Web Hack List

Collected research

Xanga Hit By Script Worm

SecuriTeam Blogs » Xanga Hit By Script Worm

Matthew Murphy's same-day analysis of the Xanga worm: a DIV whose CSS background url() holds a javascript: URI split across line breaks that IE reassembles, defeating the site's keyword filter, then eval of the DIV's own code attribute bootstraps XMLHTTP that reposts the worm through the blog editor. Annotated source for all seven routines.

Record

Document
SecuriTeam Blogs » Xanga Hit By Script Worm
Researcher
Matthew Murphy
Published by
blogs.securiteam.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Matthew Murphy, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .