414
Chapter 12
■
Attacking Other Users
70779c12.qxd:WileyRed 9/14/07 3:14 PM Page 414
T I P
One qualification to the point about auto-detection of content encoding
is that Internet Explorer tolerates null bytes appearing within HTML, and in
most cases simply ignores them. Provided that URL-encoded null bytes (
%00
)
get returned by the application as actual null bytes, you can often use UTF-16
encoding as an easy way of wrapping your XSS payloads in order to bypass
pattern-based filters, regardless of the
Content-Type
header being returned
by the server. For example, in the original reflected XSS vulnerability, the
Do'stlaringiz bilan baham: |