Author: CnCxzSec
Blog: http://hi.baidu.com/cncxz
This method is not new, but it is rarely used or desirable.
Data: similar to javascript:. To a large extent, javascript work can be completed.
For example:
During the XSS test, it was found that keywords such as javascript and script were filtered out (currently, XSS-aware administrators generally know how to filter these two keywords ). The following statements are available:
Data: text/html; base64, PHNjcmlwdD5hbGVydCgieHNzIik8L3NjcmlwdD4 =
This statement works the same as javascript: alert ("xss") or <script> alert ("xss") </script>.
Data: The syntax from the above statement can also be seen very clearly, base64 for the encoding method, you can modify any, you can UTF-8 can UTF-7, you only need to modify the encoded content. It is not just a pop-up window. If you want to src to a JS script, you can also.
SuperHei's Summary of data:
1. MIME-type such as text/html can be specified
2. Encoding such as data:; charset = UTF-8, Hello
3. firefox, ie8, and Opera support it.
If you are interested, please refer to the official FIREFOX Website:
Http://www-archive.mozilla.org/quality/networking/testing/datatests.html
Data: It's a good thing ~ OVER!