{"id":309,"date":"2017-07-29T21:20:40","date_gmt":"2017-07-29T13:20:40","guid":{"rendered":"http:\/\/120.76.142.240\/?p=309"},"modified":"2017-07-29T21:20:40","modified_gmt":"2017-07-29T13:20:40","slug":"xss%e8%b7%a8%e7%ab%99%e8%84%9a%e6%9c%ac%e6%94%bb%e5%87%bb","status":"publish","type":"post","link":"http:\/\/ssynas.top\/?p=309","title":{"rendered":"XSS\u8de8\u7ad9\u811a\u672c\u653b\u51fb"},"content":{"rendered":"<p><a href=\"http:\/\/120.76.142.240\/wp-content\/uploads\/2017\/07\/XSS\u6316\u6398\u7ed5\u8fc7\u59ff\u52bf.pdf\">XSS\u6316\u6398&amp;\u7ed5\u8fc7\u59ff\u52bf<\/a><\/p>\n<p><strong>\u8fd9\u7bc7\u6587\u7ae0\u80af\u5b9a\u4f1a\u957f\u671f\u66f4\u65b0\u7684\uff0c\u5148\u6316\u4e2a\u5751<\/strong><\/p>\n<p>2017\u5e747\u670829\u65e520:21:05<\/p>\n<p>\u5f88\u591a\u7ecf\u9a8c\u6027\u8d28\u7684\u4e1c\u897f\u5f97\u4e00\u70b9\u4e00\u70b9\u7684\u79ef\u7d2f\uff0c\u4eca\u5929\u5148\u653e\u4e0a\u6765\u6700\u8fd1\u521a\u521a\u603b\u7ed3\u7684<\/p>\n<p>&nbsp;<\/p>\n<p>0x01 XSS\u7b80\u4ecb<br \/>\n\u7528\u6211\u81ea\u5df1\u7684\u8bdd\u8bf4\u5c31\u662f\u6076\u610f\u7528\u6237\u5411\u670d\u52a1\u5668\u63d0\u4ea4\u7684\u6570\u636e\u662f\u4e00\u6bb5\u6076\u610f\u811a\u672c\uff0c\u5e76\u4e14\u88ab\u63d2\u5165\u5230\u6d4f\u89c8\u5668\u4e2d\uff0c\u4ece\u800c\u5728\u7528\u6237\u4f7f\u7528\u6d4f\u89c8\u5668\u65f6\uff0c\u6076\u610f\u811a\u672c\u4f1a\u88ab\u6267\u884c\u3002<\/p>\n<p>\u4e3e\u4e2a\u6700\u7b80\u5355\u7684\u4f8b\u5b50\uff1a<\/p>\n<p>\u8f93\u5165\u7684\u5185\u5bb9\u662f\uff1a<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-312\" src=\"http:\/\/120.76.142.240\/wp-content\/uploads\/2017\/07\/\u672a\u547d\u540d233\u56fe\u7247.png\" alt=\"\" width=\"1082\" height=\"414\" \/><\/p>\n<p>Index.php\u7684\u4ee3\u7801\u662f\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-315\" src=\"http:\/\/120.76.142.240\/wp-content\/uploads\/2017\/07\/2017-07-29-1.png\" alt=\"\" width=\"564\" height=\"105\" \/><\/p>\n<p>\u70b9\u51fbsubmit\u63d0\u4ea4\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-314\" src=\"http:\/\/120.76.142.240\/wp-content\/uploads\/2017\/07\/\u672a\u547d\u540d\u56fe\u7247.png\" alt=\"\" width=\"437\" height=\"148\" \/><\/p>\n<p>JS\u4ee3\u7801\u88ab\u6267\u884c\u4e86\uff0c\u8fd9\u5c31\u662f\u4e00\u4e2a\u6700\u7b80\u5355\u7684\u53cd\u5c04\u6027XSS\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-310\" src=\"http:\/\/120.76.142.240\/wp-content\/uploads\/2017\/07\/111.png\" alt=\"\" width=\"892\" height=\"638\" \/><\/p>\n<p>\u6b64\u65f6\u8f93\u5165\u7684JS\u4ee3\u7801\u88ab\u63d2\u5165\u5230\u7f51\u9875\u4e2d<\/p>\n<p>0x02 XSS\u5206\u7c7b<br \/>\n1\u3001\u53cd\u5c04\u578b\uff1a\u5c31\u662f\u521a\u624d\u90a3\u4e2a\u4f8b\u5b50\u3002\u6d4f\u89c8\u5668\u628a\u5e26\u6709JS\u4ee3\u7801\u7684\u6570\u636e\u4f20\u5230\u670d\u52a1\u5668\u8fdb\u884c\u5904\u7406\u3002\u7ecf\u8fc7\u5904\u7406\u540e\u518d\u8fd4\u56de\u7ed9\u6d4f\u89c8\u5668\u5e76\u6210\u529f\u6267\u884cJS\u4ee3\u7801\u3002<br \/>\n2\u3001\u50a8\u5b58\u578b\uff1a\u5982\u679c\u8fd9\u6bb5XSS\u4ee3\u7801\u88ab\u670d\u52a1\u5668\u4f20\u5230\u6570\u636e\u5e93\u50a8\u5b58\u8d77\u6765\uff0c\u90a3\u4e48\u6bcf\u4e2a\u8bbf\u95ee\u8be5\u9875\u9762\u7684\u7528\u6237\u90fd\u4f1a\u6536\u5230\u5e26\u6709\u6076\u610f\u4ee3\u7801\u7684\u7f51\u9875<br \/>\n3\u3001DOM\u578b\uff0c\u4e0d\u592a\u660e\u767d\uff0c\u5229\u7528JS\u7684DOM\u65b9\u6cd5\u4ea7\u751f\u6f0f\u6d1e\uff0c\u4e0d\u9700\u8981\u4e0e\u670d\u52a1\u7aef\u4ea4\u4e92<\/p>\n<p>(\u2299o\u2299)\u54e6\uff0c\u4e0d\u592a\u660e\u767d\u3002\u8bd5\u7740\u5728\u5e73\u53f0\u4e0a\u627e\u627e\u73a9\u73a9\u5427<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-316\" src=\"http:\/\/120.76.142.240\/wp-content\/uploads\/2017\/07\/2017-07-29-2.png\" alt=\"\" width=\"1153\" height=\"869\" \/><\/p>\n<p>\uff08\u672a\u5b8c\u5f85\u7eed\uff09<\/p>\n<p>\u603b\u7ed3\u4e0b\u7ed5\u8fc7\u59ff\u52bf\uff08\u957f\u671f\u66f4\u65b0\uff09\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-319\" src=\"http:\/\/120.76.142.240\/wp-content\/uploads\/2017\/07\/\u65e0\u6807\u9898.jpg\" alt=\"\" width=\"595\" height=\"842\" \/><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>XSS\u6316\u6398&amp;\u7ed5\u8fc7\u59ff\u52bf \u8fd9\u7bc7\u6587\u7ae0\u80af\u5b9a\u4f1a\u957f\u671f\u66f4\u65b0\u7684\uff0c\u5148\u6316\u4e2a\u5751 &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-309","post","type-post","status-publish","format-standard","hentry","category-3"],"_links":{"self":[{"href":"http:\/\/ssynas.top\/index.php?rest_route=\/wp\/v2\/posts\/309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ssynas.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ssynas.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ssynas.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/ssynas.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=309"}],"version-history":[{"count":0,"href":"http:\/\/ssynas.top\/index.php?rest_route=\/wp\/v2\/posts\/309\/revisions"}],"wp:attachment":[{"href":"http:\/\/ssynas.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ssynas.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=309"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ssynas.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}