XSS CSS INJECTION on IE7 and Firefox

Marco Ramilli
Date
26 November 2007
Read
Share
Hi folks,
today I wanna present a great work on XSS CSS injection. Following the amazing work of Martin, style="xx:expression((window.r!=1)? ...... , Gareth wrote a more complete example  of injection scenario. Here it is !

That Translated from hexadecimal  becames:

It's still incredible seeing execution of code even if converted into whole entities as htmlspecialchars. Yep, incredible but true ! Some one is just saying you should never allow users to insert HTML code in your pages but I don't think so, it's difficult to give something and than take it back, it's difficult saying STOP HTML to users now, where users are living on HTML. Maybe security staff must learn from this "another example" and works hard to prevent others similar stuff.
Marco Ramilli
Date
26 November 2007
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier