Web Hack List

Collected research

Twitter misidentifying context

Escaping quotes is not enough inside a JavaScript event attribute, because HTML entities are decoded before the script runs. Twitter escaped the literal quote characters in an onclick handler, but the named and numeric entity spellings of an apostrophe, including unterminated ones, still closed the string and injected code. Escape entities too, using hex escapes.

Record

Researcher
Gareth Heyes
Published by
thespanner.co.uk
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .