Web Hack List

Collected research

Inline UTF-7 E4X javascript hijacking

Cross-domain theft of XML data using E4X and a UTF-7 charset, needing no variable assignment in the target. Injecting a UTF-7 encoded record into the XML closes the surrounding tags and opens a new E4X assignment, so including the feed with a script tag and charset=UTF-7 leaves the whole document in an attacker-named variable.

Record

Researcher
Gareth Heyes
Published by
thespanner.co.uk
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .