Top 10 winner
Exponential XSS Attacks
Maluc's idea developed: one XSS foothold is used to exploit XSS on other domains, cascading across every site a user is authenticated to. Grossman's CSS history hack picks which domains to try, and XMLHttpRequest with an XSS proxy, IE's Expect/Flash trick and the mhtml cross-domain leak keep the shell alive as the user navigates away.
Record
- Researcher
- RSnake
- Published by
- ha.ckers.org
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of RSnake, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .