Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Execution of Javascript from PERL

From: Martin Eiszner <martin(at)websec.org>
Date: Thu Apr 17 2003 - 11:15:34 EDT

hola,

On Thu, 17 Apr 2003 10:52:45 -0400
"Brass, Phil (ISS Atlanta)" <PBrass@iss.net> wrote:



> The real problem is not getting the JavaScript in the page to execute,
> it's getting it to execute in a meaningful context

from the security-testing point of view its not necessary to execute any script .. because:  

IF input

        "<script>thingstodo();</script>"
LEADS TO output

        "<script>thingstodo();</script>"

the application is definitively vulnerable !!!

Do you need help?X

and it is a confuguration-issue to check for all "known" and "unknown" script-tags and -objects !!

nice day,
mEi

-- 
WebSec.org / Martin Eiszner
Gurkgasse 49/Top14
1140 Vienna
Austria / EUROPE

mei@websec.org
http://www.websec.org
tel: 0043 699 121772 37
Received on Thu Apr 17 11:46:45 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:50 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library