Web Hack List

Top 10 winner

Web Mayhem: Firefox's JAR: Protocol issues

Web Mayhem: Firefox’s JAR: Protocol issues

Firefox's jar: protocol runs content from inside an archive under the origin of the archive's URL, so any site accepting ZIP-derived uploads (odt, docx, attachments) becomes vulnerable to persistent XSS. pdp also notes jar: can be nested and can wrap data:, letting a payload be obfuscated past antivirus and IDS.

Record

Document
Web Mayhem: Firefox’s JAR: Protocol issues
Researcher
pdp
Published by
GNUCITIZEN
Date
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .