Top 10 winner
Bypassing Chrome's Anti-XSS filter
Chrome's static anti-XSS filter inspected each reflected parameter on its own, so a script tag in one parameter was stripped. Splitting the payload across two reflected parameters and opening a JavaScript multi-line comment in the first, closing it in the second, hides the intervening HTML from the parser and the alert fires. Google declined to treat it as in scope.
Record
- Researcher
- Nick Nikiforakis
- Published by
- blog.securitee.org
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Nick Nikiforakis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .