{"id":103579,"date":"2025-02-26T11:47:31","date_gmt":"2025-02-26T11:47:31","guid":{"rendered":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/"},"modified":"2025-02-26T11:47:31","modified_gmt":"2025-02-26T11:47:31","slug":"reflected-xss-byp4ss-using-double-encoding-xss-poc","status":"publish","type":"post","link":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/","title":{"rendered":"Reflected XSS | Byp4ss using Double Encoding | XSS PoC"},"content":{"rendered":"<div class=\"youtubomatic-video-container\"><iframe loading=\"lazy\" width=\"580\" height=\"380\" src=\"https:\/\/www.youtube.com\/embed\/81H9VNGJnlc?autoplay=1&#038;controls=1&#038;hl=en\" frameborder=\"0\" allowfullscreen><\/iframe><\/div>\n<p>In this video, I demonstrate how to bypass a strong WAF to exploit a Reflected XSS vulnerability. This technique is useful for bug hunters and pentesters dealing with strict security filters.<\/p>\n<p>\u26a0\ufe0f \ud835\uddd7\ud835\uddf6\ud835\ude00\ud835\uddf0\ud835\uddf9\ud835\uddee\ud835\uddf6\ud835\uddfa\ud835\uddf2\ud835\uddff<br \/>\nThis video is made for educational purposes and to raise awareness about cybersecurity. Any misuse of the information in this video for illegal activities is the responsibility of the individual. Use this knowledge ethically and comply with applicable laws.<\/p>\n<p>\u2753 \ud835\uddea\ud835\uddf5\ud835\uddee\ud835\ude01\u2019\ud835\ude00 \ud835\uddd6\ud835\uddfc\ud835\ude03\ud835\uddf2\ud835\uddff\ud835\uddf2\ud835\uddf1 \ud835\uddf6\ud835\uddfb \ud835\udde7\ud835\uddf5\ud835\uddf6\ud835\ude00 \ud835\udde9\ud835\uddf6\ud835\uddf1\ud835\uddf2\ud835\uddfc?<br \/>\n \u2022 Bypass automatically converted output in XSS<br \/>\n \u2022 Exploiting Reflected XSS with custom payloads<br \/>\n \u2022 Live demonstration and request-response analysis<\/p>\n<p>\u2753 \ud835\uddea\ud835\uddf5\ud835\uddee\ud835\ude01 \ud835\uddee\ud835\uddff\ud835\uddf2 \ud835\udde7\ud835\uddf5\ud835\uddf2 \ud835\udddc\ud835\uddfa\ud835\uddfd\ud835\uddee\ud835\uddf0\ud835\ude01\ud835\ude00 \ud835\uddfc\ud835\uddf3 \ud835\udde5\ud835\uddf2\ud835\uddf3\ud835\uddf9\ud835\uddf2\ud835\uddf0\ud835\ude01\ud835\uddf2\ud835\uddf1 \ud835\uddeb\ud835\udde6\ud835\udde6 \ud835\udde9\ud835\ude02\ud835\uddf9\ud835\uddfb\ud835\uddf2\ud835\uddff\ud835\uddee\ud835\uddef\ud835\uddf6\ud835\uddf9\ud835\uddf6\ud835\ude01\ud835\uddf6\ud835\uddf2\ud835\ude00?<br \/>\n \u2022 Cookie Theft &#038; Session Hijacking \u2013 Attackers can steal session cookies to take over user accounts.<br \/>\n \u2022 Phishing &#038; Social Engineering \u2013 Creating fake pages to steal credentials or sensitive information.<br \/>\n \u2022 Defacement \u2013 Modifying website appearance using malicious scripts.<br \/>\n \u2022 Payload Chaining \u2013 Redirecting victims to malicious sites for further exploitation.<br \/>\n \u2022 Bypassing CSRF Protections \u2013 Using XSS to execute actions without user consent.<\/p>\n<p>Reflected XSS usually requires user interaction (such as clicking a link).<\/p>\n<p>\ud83d\udcf1 \ud835\udde6\ud835\uddfc\ud835\uddf0\ud835\uddf6\ud835\uddee\ud835\uddf9 \ud835\udde0\ud835\uddf2\ud835\uddf1\ud835\uddf6\ud835\uddee<br \/>\nGift me: <a href=\"https:\/\/saweria.co\/randixploit\" target=\"_blank\">https:\/\/saweria.co\/randixploit<\/a><br \/>\nInstagram:  <a href=\"https:\/\/www.instagram.com\/randixploit.shtml\" target=\"_blank\">https:\/\/www.instagram.com\/randixploit.shtml<\/a><br \/>\nTikTok: <a href=\"https:\/\/www.tiktok.com\/@\" target=\"_blank\">https:\/\/www.tiktok.com\/@<\/a>randixploit.shtml<br \/>\nTelegram Channel: <a href=\"https:\/\/t.me\/justrchannel\" target=\"_blank\">https:\/\/t.me\/justrchannel<\/a><br \/>\nTelegram Group: <a href=\"https:\/\/t.me\/itactivistgroup\" target=\"_blank\">https:\/\/t.me\/itactivistgroup<\/a><\/p>\n<p>\ud83d\udd11 \ud835\uddde\ud835\uddf2\ud835\ude06::<br \/>\npentesting<br \/>\nbug hunting<br \/>\nbug bounty<br \/>\ncyber security<br \/>\nethical hacking<br \/>\ncross site scripting<br \/>\nreflected xss<\/p>\n<p>\ud83d\udce3 Don&#8217;t forget to subscribe and like this video so that I will be even more enthusiastic about uploading other similar videos, and don&#8217;t forget to activate the notification bell so you can find out about the latest content from me.