Web Hack List

Collected research

Cross Context Scripting from within the Browser

malerisch.net: Maxthon - Cross Context Scripting (XCS) - about:history

Maxthon's about:history page renders visited-URL text unescaped, so a location.hash payload on any attacker page lands inside the privileged mx://res zone. From there the maxthon.io and maxthon.program DOM objects give file read and write and command execution; a Metasploit module overwrites j2plauncher.exe to get code running on Windows 7.

Record

Document
malerisch.net: Maxthon - Cross Context Scripting (XCS) - about:history
Researcher
Roberto Suggi Liverani
Published by
blog.malerisch.net
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Roberto Suggi Liverani, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .