
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Guge&#39;sBlog</title>
      <link>https://gugesay.com/blog</link>
      <description>骨哥说事公众号首发地</description>
      <language>zh-CN</language>
      <managingEditor>undefined (Guge)</managingEditor>
      <webMaster>undefined (Guge)</webMaster>
      <lastBuildDate>Sat, 07 Oct 2023 01:38:14 GMT</lastBuildDate>
      <atom:link href="https://gugesay.com/tags/xss/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://gugesay.com/blog/2023 Microsoft Office XSS</guid>
    <title>2023 Microsoft Office XSS</title>
    <link>https://gugesay.com/blog/2023 Microsoft Office XSS</link>
    undefined
    <pubDate>Sat, 07 Oct 2023 01:38:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>MSRC</category><category>Office</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/burpsuite-intruder-自动化测试反射型-xss</guid>
    <title>BurpSuite Intruder 自动化测试反射型 XSS</title>
    <link>https://gugesay.com/blog/burpsuite-intruder-自动化测试反射型-xss</link>
    undefined
    <pubDate>Sat, 18 Jun 2022 07:36:31 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>burpsuite</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/chrome-新的xss攻击向量：cve-2023-5480</guid>
    <title>Chrome 最新XSS攻击向量：CVE-2023-5480</title>
    <link>https://gugesay.com/blog/chrome-新的xss攻击向量：cve-2023-5480</link>
    undefined
    <pubDate>Tue, 30 Jan 2024 01:51:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Chrome</category><category>CVE</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/hackerone上top5的开放重定向漏洞</guid>
    <title>hackerone上TOP5的开放重定向漏洞</title>
    <link>https://gugesay.com/blog/hackerone上top5的开放重定向漏洞</link>
    undefined
    <pubDate>Fri, 16 Aug 2024 06:50:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>XSS</category><category>开放重定向</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/swagger-ui-从xss到账户接管</guid>
    <title>Swagger-UI 从XSS到账户接管</title>
    <link>https://gugesay.com/blog/swagger-ui-从xss到账户接管</link>
    undefined
    <pubDate>Tue, 24 May 2022 07:27:47 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>SwaggerUI</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/xss-waf绕过的一些基本思考</guid>
    <title>XSS WAF绕过的一些基本思考</title>
    <link>https://gugesay.com/blog/xss-waf绕过的一些基本思考</link>
    undefined
    <pubDate>Fri, 14 Jun 2024 11:55:58 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/xss！一次对抗akamai-waf的经历</guid>
    <title>XSS！一次对抗Akamai WAF的经历</title>
    <link>https://gugesay.com/blog/xss！一次对抗akamai-waf的经历</link>
    undefined
    <pubDate>Mon, 30 Oct 2023 03:27:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>akamai</category><category>bugbounty</category><category>bypass</category><category>XSS</category><category>未分类</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【500】将dom-xss升级为存储型xss</guid>
    <title>【$500】如何将DOM XSS升级为存储型XSS</title>
    <link>https://gugesay.com/blog/【500】将dom-xss升级为存储型xss</link>
    undefined
    <pubDate>Mon, 25 Dec 2023 08:20:26 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【cve-2025-4123】：grafana-ssrf-和帐户接管利用</guid>
    <title>【CVE-2025–4123】：Grafana SSRF 和帐户接管利用</title>
    <link>https://gugesay.com/blog/【cve-2025-4123】：grafana-ssrf-和帐户接管利用</link>
    undefined
    <pubDate>Fri, 23 May 2025 03:16:56 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>CVE-2025–4123</category><category>Grafana</category><category>ssrf</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【文末有吐槽】如何将一个无害-xss-提升为现实中的</guid>
    <title>【文末有吐槽】如何将一个无害 XSS 提升为现实中的钓鱼Payload</title>
    <link>https://gugesay.com/blog/【文末有吐槽】如何将一个无害-xss-提升为现实中的</link>
    undefined
    <pubDate>Tue, 30 Dec 2025 02:47:19 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category><category>钓鱼</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/【白帽故事】8000赏金奖励：opera浏览器从xss-到-rce</guid>
    <title>【白帽故事】$8000赏金奖励：Opera浏览器从XSS 到 RCE</title>
    <link>https://gugesay.com/blog/【白帽故事】8000赏金奖励：opera浏览器从xss-到-rce</link>
    undefined
    <pubDate>Tue, 18 Jan 2022 08:03:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>Opera</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一则绕过-cloudflare-waf-实现-xss-的案例</guid>
    <title>一则绕过 Cloudflare WAF 实现 XSS 的案例</title>
    <link>https://gugesay.com/blog/一则绕过-cloudflare-waf-实现-xss-的案例</link>
    undefined
