XSS (Cross Site Scripting) cheat sheet
ESP: For filter Evasion
By rsnake
Note from the author: XSS is cross site scripting. if you don't know how XSS (Cross Site Scripting) works, this page probably won't help you. this page is for people who already understand the basics of XSS attacks but want a deep understanding of the nuances regarding filter evasion. this page will also not show you how to mitigate XSS vectors or how to write the actual cookie/credential stealing/replay/session riding portion of the attack. it will simply show the underlying methodology and you can infer the rest. also, please note my XSS page has been replicated by the OWASP 2.0 guide in the appendix section with my permission. however, because this is a living document I suggest you continue to use this Site to stay up to date.
Also, please note that most of these cross site scripting vectors have been tested in the browsers listed at the bottom of the page, however, if you have specific concerns about outdated or obscure versions Please download them from evolt. please see the XML format of the XSS cheat sheet if you intend to use cal9000 or other automatic tools. if you have an RSS reader feel free to subscribe to the Web Application Security RSS feed below, or join the Forum:
Browser support reference table:
Ie7.0 |
|
Vector works in Internet Explorer 7.0. Most recently tested with Internet Explorer 7.0.5700.6 RC1, Windows XP Professional SP2. |
|
Ie6.0 |
|
Vector works in Internet Explorer. Most recently tested with Internet Explorer 6.0.28.1.1106co, SP2 on Windows 2000. |
|
NS8.1-IE |
|
Vector works in Netscape 8.1 + in IE rendering engine mode. most recently tested with Netscape 8.1 on Windows XP Professional. this used to be called trusted mode, but Netscape has changed it's security model away from the trusted/untrusted model and has opted towards Gecko as a default and IE as an option. |
|
NS8.1-G |
|
Vector works in Netscape 8.1 + in the gecko rendering engine mode. Most recently tested with Netscape 8.1 on Windows XP Professional |
|
Ff2.0 |
|
Vector works in Mozilla's gecko rendering engine, used by Firefox. Most recently tested with Firefox 2.0.0.2 on Windows XP Professional. |
|
O9.02 |
|
Vector works in opera. Most recently tested with opera 9.02, build 8586 on Windows XP Professional |
|
Ns4 |
|
Vector works in older versions of Netscape 4.0-untested. |
|
Note: If a vector is not marked it either does not work or it is untested.
Http://ha.ckers.org/xss.html