XSS DVWA learning

XSS DVWA learning
reflective XSS
Low Level
Here Insert Picture Description
Here Insert Picture Description

【】

Here Insert Picture DescriptionHere Insert Picture Description

Medium Level

Here Insert Picture Description
Here Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture Description

Double bypass write:
[<scr

Here Insert Picture DescriptionHere Insert Picture Description
Bypassing the case
[]
Here Insert Picture DescriptionHere Insert Picture Description

High Level
Here Insert Picture DescriptionHere Insert Picture Description

[]
[] When you click a button keyboard at any time trigger.
Here Insert Picture DescriptionHere Insert Picture Description

Impossible Level
Here Insert Picture Description

Storage-type XSS
Low Level

trim (string, charlist)
function removes white space on both sides of a string of characters or other predefined characters, including pre-defined character, \ t, \ n, \ x0B, \ r and space, optional parameters charlist additional support needs to be removed character of.
mysql_real_escape_string (string, connection)
function will special symbol string (\ x00, \ n, \ r, \, ', ", \ x1a) escape.
stripslashes (String)
function to remove the string backslash bar.

a front end column name character limit,
method a: f12- change the frame number limit
Method two: either to capture
three: for playing an input block in the second column

Here Insert Picture DescriptionHere Insert Picture Description

When revisit the page, it will continue to play the box
Medium Level

the strip_tags () function string stripped HTML, XML tags and PHP, but allows the use of labels.
addslashes () function returns a predefined character (single and double quotation marks, the backslash, NULL) before adding backslash character string.
-------------------------------------------Here Insert Picture DescriptionHere Insert Picture Description

Double the bypass
[<scrip]
Here Insert Picture Description
Case bypassed

Here Insert Picture Description
Here Insert Picture Description

High levels
Here Insert Picture Description
Here Insert Picture Description
[ ]
Here Insert Picture Description
Here Insert Picture Description
Here Insert Picture Description
Impossible Level
Here Insert Picture Description
DOM type xss

DOM attribute may trigger type of XSS:
document.referer property
window.name property
location property
innerHTML property
documen.write property

Low Level

Here Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture DescriptionHere Insert Picture Description

Medium Level

Here Insert Picture DescriptionHere Insert Picture Description

Here Insert Picture Description
Here Insert Picture Description

High levels
[/ xss_d /? Default = English #% 3Cscript% 3Ealert (202020)% 3C / script% 3E] Refresh

Here Insert Picture Description

Published 223 original articles · won praise 32 · views 70000 +

Guess you like

Origin blog.csdn.net/qq_41901122/article/details/103811650