Collected research
Multi-pass filters bypass
Обхід багатопрохідних фільтрів - Websecurity
Space-hack technique against multi-pass filters that scan for XSS keywords first and strip whitespace afterwards. Writing "e xpression" hides the CSS expression keyword and "o nLoad" hides the handler; the second pass deletes the spaces and revives both. A slash replaces the space as tag/attribute separator so the payload still parses once spaces are gone.
Record
- Document
- Обхід багатопрохідних фільтрів - Websecurity
- Published by
- websecurity.com.ua
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of websecurity.com.ua, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .