Collected research
Cross-protocol XSS with non-standard service ports
Browsers render non-HTTP responses without requiring HTTP headers, and IE ignores the port when deciding DOM origin. A multipart form POST drives an FTP or SMTP server on a non-standard port into reflecting attacker input; the reflected script then executes in the site's origin, giving XSS on hosts that merely run another service alongside the website.
Record
- Researcher
- Arshan Dabirsiaghi
- Published by
- i8jesus.com
- Topic
- XSS
In the archive
Related sources
- HTML Form Protocol Attack Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of Arshan Dabirsiaghi, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .