How to Use JavaScript Injections

JavaScript injection is a process by which we can insert and use our own JavaScript code in a page, either by entering the code into the address bar, or by finding an XSS vulnerability in a website. Note that the changes can only be seen...

Sample Injections

How to Use JavaScript Injections Picture 1How to Use JavaScript Injections Picture 1 Sample Javascript Injections
Method 1 of 1:

Using JavaScript Injections

  1. How to Use JavaScript Injections Picture 2How to Use JavaScript Injections Picture 2
    You must enter the code in the URL address bar of the window. Try these injections:
    1. Note - If you use Firefox, you will have to use another way, like cmd-shift-k on a Mac
    2. javascript:alert("Hello!");
    3. To bring up an alert box saying "Hello!":
  2. How to Use JavaScript Injections Picture 3How to Use JavaScript Injections Picture 3
    javascript:alert("Hello"); alert("World");
    1. To bring up 2 alert boxes, the one in the front will say "Hello" and once you click OK, the one saying "World" will appear:
  3. How to Use JavaScript Injections Picture 4How to Use JavaScript Injections Picture 4
    javascript:alert(document.forms[0].to.value="something")
    1. To change the value of form [0] to something:
  4. How to Use JavaScript Injections Picture 5How to Use JavaScript Injections Picture 5
    javascript:void(document.bgColor="blue")
    1. To change the background color to blue. You can put any other color in the place of blue to change it to a different color:
  5. How to Use JavaScript Injections Picture 6How to Use JavaScript Injections Picture 6
    javascript:alert("The actual url is:tt" + location.protocol + "//" + location.hostname + "/" + "nThe address URL is:tt" + location.href + "n" + "nIf the server names do not match, this may be a spoof.");
    1. To see the real server name of the site you are looking at. You should use it if you think that you are viewing a spoofed website, or anytime just to make sure:
  6. How to Use JavaScript Injections Picture 7How to Use JavaScript Injections Picture 7
    javascript:R=0; x1=.1; y1=.05; x2=.25; y2=.24; x3=1.6; y3=.24; x4=300; y4=200; x5=300; y5=200; DI=document.images; DIL=DI.length; function A(){for(i=0; i-DIL; i++){DIS=DI[ i ].style; DIS.position='absolute'; DIS.left=Math.sin(R*x1+i*x2+x3)*x4+x5; DIS.top=Math.cos(R*y1+i*y2+y3)*y4+y5}R++}setInterval('A()',5); void(0);
    1. To make pictures fly around. Make sure to find a site like Google Images so there are more pictures!(If you press the refresh button, it goes really fast, but might only work with macOS):
  7. How to Use JavaScript Injections Picture 8How to Use JavaScript Injections Picture 8
    javascript:R=0; x1=.1; y1=.05; x2=.25; y2=.24; x3=1.6; y3=.24; x4=300; y4=200; x5=300; y5=200; DI=document.images; DIL=DI.length; function A(){for(i=0; i-DIL; i++){DIS=DI[ i ].style; DIS.position='absolute'; DIS.left=Math.cos(R*x1+i*x1+x2)*x4+x5; DIS.top=Math.cos(R*y1+i*y2+y3)*y4+y5}R++}setInterval('A()',5); void(0);
    1. To spin circle of pictures. It funnels the pictures in a snake-like motion:
  8. How to Use JavaScript Injections Picture 9How to Use JavaScript Injections Picture 9
    javascript:document.body.contentEditable='true';document.designMode='on';void 0
    1. To move things around on the webpage:
4 ★ | 2 Vote