    <pubDate>Tue, 15 Jul 2025 04:04:15 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一处价值-2500-的-dom-xss-漏洞</guid>
    <title>一处价值 $2500 的 DOM XSS 漏洞</title>
    <link>https://gugesay.com/blog/一处价值-2500-的-dom-xss-漏洞</link>
    undefined
    <pubDate>Thu, 29 May 2025 07:30:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/一种新奇另类的文件上传利用</guid>
    <title>Outlook Web 上一种新奇另类的文件上传利用</title>
    <link>https://gugesay.com/blog/一种新奇另类的文件上传利用</link>
    undefined
    <pubDate>Mon, 29 Sep 2025 02:08:28 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>outlook</category><category>XSS</category><category>文件上传</category><category>白帽故事</category><category>钓鱼</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/仅用google-dork快速发现2枚微软xss</guid>
    <title>仅用Google Dork快速发现2枚微软XSS</title>
    <link>https://gugesay.com/blog/仅用google-dork快速发现2枚微软xss</link>
    undefined
    <pubDate>Fri, 11 Aug 2023 11:29:50 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>google dork</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从-self-xss-到-rce</guid>
    <title>从 Self XSS 到 RCE</title>
    <link>https://gugesay.com/blog/从-self-xss-到-rce</link>
    undefined
    <pubDate>Fri, 11 Apr 2025 01:47:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>rce</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从adobe的vip赏金计划中获得近50000美元奖励的故事</guid>
    <title>从Adobe的VIP赏金计划中获得近50,000美元奖励的故事</title>
    <link>https://gugesay.com/blog/从adobe的vip赏金计划中获得近50000美元奖励的故事</link>
    undefined
    <pubDate>Tue, 02 Jan 2024 09:52:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/从self-xss-到账户接管</guid>
    <title>从Self XSS 到账户接管</title>
    <link>https://gugesay.com/blog/从self-xss-到账户接管</link>
    undefined
    <pubDate>Fri, 22 Dec 2023 06:54:44 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用-google-脚本资源绕过-portswigger上的-csp</guid>
    <title>使用 Google 脚本资源绕过 PortSwigger上的 CSP</title>
    <link>https://gugesay.com/blog/使用-google-脚本资源绕过-portswigger上的-csp</link>
    undefined
    <pubDate>Tue, 27 Feb 2024 07:46:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bypass</category><category>csp</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/使用工具快速发现-ssrf、lfi、xss</guid>
    <title>使用工具快速发现 SSRF、LFI、XSS</title>
    <link>https://gugesay.com/blog/使用工具快速发现-ssrf、lfi、xss</link>
    undefined
    <pubDate>Tue, 29 Aug 2023 03:15:33 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>LFI</category><category>ssrf</category><category>XSS</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/凭借一手apple-存储xss赚取5000美元的故事</guid>
    <title>凭借一手Apple 存储XSS赚取5000美元的故事</title>
    <link>https://gugesay.com/blog/凭借一手apple-存储xss赚取5000美元的故事</link>
    undefined
    <pubDate>Thu, 18 Apr 2024 16:00:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Apple</category><category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/利用param-miner挖掘基于缓存中毒的xss漏洞</guid>
    <title>利用Param Miner挖掘基于缓存中毒的XSS漏洞</title>
    <link>https://gugesay.com/blog/利用param-miner挖掘基于缓存中毒的xss漏洞</link>
    undefined
    <pubDate>Fri, 10 Feb 2023 02:46:30 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>工具</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/化腐朽为神奇：将-self-xss-升级为真正可利用的-xss-漏洞</guid>
    <title>化腐朽为神奇：将 Self-XSS 升级为真正可利用的 XSS 漏洞</title>
    <link>https://gugesay.com/blog/化腐朽为神奇：将-self-xss-升级为真正可利用的-xss-漏洞</link>
    undefined
    <pubDate>Mon, 21 Jul 2025 07:06:18 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/参数污染的艺术：用javascript注入绕过waf</guid>
    <title>机器“聪明”与人“狡黠”：黑客机器人如何用参数污染“突破”顶级WAF</title>
    <link>https://gugesay.com/blog/参数污染的艺术：用javascript注入绕过waf</link>
    undefined
    <pubDate>Mon, 08 Dec 2025 06:45:13 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>JS注入</category><category>WAF</category><category>XSS</category><category>参数污染</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/另一处xss！荣登微软msrc-2022-q3排行榜</guid>
    <title>另一处XSS！荣登微软MSRC 2022 Q3排行榜</title>
    <link>https://gugesay.com/blog/另一处xss！荣登微软msrc-2022-q3排行榜</link>
    undefined
    <pubDate>Wed, 15 Feb 2023 16:00:07 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>微软</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在chatgpt中挖掘xss漏洞实现任意账户接管</guid>
    <title>在ChatGPT中挖掘XSS漏洞实现任意账户接管</title>
    <link>https://gugesay.com/blog/在chatgpt中挖掘xss漏洞实现任意账户接管</link>
    undefined
