Collected research
Inline UTF-7 E4X javascript hijacking
Cross-domain theft of XML data using E4X and a UTF-7 charset, needing no variable assignment in the target. Injecting a UTF-7 encoded record into the XML closes the surrounding tags and opens a new E4X assignment, so including the feed with a script tag and charset=UTF-7 leaves the whole document in an attacker-named variable.
Record
- Researcher
- Gareth Heyes
- Published by
- thespanner.co.uk
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .