重新定义“不可能”:无任意 JavaScript 的 XSS
portswigger.net | 研究 | #web-security | #xss | #side-channel | #exfiltration | #tagged-templates | #charset-restriction
摘要
Luan Herrera 破解「不可能」XSS 挑战的客座文章:注入点位于单引号字符串内且字符集受限,无法执行任意 JavaScript,最终借助侧信道技术完成 Cookie 窃取与外带。
- 发布时间
- 收录时间
Skip to content