Skip to content
Kurisu
Go back

XSS-Labs 靶场全关卡通关

靶场地址:http://localhost/xss-labs/
环境:phpStudy Pro (PHP 7.3.4 + Apache 2.4.39)
通关日期:2024-12-01
确认机制:alert() 被覆盖为 confirm("完成的不错!"),自动跳转下一关


Level 1 — 无过滤直接注入


Level 2 — 闭合双引号属性


Level 3 — htmlspecialchars 不转义单引号


Level 4 — 去 <> 后用事件属性


Level 5 — on 和 script 被替换


Level 6 — 大小写绕过


Level 7 — 双写绕过


Level 8 — HTML 实体编码绕过


Level 9 — 绕过 http:// 检查


Level 10 — hidden input 改 type


Level 11 — HTTP Referer 注入


Level 12 — HTTP User-Agent 注入



Level 14 — EXIF XSS ⚠️(外部站点)


Level 15 — AngularJS ng-include 注入


Level 16 — 换行符绕过空格过滤


Level 17 — embed 无引号 src(xsf01.swf)


Level 18 — embed 无引号 src(xsf02.swf)


Level 19 — embed 双引号 src(xsf03.swf)⚠️ Flash


Level 20 — embed 双引号 src(xsf04.swf)⚠️ Flash


防御总结

防御方法效果
htmlspecialchars($str, ENT_QUOTES)转义 " ' < > & — 覆盖大部分场景
上下文感知输出JS 里用 json_encode(),URL 里用 urlencode()
CSP(Content-Security-Policy)禁用 inline script,从源头阻断
HttpOnly Cookie防 Cookie 窃取(减轻但不能防 XSS)
输入验证 + 白名单对特定字段(如 URL、数字)做格式校验

绕过技巧速查

场景技巧
过滤 <script><img src=x onerror=...> <svg onload=...> <iframe src=javascript:...>
过滤 on*javascript: 伪协议
过滤 < >事件属性注入(autofocus onfocus=)
过滤关键字大小写混用、双写、HTML 实体编码 &#115;
过滤空格换行 %0a 回车 %0d 换页 %0c 斜杠 /
过滤双引号单引号属性绕过 htmlspecialchars(ENT_COMPAT)
AngularJSng-include 远程包含
隐藏 input改 type="text" + autofocus
HTTP 头注入Referer、User-Agent、Cookie

Share this post:

Previous Post
文件包含漏洞(LFI/RFI)
Next Post
命令执行与代码执行