Collected research
Xanga Hit By Script Worm
SecuriTeam Blogs » Xanga Hit By Script Worm
Matthew Murphy's same-day analysis of the Xanga worm: a DIV whose CSS background url() holds a javascript: URI split across line breaks that IE reassembles, defeating the site's keyword filter, then eval of the DIV's own code attribute bootstraps XMLHTTP that reposts the worm through the blog editor. Annotated source for all seven routines.
Record
- Document
- SecuriTeam Blogs » Xanga Hit By Script Worm
- Researcher
- Matthew Murphy
- Published by
- blogs.securiteam.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Matthew Murphy, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .