xss_callback_arg foo; echo '[]'; } --- request GET /foo --- response_headers_like Content-Type: application/json --- response_body []=== TEST 2: sanity --- config location /foo { default_type 'application/json';
5月24日 | Gitee Talk 模力方舟 AI 应用沙龙合肥站,多个 AI+ 项目实践分享,跨行业 AI 场景落地,报名现已开启~ 扫描微信二维码支付 取消 支付完成 Watch 不关注关注所有动态仅关注版本发行动态关注但不提醒动态 1Star0Fork0 leetsura/xss-nginx-module ...
leetsura/xss-nginx-module 代码Issues0Pull Requests0Wiki统计流水线 服务 Issues / 里程碑 所有已开启 0 已关闭 0 欢迎使用里程碑! 里程碑是一个项目计划管理工具,用于集中管理 Issue 和 Pull Request 进度。 北京奥思研工智能科技有限公司版权所有
=== TEST 3: used (multiple http {} blocks) This test case won't run with nginx 1.9.3+ since duplicate http {} blocks have been prohibited since then. --- SKIP --- config location = /t { default_type application/json;0 comments on commit 97c2139 Please sign in to comment. ...
tags: nginx,xss,status metadata: max-request: 1 max-request: 2 http: - method: GET path: - "{{BaseURL}}/status%3E%3Cscript%3Ealert(31337)%3C%2Fscript%3E" - raw: - | GET /_404_%3E%3Cscript%3Ealert(1337)%3C%2Fscript%3E HTTP/1.1 Host: {{Hostname}} - | GET /status%3E%3Cscri...