haozi / xss-demo

👮🏻‍♂️ XSS attack playground,there are answers in issues. XSS 攻防靶场,issues 有答案
https://xss.haozi.me
295 stars 58 forks source link

0x0a 怎么做 #4

Closed xundididi closed 6 years ago

xundididi commented 6 years ago

方法只能是建一个符合域名正则的二级站点么?求指教

haozi commented 6 years ago

之前还可以构建形如这样的 url,不过最新的 chrome 已经 block 这个特性了

https://www.segmentfault.com@xss.haozi.me/j.js