Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
1 json标准中都是使用双引号的,http://www.json.org/json-zh.html 。最近使用django和您的xss probe写一个xss平台,发现python的json.loads()等函数在处理单引号的json的时候会报错。规范一下比较好。
2 去掉了window.onload 这样在部分xss利用场景中可以插入xss代码后就立即起作用。比如我上面自己写的平台,构造一个dom xss,提供一个文本框,点击后插入到html中,如果使用window.onload,就不会起作用。
我说的有什么问题,还希望大神提出来~~