haozi / xss-demo

👮🏻‍♂️ XSS attack playground,there are answers in issues. XSS 攻防靶场,issues 有答案
https://xss.haozi.me
296 stars 59 forks source link

0x0B加载js不成功 #11

Open caijynb opened 4 years ago

caijynb commented 4 years ago

payload为<script src="https://xss.haozi.me/j.js"></script>时不成功 但是将src改成https://www.segmentfault.com.haozi.me/j.js 却成功了

可这两个地址本质是同一个,想不明白为什么第一个payload无法加载js

caijynb commented 4 years ago

PS:发现有用第一个payload成功弹框的小伙伴 PPS:环境是Chrome 80,但是关系应该不大。同样问题也出现在我的旧版本firefox上

haozi commented 2 years ago

应该可以了