当前位置:网站首页>XSS challenge (6-10) more detailed answers
XSS challenge (6-10) more detailed answers
2022-06-30 14:18:00 【Huaxi GG】
LEVEL 6

After capturing the package of this question, it is found that the keyword has been replaced ,script src on All replaced 
The words here , You can try to bypass the case “><iframe Src=javascript:alert(/xss/)”>
So neat , You can go through ( It did , I didn't cut it off -_-)
LEVEL 7
Conventional thinking , Clostridium input Build after tag script label ">
Find out script Deleted
Try double write bypass ">alert(/xss/)
LEVEL 8


f12 Found entered in url Has been inserted in the following links
So try it directly javascript:alert(/xss/)
Find out javascript Replaced , After many attempts , Find out src script And other fields are replaced
So the use of TAB Tab bypass %09
js You can insert tabs in the links of the code without affecting the operation
payload: javascr%09ipt:alert(/xss/)
LEVEL 9

Compared with the last one , Added http:// Field detection , The only way to get around here is to use comments and add http://
payload: javascript:alert(/xss/)//http://
there r Used html Entity encoding is used to bypass the pair script The escape of , As used before to filter sensitive characters specialchars() Will be <> Such characters are converted into entity codes 
LEVEL 10
Found after testing <> Encoded by entities , There is only one output point , But after many attempts, I still can't pass , So check f12
Found that there was a form Forms , So build payload
123&t_sort=test" type=“text” οnmοuseοut="alert(/xss/)
Pop-up window 
边栏推荐
- Error on datetime when importing SQL file from MySQL
- notepad正则删除关键词所在行
- When SQL queries are performed in table storage, an error is reported when the primary key is added to the query result, and the query result exceeds 10W rows. Do you want to add multiple indexes to t
- Google Earth engine (GEE) - ghsl: global human settlements layer, built grid 1975-1990-2000-2015 (p2016) data set
- [the path of system analyst] Chapter V software engineering (software process improvement)
- Why does the folder appear open in another program
- "Persistent diseases" that cannot be solved in IM application development
- @ResponseBody的作用
- Google Earth Engine(GEE)——将字符串的转化为数字并且应用于时间搜索( ee.Date.fromYMD)
- PHP common authentication / third-party methods
猜你喜欢

Google Earth Engine(GEE)——将字符串的转化为数字并且应用于时间搜索( ee.Date.fromYMD)
![[redis series] redis learning 16. Redis Dictionary (map) and its core coding structure](/img/5a/5da6180db0b2b96660bcd9b4fa0633.png)
[redis series] redis learning 16. Redis Dictionary (map) and its core coding structure
![[Title brushing] heater](/img/ee/70e122b1b1a406624aa7c6442fcdc1.png)
[Title brushing] heater

【Redis 系列】redis 学习十六,redis 字典(map) 及其核心编码结构

编程实战赛来啦!B站周边、高级会员等好礼送你啦!
![【科研数据处理】[基础]类别变量频数分析图表、数值变量分布图表与正态性检验(包含对数正态)](/img/70/8bf226964118efb324ca4d339df654.png)
【科研数据处理】[基础]类别变量频数分析图表、数值变量分布图表与正态性检验(包含对数正态)

The programming competition is coming! B station surrounding, senior members and other good gifts to you!

remote: Support for password authentication was removed on August 13, 2021. Please use a personal ac

MFQE 2.0: A New Approach for Multi-FrameQuality Enhancement on Compressed Video

MySQL access denied, opened as Administrator
随机推荐
ot initialized – call ‘refresh’ before invoking lifecycle methods via the context: Root WebApplicati
LeetCode_ Stack_ Medium_ 227. basic calculator II (without brackets)
Summary of use of laravel DCAT admin
Go common lock mutex and rwmutex
When SQL queries are performed in table storage, an error is reported when the primary key is added to the query result, and the query result exceeds 10W rows. Do you want to add multiple indexes to t
[scientific research data processing] [practice] frequency analysis chart of category variables, distribution chart of numerical variables and normality test (including lognormal)
Alipay certificate mode payment interface
【 scientific literature measurement 】 mining and visualization of keywords in foreign and Chinese Literature
[Title brushing] coco, who likes bananas
Wechat applet realizes map navigation + door-to-door recycling
ot initialized – call ‘refresh’ before invoking lifecycle methods via the context: Root WebApplicati
Meaning of while (~scanf ("%d%d", & A, & B))
Jetpack Compose 实现完美屏幕适配
深入理解.Net中的线程同步之构造模式(二)内核模式3.内核模式构造物Mutex
点击table的td单元格出现dialog弹窗,获取值后将值放回td单元格
About the problems encountered when using the timer class to stop with a button (why does the QPushButton (for the first time) need to be clicked twice to respond?)
I want to ask how to open an account at China Merchants Securities? Is it safe to open a stock account through the link
Getting started with shell Basics
Attack and defense world web questions
DB2 SQL Error: SQLCODE=-206, SQLSTATE=42703