http:// Field detection , The only way to get around here is to use comments and add http://
payload: javascript:alert(/xss/)//http://
there r Used html Entity encoding is used to bypass the pair script The escape of , As used before to filter sensitive characters specialchars() Will be <> Such characters are converted into entity codes 
LEVEL 10
Found after testing <> Encoded by entities , There is only one output point , But after many attempts, I still can't pass , So check f12
Found that there was a form Forms , So build payload
123&t_sort=test" type=“text” οnmοuseοut="alert(/xss/)
Pop-up window 
边栏推荐
- Data recovery software easyrecovery15 Download
- go channel && select
- LeetCode_ Stack_ Medium_ 227. basic calculator II (without brackets)
- Zend studio how to import an existing project
- @ResponseBody的作用
- Implementation of forwarding server using IO multiplexing
- ot initialized – call ‘refresh’ before invoking lifecycle methods via the context: Root WebApplicati
- I love network security for new recruitment assessment
- Knowledge dissemination cannot replace professional learning!
- VisualStudio and SQL
猜你喜欢

The first three passes of sqli Labs

Step by step | help you easily submit Google play data security form

MFQE 2.0: A New Approach for Multi-FrameQuality Enhancement on Compressed Video

步骤详解 | 助您轻松提交 Google Play 数据安全表单

This editor will open source soon!

go channel && select

Realize a simple LAN communication (similar to feiqiu)
![[Title brushing] heater](/img/ee/70e122b1b1a406624aa7c6442fcdc1.png)
[Title brushing] heater
![[scientific research data processing] [practice] frequency analysis chart of category variables, distribution chart of numerical variables and normality test (including lognormal)](/img/5a/eaa845f4332f0b8ee8b6409d6a79e8.png)
[scientific research data processing] [practice] frequency analysis chart of category variables, distribution chart of numerical variables and normality test (including lognormal)

QQ 居然被盗了?原因在这......
随机推荐
IM即时通讯应用开发中无法解决的“顽疾”
Step by step | help you easily submit Google play data security form
Mutex lock, read / write lock, spin lock, pessimistic lock, and optimistic lock
【科研数据处理】[基础]类别变量频数分析图表、数值变量分布图表与正态性检验(包含对数正态)
Use PHP to delete the specified text content in the file
[kubernetes series] k8s set mysql8 case insensitive
【刷题篇】爱吃香蕉的珂珂
想請教一下,我在佛山,到哪裏開戶比較好?手機開戶是安全麼?
表格储存中sql查询的时候,查询结果增加主键报错,查询结果超过10w行。需要对主键增加上多元索引吗?
Project management - common English vocabulary I
Comprehensively analyze the basic features and summary of free and paid SSH tools
Optimization of unit test efficiency: why test programs? What are the benefits of testing?
Go language mutex lock
点击table的td单元格出现dialog弹窗,获取值后将值放回td单元格
How to take the first step in digital transformation
Je suis à Foshan, où puis - je ouvrir un compte? L'ouverture d'un compte par téléphone mobile est - elle sécurisée?
半导体动态杂谈
Summary of use of laravel DCAT admin
Observable, seulement fiable: première bombe de salon de la série cloudops d'exploitation et d'entretien automatisés dans le nuage
单元测试效率优化:为什么要对程序进行测试?测试有什么好处?