黑客大神熬夜整理的xss各种骚操作( 四 )


基本:
基本

  • 假=>![]
  • 正确=> !! []
  • 未定义=> [] [[]]
  • NaN => + [![]]
  • 0 => + []
  • 1 => +!+ []
  • 2 =>!+ [] +!+ []
  • 10 => [+!+ []] + [+ []]
  • 数组=> []
  • 数字=> + []
  • 字符串=> [] + []
  • 布尔值=>![]
  • 功能=> [] [“过滤器”]
  • eval => [] [“ filter”] [“ constructor”](CODE)()
  • window => [] [“ filter”] [“ constructor”](“ return this”)()
最后推荐一个GitHub上的xss payload的速查表共计100+条xss突破测试小技巧
以下文章来源于未知数Y  , 作者未知数Y
https://github.com/heroanswer/XSS_Cheat_Sheet_2020_Edition




推荐阅读