    <pubDate>Fri, 23 Feb 2024 03:19:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>chatgpt</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/在一个web网站中获得7000赏金奖励</guid>
    <title>在一个Web网站中获得$7000赏金奖励</title>
    <link>https://gugesay.com/blog/在一个web网站中获得7000赏金奖励</link>
    undefined
    <pubDate>Wed, 27 Mar 2024 01:32:37 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>hackerone</category><category>rce</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何在bugcrowd公共项目中找到50多个xss漏洞</guid>
    <title>如何在Bugcrowd公共项目中找到50多个XSS漏洞</title>
    <link>https://gugesay.com/blog/如何在bugcrowd公共项目中找到50多个xss漏洞</link>
    undefined
    <pubDate>Wed, 20 Apr 2022 07:48:49 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>bugcrowd</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将-dom-xss升级为一键帐户接管（下集）</guid>
    <title>如何将 DOM XSS升级为一键帐户接管（下集）</title>
    <link>https://gugesay.com/blog/如何将-dom-xss升级为一键帐户接管（下集）</link>
    undefined
    <pubDate>Thu, 18 Apr 2024 02:21:17 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何将dom-xss升级为一键帐户接管（上集）</guid>
    <title>如何将DOM XSS升级为一键帐户接管（上集）</title>
    <link>https://gugesay.com/blog/如何将dom-xss升级为一键帐户接管（上集）</link>
    undefined
    <pubDate>Wed, 17 Apr 2024 16:00:52 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>帐户接管</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/如何通过搜索js文件找到存储xss的故事</guid>
    <title>如何通过搜索JS文件找到存储XSS的故事</title>
    <link>https://gugesay.com/blog/如何通过搜索js文件找到存储xss的故事</link>
    undefined
    <pubDate>Sat, 15 Mar 2025 09:35:06 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/将selfxss升级为存储xss</guid>
    <title>将SelfXSS升级为存储XSS</title>
    <link>https://gugesay.com/blog/将selfxss升级为存储xss</link>
    undefined
    <pubDate>Mon, 01 Apr 2024 01:38:45 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/将赏金从50变为1000的帐户接管漏洞</guid>
    <title>将赏金从$50变为$1000的帐户接管漏洞</title>
    <link>https://gugesay.com/blog/将赏金从50变为1000的帐户接管漏洞</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 05:59:16 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/最新twitter-xss-csrf-漏洞完整披露</guid>
    <title>最新Twitter XSS + CSRF 漏洞完整披露</title>
    <link>https://gugesay.com/blog/最新twitter-xss-csrf-漏洞完整披露</link>
    undefined
    <pubDate>Wed, 20 Dec 2023 02:03:24 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bugbounty</category><category>csrf</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/某android-app中一处有趣的bug</guid>
    <title>某Android APP中一处国内不认国外认的有趣Bug</title>
    <link>https://gugesay.com/blog/某android-app中一处有趣的bug</link>
    undefined
    <pubDate>Wed, 12 Jun 2024 06:17:36 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>APP</category><category>bugbounty</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/致命xss！利用存储xss窃取-oauth-凭证并泄露数据？</guid>
    <title>利用存储XSS窃取 Oauth 凭证并泄露数据</title>
    <link>https://gugesay.com/blog/致命xss！利用存储xss窃取-oauth-凭证并泄露数据？</link>
    undefined
    <pubDate>Mon, 26 May 2025 02:43:39 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/赚取5w刀的5个顶级xss-poc</guid>
    <title>赚取50000美元的5个顶级 XSS PoC</title>
    <link>https://gugesay.com/blog/赚取5w刀的5个顶级xss-poc</link>
    undefined
    <pubDate>Thu, 05 Jun 2025 02:12:51 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/逆向-citrix-gateway-发现-xss-漏洞</guid>
    <title>逆向 Citrix Gateway 发现 XSS 漏洞</title>
    <link>https://gugesay.com/blog/逆向-citrix-gateway-发现-xss-漏洞</link>
    undefined
    <pubDate>Sun, 13 Aug 2023 02:49:14 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>Citrix</category><category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/通过链式攻击劫持会话获得2500奖励</guid>
    <title>通过链式攻击劫持会话获得$2500奖励</title>
    <link>https://gugesay.com/blog/通过链式攻击劫持会话获得2500奖励</link>
    undefined
    <pubDate>Sat, 12 Aug 2023 09:17:09 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>XSS</category><category>白帽故事</category>
  </item>

  <item>
    <guid>https://gugesay.com/blog/错过游戏时光，意外在-tiktok-赚取-3000-美元的故事</guid>
    <title>错过游戏时光，意外在 TikTok 赚取 3000 美元的故事</title>
    <link>https://gugesay.com/blog/错过游戏时光，意外在-tiktok-赚取-3000-美元的故事</link>
    undefined
    <pubDate>Mon, 14 Jul 2025 02:28:53 GMT</pubDate>
    <author>undefined (Guge)</author>
    <category>bypass</category><category>tiktok</category><category>XSS</category><category>白帽故事</category>
  </item>

    </channel>
  </rss>
