xss小试

javascript:alert(document.cookie)
javascript:alert(document.domain)

预防: HTTP cookie设置为readOnly

豆瓣 cookie

OnBeforeRequest

if(oSession.uriContains("douban"))
{
var sCookie="dbcl2=\"133786178:Y28Yw+Uq6/k\"";
oSession.oRequest["Cookie"]=sCookie;
}

 

你可能感兴趣的:(xss小试)