Unique scripts which used to bypass specify situations
DOM XSS with Angular expression
Arithmetic operator with JSΒ β> Cause Reflected DOM XSS
Stored DOM XSS bypass the encode bracket
Script for executing CSRF Form for XSS by using token CSRF
Tip for causing XSS with block by WAF (web applications firewall)
- Brute force to find the tag can available
- Try to execute attribute with tag available
- And force the website do the eventΒ β> Execute the XSS. For example
Use own tag
Info
If on situation the server block all of tag can inject into the codeΒ β> we need to create them own likeΒ
<xss>
Payload can help you filter xss via press event by key button to causing the reflect
Add \
splash for bypass filter
Info
If some case study like they add black splashΒ
/
Β after you input that with quote so with causing reflect xss using close tag for</script>
Β for ignore that situation and after that causing payload