当前位置:网站首页>XSS challenge (6-10) more detailed answers
XSS challenge (6-10) more detailed answers
2022-06-30 14:18:00 【Huaxi GG】
LEVEL 6

After capturing the package of this question, it is found that the keyword has been replaced ,script src on All replaced 
The words here , You can try to bypass the case “><iframe Src=javascript:alert(/xss/)”>
So neat , You can go through ( It did , I didn't cut it off -_-)
LEVEL 7
Conventional thinking , Clostridium input Build after tag script label ">
Find out script Deleted
Try double write bypass ">alert(/xss/)
LEVEL 8


f12 Found entered in url Has been inserted in the following links
So try it directly javascript:alert(/xss/)
Find out javascript Replaced , After many attempts , Find out src script And other fields are replaced
So the use of TAB Tab bypass %09
js You can insert tabs in the links of the code without affecting the operation
payload: javascr%09ipt:alert(/xss/)
LEVEL 9

Compared with the last one , Added http:// Field detection , The only way to get around here is to use comments and add http://
payload: javascript:alert(/xss/)//http://
there r Used html Entity encoding is used to bypass the pair script The escape of , As used before to filter sensitive characters specialchars() Will be <> Such characters are converted into entity codes 
LEVEL 10
Found after testing <> Encoded by entities , There is only one output point , But after many attempts, I still can't pass , So check f12
Found that there was a form Forms , So build payload
123&t_sort=test" type=“text” οnmοuseοut="alert(/xss/)
Pop-up window 
边栏推荐
- This article explains the concepts of typed array, arraybuffer, typedarray, DataView, etc
- Deep understanding Net (2) kernel mode 3 Kernel mode construct mutex
- Details of gets, fgetc, fgets, Getc, getchar, putc, fputc, putchar, puts, fputs functions
- 半导体动态杂谈
- 想請教一下,我在佛山,到哪裏開戶比較好?手機開戶是安全麼?
- Jetpack compose for perfect screen fit
- 表格储存中sql查询的时候,查询结果增加主键报错,查询结果超过10w行。需要对主键增加上多元索引吗?
- Project management - common English vocabulary I
- [observation] as the intelligent industry accelerates, why should AI computing power take the lead?
- Realize a simple LAN communication (similar to feiqiu)
猜你喜欢

Geoffreyhinton: my 50 years of in-depth study and Research on mental skills

Embedded development: five C features that may no longer be prohibited

Wuenda 2022 machine learning special course evaluation is coming!

步骤详解 | 助您轻松提交 Google Play 数据安全表单

MFQE 2.0: A New Approach for Multi-FrameQuality Enhancement on Compressed Video

The programming competition is coming! B station surrounding, senior members and other good gifts to you!

Google Earth Engine(GEE)——将字符串的转化为数字并且应用于时间搜索( ee.Date.fromYMD)

VisualStudio and SQL

Pytorch查看模型参数量和计算量

Detailed explanation of the first three passes of upload Labs
随机推荐
Prometheus 2.29.0 new features
go time. after
用Unity实现Flat Shading
Configuration of headquarters dual computer hot standby and branch infrastructure for firewall Foundation
“即服务”,企业数字化转型的必然选择
【Kubernetes系列】K8s设置MySQL8大小写不敏感
【观察】智能产业加速,为何AI算力要先行?
Service online governance
编程实战赛来啦!B站周边、高级会员等好礼送你啦!
Step by step | help you easily submit Google play data security form
QQ 居然被盗了?原因在这......
Numpy creates an empty array data = np empty(shape=[1, 64,64,3])
MFQE 2.0: A New Approach for Multi-FrameQuality Enhancement on Compressed Video
Chapter 13 signal (III) - example demonstration
Dart 扩展特性
Realize a simple LAN communication (similar to feiqiu)
Summary of use of laravel DCAT admin
Detailed explanation of the first three passes of upload Labs
Google Earth Engine(GEE)——将字符串的转化为数字并且应用于时间搜索( ee.Date.fromYMD)
The first three passes of sqli Labs