Collected research
Top-Level Universal XSS
Internet Explorer's PlainHostName rule maps any dotless hostname to the Local Intranet Zone, so sites served at a bare TLD such as http://ac/ load with reduced origin checks and no XSS filter. An XSS on such a host therefore becomes universal XSS able to read cross-domain responses. A working proof of concept reads reddit.com response headers.
Record
- Researcher
- superevr
- Published by
- Superevr
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of superevr, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .