Using data: XSS testing

Source: Internet
Author: User

Author: CnCxzSec
Blog: http://hi.baidu.com/cncxz

This method is not new, but it is rarely used or desirable.

Data: similar to javascript:. To a large extent, javascript work can be completed.

For example:

During the XSS test, it was found that keywords such as javascript and script were filtered out (currently, XSS-aware administrators generally know how to filter these two keywords ). The following statements are available:

Data: text/html; base64, PHNjcmlwdD5hbGVydCgieHNzIik8L3NjcmlwdD4 =

This statement works the same as javascript: alert ("xss") or <script> alert ("xss") </script>.

Data: The syntax from the above statement can also be seen very clearly, base64 for the encoding method, you can modify any, you can UTF-8 can UTF-7, you only need to modify the encoded content. It is not just a pop-up window. If you want to src to a JS script, you can also.

SuperHei's Summary of data:

1. MIME-type such as text/html can be specified
2. Encoding such as data:; charset = UTF-8, Hello
3. firefox, ie8, and Opera support it.


If you are interested, please refer to the official FIREFOX Website:

Http://www-archive.mozilla.org/quality/networking/testing/datatests.html


Data: It's a good thing ~ OVER!

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.