Web Hack List

Collected research

Top-Level Universal XSS

Internet Explorer's PlainHostName rule maps any dotless hostname to the Local Intranet Zone, so sites served at a bare TLD such as http://ac/ load with reduced origin checks and no XSS filter. An XSS on such a host therefore becomes universal XSS able to read cross-domain responses. A working proof of concept reads reddit.com response headers.

Record

Researcher
superevr
Published by
Superevr
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of superevr, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .