Skip to content

Instantly share code, notes, and snippets.

@drewsmith
Created February 8, 2018 05:02
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save drewsmith/aa70d1fddd814c1e82b987b7fd2834d3 to your computer and use it in GitHub Desktop.
Save drewsmith/aa70d1fddd814c1e82b987b7fd2834d3 to your computer and use it in GitHub Desktop.
XSS regex
var regex = /.*(script\b).*>.*<.*(script\b).*/gi;
var scripts = [
"<script> alert(); </script>",
"<< ScRiPT >alert(\"XSS\");//<</ ScRiPT >",
"<script/src=test.js></script>",
"<script src=test.js></script>",
"<div><script> alert(); </script></div>",
"<script+>alert();</script>",
"<script/script>", //valid
"<scripting></scripting>", // valid
"<script/src=test.js/>" // valid
]
var x = document.getElementById('x');
scripts.forEach(function(script) {
var i = document.createElement('input');
i.value = script;
x.appendChild(i);
x.appendChild(document.createElement('br'));
})
var btn = document.createElement('button');
btn.innerHTML = 'Click Me';
btn.addEventListener('click', function(e) {
checkInputs();
});
x.appendChild(btn);
function checkInputs() {
var inputs = document.getElementsByTagName('input');
if (!inputs) {
inputs = []
}
for(var i = 0; i < inputs.length; i++) {
var input = inputs[i];
if(input) {
var output = input.value.match(regex);
console.log(output)
}
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment