Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: XSS question.

From: VAM <thebigbadwolf(at)fastmail.fm>
Date: Thu Dec 05 2002 - 16:17:42 EST


Thanks Zeno,

On Thu, 5 Dec 2002 14:23:36 -0500 (EST), "zeno" <bugtraq@cgisecurity.net> said:
> If the server escapes everything (example <b>hi</b> becomes

This server (Webster web server) does not escapes like you mention above, but converts all '/'s into '\'.. so </script> becomes useless.

> As far as the browser leaving %20

Right..

> If you

In this case, </script> isn't helping.. Mozilla/IE do not seem to honor <\script> in the response. When the same response is changed to </script>, the script does get executed.

> Obviously script isn't the only method to call

Do you need help?X

I am looking for ways other than <script>...</script> and <img src=javascript:...> to run javascripts. Any ideas on that?

> When
> you encode the entire string does it leave it or attempt any type of

All %xx s are left as they are in the response.. so they become pretty much useless..

>
> - zeno@cgisecurity.com

Thanks,
VAM.
>
>
> >
> > Hey I am trying to figure out a way to exploit a webserver that is
Received on Thu Dec 5 18:41:02 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:37 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library