Загрузка видео...
Не удалось загрузить видео
Do not use the script tag when testing for XSS
41,260 просмотров • 2 лет назад •via X (Twitter)
Комментарии: 7

Better advice would be to not use exploit payloads for XSS detection in the first place, IMO. I personally like @cinzinga_'s goto payload of <s>asdf since it's small, easily searchable, and the strike-through text is more noticeable.

In case your sink is innerHTML, but you still need to load <script> use this: <iframe srcdoc="<script src=''></script>"></iframe> Last time I saw this trick in @bbuerhaus article

@bbuerhaus Yes, I've used for actually exploiting the innerHTML XSS but not for detecting it.

Learnt this the hard way on hacker101 CTF

That brings me to the question that has been bugging me for a while now (Noob here) When you payload is being encoded, is that the end of the road? Cause usually i get stuck at this point

yes, encoding is a proper defence against xss and there's nothing you can do

Event handlers use need the same ''unsafe-inline' directive as inline scripts so what you say doesn't make sense.
Похожие видео
Sensitive content
do not turn up the volume do not use headphones 😭
sim
163,942 просмотров • 9 месяцев назад
Sensitive content
#BiologicallyDefeated use the same script as #DickPoliceUnit & #BlackMenDefenseForce “Good for me but not for you & we’ll pretend like it’s not happening until caught, then there are valid reasons why” Did they plan this together?!
Anos Voldigoad V
168,383 просмотров • 1 месяц назад

![Myles Lewis-Skelly: "We just want to embrace 'title favourites' (tag), use it for us, not against us!" [TNT]](https://image.24vids.com/tw-2016645675488838084/media/G_yOydBWAAA6YPv.jpg)
