当前位置:网站首页>XX attack - reflective XSS attack hijacking user browser
XX attack - reflective XSS attack hijacking user browser
2022-07-01 08:08:00 【Cwillchris】
Let's build a reflective XSS The attack jumps to the vulnerable page . In fact, it can also be in DVWA Attack directly in , But we constructed a relatively complex environment for demonstration purposes .
<script>
window.onload = function() {
var link=document.getElementsByTagName("a");
for(j = 0; j < link.length; j++) {
link[j].href="http://www.baidu.com";}
}
</script>
JavaScript The code analysis window.onload When the web page is loaded , perform function Anonymous functions
The functionality :document.getElementsByTagName Gets all of the a label , Store in link Array , Use for The cycle will link Replace all elements in the array with malicious URLs .
open chrome browser , We're in reflex XSS Test the effect
Sign in http://192.168.98.66/DVWA-master/login.php user name : admin password :password , Change it to low Level
边栏推荐
- 力扣每日一题-第32天-1822.数组元素积的符号
- String coordinates of number to excel
- Set up file server Minio for quick use
- 【批处理DOS-CMD-汇总】扩展变量-延迟变量cmd /v:on、cmd /v:off、setlocal enabledelayedexpansion、DisableDelayedExpansion
- LM08丨网格系列之网格反转(精)
- 038 network security JS
- 数字转excel的字符串坐标
- 力扣每日一题-第31天-202.快乐数
- Five combination boxing, solving six difficult problems on campus and escorting the construction of educational informatization
- The difference between interceptors and filters
猜你喜欢
![[getting started] enter the integer array and sorting ID, and sort its elements in ascending or descending order](/img/87/07783593dbabcf29700fa207ecda08.png)
[getting started] enter the integer array and sorting ID, and sort its elements in ascending or descending order

Access报表实现小计功能

【入门】输入n个整数,输出其中最小的k个

源代码加密的意义和措施

PWN attack and defense world int_ overflow

How relational databases work
![[getting started] intercepting strings](/img/16/363baa4982408f55493057200bcba5.png)
[getting started] intercepting strings

使用beef劫持用户浏览器

How to make the two financial transactions faster

P4 安装bmv2 详细教程
随机推荐
Analysis of slice capacity expansion mechanism
OJ input and output exercise
Li Kou daily question - day 31 -1790 Can a string exchange be performed only once to make two strings equal
力扣每日一题-第32天-1822.数组元素积的符号
【力扣10天SQL入门】Day10 控制流
量化交易之读书篇 - 《征服市场的人》读书笔记
Aardio - 阴影渐变文字
软键盘高度报错
golang中的正则表达式使用注意事项与技巧
[untitled]
Erreur de hauteur du clavier souple
How to prevent the other party from saying that he has no money after winning the lawsuit?
一套十万级TPS的IM综合消息系统的架构实践与思考
力扣每日一题-第31天-1502.判断能否形成等差数列
Access报表实现小计功能
Introduction to kubernetes resource objects and common commands (II)
[getting started] extract non repeating integers
window c盘满了
Sqlalchemy creating MySQL_ Table
[kv260] generate chip temperature curve with xadc