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this video, I demonstrate how to bypass a strong WAF to exploit a Reflected XSS vulnerability. This technique is useful for bug hunters and pentesters dealing with strict security filters. \u26a0\ufe0f \ud835\uddd7\ud835\uddf6\ud835\ude00\ud835\uddf0\ud835\uddf9\ud835\uddee\ud835\uddf6\ud835\uddfa\ud835\uddf2\ud835\uddff This video is made for educational purposes and to raise awareness about cybersecurity. Any misuse of the information in this video for illegal activities is the responsibility of the individual. Use this knowledge ethically and comply with&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[1],"tags":[],"class_list":["post-103579","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Reflected XSS | Byp4ss using Double Encoding | XSS PoC - UshopWell.com<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Reflected XSS | Byp4ss using Double Encoding | XSS PoC - UshopWell.com\" \/>\n<meta property=\"og:description\" content=\"In this video, I demonstrate how to bypass a strong WAF to exploit a Reflected XSS vulnerability. This technique is useful for bug hunters and pentesters dealing with strict security filters. \u26a0\ufe0f \ud835\uddd7\ud835\uddf6\ud835\ude00\ud835\uddf0\ud835\uddf9\ud835\uddee\ud835\uddf6\ud835\uddfa\ud835\uddf2\ud835\uddff This video is made for educational purposes and to raise awareness about cybersecurity. Any misuse of the information in this video for illegal activities is the responsibility of the individual. Use this knowledge ethically and comply with...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/\" \/>\n<meta property=\"og:site_name\" content=\"UshopWell.com\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-26T11:47:31+00:00\" \/>\n<meta name=\"author\" content=\"UShopWell\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"UShopWell\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/reflected-xss-byp4ss-using-double-encoding-xss-poc\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/reflected-xss-byp4ss-using-double-encoding-xss-poc\\\/\"},\"author\":{\"name\":\"UShopWell\",\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/#\\\/schema\\\/person\\\/6fd1f9e0ff932e534c86c70d5acff0fc\"},\"headline\":\"Reflected XSS | Byp4ss using Double Encoding | XSS PoC\",\"datePublished\":\"2025-02-26T11:47:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/reflected-xss-byp4ss-using-double-encoding-xss-poc\\\/\"},\"wordCount\":247,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/#organization\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/reflected-xss-byp4ss-using-double-encoding-xss-poc\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/reflected-xss-byp4ss-using-double-encoding-xss-poc\\\/\",\"url\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/reflected-xss-byp4ss-using-double-encoding-xss-poc\\\/\",\"name\":\"Reflected XSS | Byp4ss using Double Encoding | XSS PoC - UshopWell.com\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/#website\"},\"datePublished\":\"2025-02-26T11:47:31+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/reflected-xss-byp4ss-using-double-encoding-xss-poc\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/reflected-xss-byp4ss-using-double-encoding-xss-poc\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/reflected-xss-byp4ss-using-double-encoding-xss-poc\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Reflected XSS | Byp4ss using Double Encoding | XSS PoC\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/#website\",\"url\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/\",\"name\":\"UshopWell.com\",\"description\":\"The Premiere Online Marketplace\",\"publisher\":{\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/#organization\",\"name\":\"UshopWell\",\"url\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/wp-content\\\/uploads\\\/2018\\\/01\\\/pandaSwea.png\",\"contentUrl\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/wp-content\\\/uploads\\\/2018\\\/01\\\/pandaSwea.png\",\"width\":365,\"height\":359,\"caption\":\"UshopWell\"},\"image\":{\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/#\\\/schema\\\/person\\\/6fd1f9e0ff932e534c86c70d5acff0fc\",\"name\":\"UShopWell\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4adb372cadd43b4d4c57964dab95b0f69618bf960d131c4acf49d96d6bbc9c6e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4adb372cadd43b4d4c57964dab95b0f69618bf960d131c4acf49d96d6bbc9c6e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4adb372cadd43b4d4c57964dab95b0f69618bf960d131c4acf49d96d6bbc9c6e?s=96&d=mm&r=g\",\"caption\":\"UShopWell\"},\"url\":\"https:\\\/\\\/ushopwell.com\\\/ublog\\\/author\\\/kburnettu\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Reflected XSS | Byp4ss using Double Encoding | XSS