4 ms·
Pretty clever, but I'm wondering how this would be exploited. To insert an XSS attack on facebook.com, he would have to be able to change the extension in url i
by bwindels 11y ago
Pretty clever, but I'm wondering how this would be exploited. To insert an XSS attack on facebook.com, he would have to be able to change the extension in url in the facebook page of an uploaded image to .html, right? Don't see a way of doing that.
Am I missing something, or the attack assumes you can convince a victim to go to the given URL through other means? Like spreading through IM, E-mail...
- bwindels 11y agoAfter reading the comments here, it seems like the attack would indeed assume you spread the alternative URL with the .html extension through other means like IM, ...
- dwild 11y agoThere's multiple way to spread it, you put that url inside an iframe and then you could upload it on some ad network, you could build some viral content somewhere and let it spread that way. It's pretty easy to spread an XSS.