正在加载视频...
视频加载失败
Do not use the script tag when testing for XSS
7 条评论

Better advice would be to not use exploit payloads for XSS detection in the first place, IMO. I personally like @cinzinga_'s goto payload of <s>asdf since it's small, easily searchable, and the strike-through text is more noticeable.

In case your sink is innerHTML, but you still need to load <script> use this: <iframe srcdoc="<script src=''></script>"></iframe> Last time I saw this trick in @bbuerhaus article

@bbuerhaus Yes, I've used for actually exploiting the innerHTML XSS but not for detecting it.

Learnt this the hard way on hacker101 CTF

That brings me to the question that has been bugging me for a while now (Noob here) When you payload is being encoded, is that the end of the road? Cause usually i get stuck at this point

yes, encoding is a proper defence against xss and there's nothing you can do

Event handlers use need the same ''unsafe-inline' directive as inline scripts so what you say doesn't make sense.
相关视频
Sensitive content
#BiologicallyDefeated use the same script as #DickPoliceUnit & #BlackMenDefenseForce “Good for me but not for you & we’ll pretend like it’s not happening until caught, then there are valid reasons why” Did they plan this together?!
Anos Voldigoad V
167,329 次观看 • 26 天前


![Myles Lewis-Skelly: "We just want to embrace 'title favourites' (tag), use it for us, not against us!" [TNT]](https://image.24vids.com/tw-2016645675488838084/media/G_yOydBWAAA6YPv.jpg)