Anemone95 / anemone95.github.io

http://anemone.top/
2 stars 1 forks source link

XSS类型、利用和防御 | Anemone's Blog #46

Open Anemone95 opened 5 years ago

Anemone95 commented 5 years ago

http://anemone.top/xss-XSS%E7%B1%BB%E5%9E%8B%E3%80%81%E5%88%A9%E7%94%A8%E5%92%8C%E9%98%B2%E5%BE%A1/

XSS类型反射型用户访问带有XSS代码的请求,服务器立即将代码发送至浏览器,浏览器执行恶意代码: 123// http://127.0.0.1/reflect.php?xss=<script>alert(1);</script>setcookie('session', 'qwerty');echo $_GET['xss']; 存储型XSS代码被保存(至数据库),待页面被访