Top 10 winner
Universal XSS in IE8
IE8's XSS filter neutralises a detected attack by rewriting one character of the response to a hash. The authors show an attacker can trigger that deliberately with a dummy GET parameter carrying a string already on the page, corrupting an equals sign just before a quoted attribute so injected text becomes a new attribute pair. That gave universal XSS on bing, wikipedia and twitter.
Record
- Researcher
- Eduardo Vela Nava and David Lindsay
- Published by
- wokb.cz
- Topic
- XSS
In the archive
Related sources
- Abusing Internet Explorer 8's XSS Filters Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Eduardo Vela Nava and David Lindsay, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .