Shibuya.XSS techtalk #7 の資料です。
View Slide
https://host/tags/aaa/......
...content="https://host/path/index">...https://host/path/index?p=1
...content="https://host/path/index;aaa">...https://host/path/index;aaa?p=1
http://php.net/index.phphttp://php.net/index.php/xxx/yyy/zzz
http://shibuyaxss.connpass.com/event/28232/http://shibuyaxss.connpass.com/event/28232/;abc
SCRIPT_URL /test.php/PATHSCRIPT_URI http://localhost/test.php/PATHPATH_INFO /PATHPATH_TRANSLATED \PATH<\b>PHP_SELF /test.php/PATH
GET /path?query HTTP/1.1http://php.net/manual/ja/reserved.variables.server.php
/test.php/PATH?QUERYGET/test.php/%3Cb%3EPATH%3C/b%3E?%3Cb%3EQUERY%3C/b%3E HTTP/1.1QUERY_STRING %3Cb%3EQUERY%3C/b%3EREQUEST_URI /test.php/%3Cb%3EPATH%3C/b%3E?%3Cb%3EQUERY%3C/b%3Ehttp://localhost/test.php/PATH?QUERY
/test.php/%3Cb%3EPATH%3C/b%3E?QUERYGET /test.php/%3Cb%3EPATH%3C/b%3E?QUERYHTTP/1.1QUERY_STRING QUERYREQUEST_URI /test.php/%3Cb%3EPATH%3C/b%3E?QUERYhttp://localhost/test.php/PATH?QUERY
http://localhost/test.php/PATHGET /test.php/PATH HTTP/1.1
/test.php/%3Cb%3EPATH%3C/b%3EGET /test.php/PATH HTTP/1.1REQUEST_URI /test.php/PATHlocation.pathname/test.php/%3Cb%3EPATH%3C/b%3Ehttp://localhost/test.php/PATH
HTTP/1.1 200 OKContent-Type: text/html; charset=UTF-8X-UA-Compatible: IE=9
ifr=document.createElement('');document.body.appendChild(ifr);InvalidCharacterError
<br/>console.log(document.documentMode) /* 9 */<br/>http://blogs.msdn.com/cfs-filesystemfile.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-01-35-07/3073.IE_5F00_chart_5F00_jp.pdf
src="http://shibuya.vulnerabledoma.in/javascript:alert(1)/%2F..%2F..%2Fjizen2#hash">
src="//ajax.googleapis.com/ajax/libs/jquerymobile/1.4.5/jquery.mobile.min.js">