Protocol Resolution In Script Tags

May 29th, 2006 by admin

This particular variant was submitted by Łukasz Pilorz and was based partially off of Ozh’s protocol resolution bypass. This cross site scripting example works in IE, Netscape in IE rendering mode and Opera if you add in a tag at the end. However, this is especially useful where space is an issue, and of course, the shorter your domain, the better. The “.j” is valid, regardless of the MIME type because the browser knows it in context of a SCRIPT tag.


Tags: ,

Posted in General | No Comments »