Ok, prove me wrong. xss this get parameter: efukt.com/?search=<xss vector goes here>. If it works on chrome or IE, i'll take back my words and chop off my balls. As i predicted, weird behavior in GET parameter (just received pm from danyweb), not a bypass in either of the xss filters. It's ok .