@L3m0n师傅 的wp
微信公众号阅读地址:
@LoRexxar师傅的解读
在线挑战地址
- xss1_uploadfiles
- xss2_getallheaders
- xss3_json
- xss4_referer
- xss5_redirect
- xss6_forcedownload
- xss7_textplain
- xss8_tag
- xss9_plaintext
- xss10_mvm
- xss13_request_uri
- xss14_hidden
- xss15_frameBuster
- xss16_phpself
- xss17_passiveElement
- xss18_graduate
- xss19_party
- xss20_theend
- xss21_othersJquery
ex: 题目1:http://t.r00tuserclient.xyz/xianzhi_xss/xss1_uploadfiles/