
Laboratoires de cross-site scripting pour les passionnés de sécurité des applications web
Laboratoires de Cross-site scripting pour les passionnés de sécurité des applications web
~ Chall 1 | URL ~ Chall 2 | Formulaire ~ Chall 3 | User-Agent ~ Chall 4 | Referrer ~ Chall 5 | Cookie ~ Chall 6 | LocalStorage ~ Chall 7 | Page de connexion ~ Chall 8 | Téléchargement de fichier ~ Chall 9 | Encodage Base64 ~ Chall 10 | Supprime Alert ~ Chall 11 | Supprime Script ~ Chall 12 | Preg_replace ~ Chall 13 | Entités HTML ~ Chall 14 | Filtre Regex #1 ~ Chall 15 | Filtre Regex #2 ~ Chall 16 | Filtre Regex #3 ~ Chall 17 | Entités HTML + Encodage URL ~ Chall 18 | Entités HTML #2 (Caractère spécial) ~ Chall 19 | Entités HTML #3 (Valeur d'entrée) ~ Chall 20 | Entités HTML #4 (Valeur d'entrée + Capitalisation)


Pour exécuter cette image, vous devez avoir docker installé. Il suffit d'exécuter la commande :
docker run --name web-ctf -d -it -p 80:80 hightechsec/xsslabs
git clone https://github.com/tegal1337/0l4bs)docker build -t "xsslabs" . et attendez que ce soit terminédocker run --name web-ctf -d -it -p 80:80 xsslabs0l4bs XSS Labs (https://tegalsec.org/0l4bs-cross-site-scripting-labs-for-web-application-security-enthusiasts/)
跨站脚本攻击实验室:0l4bs (https://zhuanlan.zhihu.com/p/108023848)
0l4bs XSS实验 (https://icssec.club/2020/02/25/0l4bs-XSS/)
Kitploit (https://www.kitploit.com/2020/02/0l4bs-cross-site-scripting-labs-for-web.html?m=0)