5 ms·
Level 3 seems to no longer be exploitable. Firefox 45.5 here automatically %-encodes the characters into the src attribute.
by xssfoofoo 10y ago
Level 3 seems to no longer be exploitable. Firefox 45.5 here automatically %-encodes the characters into the src attribute.
- xssfoofoo 10y agothis app appears to be at least 2.5 years old.
- flanbiscuit 10y agoprevious hacker news discussion from 2014 about it: https://news.ycombinator.com/item?id=7815237 https://news.ycombinator.com/item?id=7815237
- fdb 10y agoYou're right. It still works in Chrome though...
- Kenji 10y agoIf someone has trouble making the exploit work in Chrome: The developer tools replace all ' with " if you inspect the element. Therefore, it misleads you into thinking that the website encloses attributes in " ", whereas instead it is enclosed in ' '.
- grenoire 10y agoThis did throw me off initially.
- Warp__ 10y agoHere's a way to by bypass that- point the FF dev tools soley at the iframe, then use the scratchpad to run the alert. It will accept that and let you move past. I spent 20 minutes thinking I had something horribly wrong until I read this comment. (This works in FF 52.0a2)
- dagurp 10y agoThank you. This explains a lot
- yellowapple 10y agoEven percent-encoding it ends up just including the entire injection as the path (on 50.0). I worked around it for now by editing the element directly in Developer Tools.