hacktricks/pentesting-web/xs-search/javascript-execution-xs-leak.md

3.7 KiB
Raw Blame History

JavaScript执行XS泄漏

从零开始学习AWS黑客技术成为专家 htARTEHackTricks AWS红队专家
```javascript // Code that will try ${guess} as flag (need rest of the server code app.get('/guessing', function(req, res) { let guess = req.query.guess let page = `<html> <head> </head>

hello2

</html>` res.send(page) }); ``` 主页会生成 iframes 到之前的 `/guessing` 页面,以测试每种可能性。 ```html <html> <head>

</head>

hello

</html> ```
从零开始学习AWS黑客技术成为专家 htARTEHackTricks AWS Red Team Expert