Web Hack List

Collected research

Drag and Drop XSS in Firefox by HTML5 (Cross Domain in frames)

Dalili bypasses Firefox's block on dragged javascript: URLs by capitalising the scheme (jAvAscript:) or wrapping it in the feed: protocol. Dropping such a string on an HTML5 drop target inside an iframe redirects the framing page, so the script runs in the parent site's origin. A hidden textarea keeps the payload invisible during selection.

Record

Researcher
Soroush Dalili
Published by
soroush.me
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Soroush Dalili, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .