You can use Dean Edwards’s JavaScript packer to shrink a given script as
far as possible by eliminating unnecessary whitespace. This utility also converts
scripts to a single line, for easy insertion into a request parameter:
http://dean.edwards.name/packer/
The second, potentially more powerful, technique for beating length limits
is to span an attack payload across multiple different locations where user-
controllable input is inserted into the same returned page. For example, con-
sider the following URL:
https://wahh-app.com/account.php?page_id=244&seed=129402931&mode=normal
Do'stlaringiz bilan baham: |