PoC - UshopWell.com","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/","og_locale":"en_US","og_type":"article","og_title":"Reflected XSS | Byp4ss using Double Encoding | XSS PoC - UshopWell.com","og_description":"In this video, I demonstrate how to bypass a strong WAF to exploit a Reflected XSS vulnerability. This technique is useful for bug hunters and pentesters dealing with strict security filters. \u26a0\ufe0f \ud835\uddd7\ud835\uddf6\ud835\ude00\ud835\uddf0\ud835\uddf9\ud835\uddee\ud835\uddf6\ud835\uddfa\ud835\uddf2\ud835\uddff This video is made for educational purposes and to raise awareness about cybersecurity. Any misuse of the information in this video for illegal activities is the responsibility of the individual. Use this knowledge ethically and comply with...","og_url":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/","og_site_name":"UshopWell.com","article_published_time":"2025-02-26T11:47:31+00:00","author":"UShopWell","twitter_card":"summary_large_image","twitter_misc":{"Written by":"UShopWell","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/#article","isPartOf":{"@id":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/"},"author":{"name":"UShopWell","@id":"https:\/\/ushopwell.com\/ublog\/#\/schema\/person\/6fd1f9e0ff932e534c86c70d5acff0fc"},"headline":"Reflected XSS | Byp4ss using Double Encoding | XSS PoC","datePublished":"2025-02-26T11:47:31+00:00","mainEntityOfPage":{"@id":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/"},"wordCount":247,"commentCount":0,"publisher":{"@id":"https:\/\/ushopwell.com\/ublog\/#organization"},"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/","url":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/","name":"Reflected XSS | Byp4ss using Double Encoding | XSS PoC - UshopWell.com","isPartOf":{"@id":"https:\/\/ushopwell.com\/ublog\/#website"},"datePublished":"2025-02-26T11:47:31+00:00","breadcrumb":{"@id":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/ushopwell.com\/ublog\/reflected-xss-byp4ss-using-double-encoding-xss-poc\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ushopwell.com\/ublog\/"},{"@type":"ListItem","position":2,"name":"Reflected XSS | Byp4ss using Double Encoding | XSS PoC"}]},{"@type":"WebSite","@id":"https:\/\/ushopwell.com\/ublog\/#website","url":"https:\/\/ushopwell.com\/ublog\/","name":"UshopWell.com","description":"The Premiere Online Marketplace","publisher":{"@id":"https:\/\/ushopwell.com\/ublog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ushopwell.com\/ublog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/ushopwell.com\/ublog\/#organization","name":"UshopWell","url":"https:\/\/ushopwell.com\/ublog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ushopwell.com\/ublog\/#\/schema\/logo\/image\/","url":"https:\/\/ushopwell.com\/ublog\/wp-content\/uploads\/2018\/01\/pandaSwea.png","contentUrl":"https:\/\/ushopwell.com\/ublog\/wp-content\/uploads\/2018\/01\/pandaSwea.png","width":365,"height":359,"caption":"UshopWell"},"image":{"@id":"https:\/\/ushopwell.com\/ublog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/ushopwell.com\/ublog\/#\/schema\/person\/6fd1f9e0ff932e534c86c70d5acff0fc","name":"UShopWell","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/4adb372cadd43b4d4c57964dab95b0f69618bf960d131c4acf49d96d6bbc9c6e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4adb372cadd43b4d4c57964dab95b0f69618bf960d131c4acf49d96d6bbc9c6e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4adb372cadd43b4d4c57964dab95b0f69618bf960d131c4acf49d96d6bbc9c6e?s=96&d=mm&r=g","caption":"UShopWell"},"url":"https:\/\/ushopwell.com\/ublog\/author\/kburnettu\/"}]}},"_links":{"self":[{"href":"https:\/\/ushopwell.com\/ublog\/wp-json\/wp\/v2\/posts\/103579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ushopwell.com\/ublog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ushopwell.com\/ublog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ushopwell.com\/ublog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ushopwell.com\/ublog\/wp-json\/wp\/v2\/comments?post=103579"}],"version-history":[{"count":0,"href":"https:\/\/ushopwell.com\/ublog\/wp-json\/wp\/v2\/posts\/103579\/revisions"}],"wp:attachment":[{"href":"https:\/\/ushopwell.com\/ublog\/wp-json\/wp\/v2\/media?parent=103579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ushopwell.com\/ublog\/wp-json\/wp\/v2\/categories?post=103579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ushopwell.com\/ublog\/wp-json\/wp\/v2\/tags?post=103579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}