Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


RaccoonCity's XSS Handbook filter_list
Author
Message
RE: RaccoonCity's XSS Handbook #3
(06-07-2014, 06:15 PM)alok9shm Wrote: Weew!! Got an exam tomorrow morning, but that couldn't stop me from reading the whole stuff. I'm not much interested in hacking but I would really want to know something.

Will using this [ <script>alert('NOKIA')</script> ] in an unSanitized search bar make it persistence? Or does it depend on whether the awesome website is vulnerable to persistence XSS or not?

First of all you have to make sure it's vulnerable.
In a search bar the thing you enter is not stored anywhere.
But, for exmaple on HC. If I would make a thread named a XSS payload of HTML and javascript and HC would be vulnerable, then the thread would stay there until @bluedog.tar.gz removes it.
That would be a persistant XSS.

Like a search that isn't saved somewhere will only be executed for you or anyone with that link. I hope you understand! Smile

Good luck with your exams by the way!

Reply





Messages In This Thread