Web Hack List

Top 10 winner

Bypassing Chrome's Anti-XSS filter

Chrome's static anti-XSS filter inspected each reflected parameter on its own, so a script tag in one parameter was stripped. Splitting the payload across two reflected parameters and opening a JavaScript multi-line comment in the first, closing it in the second, hides the intervening HTML from the parser and the alert fires. Google declined to treat it as in scope.

Record

Researcher
Nick Nikiforakis
Published by
blog.securitee.org
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Nick Nikiforakis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .