Jump to content
SilenTx0

XSS Challenge

Recommended Posts

Solu?ia trimisa de blueray este urm?toarea:

http://www.pwnthecode.org/challenges/xss_chall2.php?xss=%22%20onmouseover=%22var%20a=%27aler%27,%20b=%27t%281%29%27;%20eval%28a.concat%28b%29%29;%

Solu?ia lui nu e buna pentru ca vectorul trebuie executat f?r? interac?iunea utilizatorului (sau cu un minim de interactiune). In cazul sau, codul se executa doar daca userul trece cu mouse-ul peste div-ul xss_chall.

Prin "minim de interactiune" se în?elege ca vectorul sa se execute indiferent unde e victima cu mouse-ul pe pagina, iar in cel mai rau caz, sa trebuiasc? sa miste maxim 1px mouse-ul pentru ca vectorul sa se execute).

  • Upvote 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...