Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

0x03不认可base64编码 #2

Open
lifangzheng opened this issue May 12, 2017 · 1 comment
Open

0x03不认可base64编码 #2

lifangzheng opened this issue May 12, 2017 · 1 comment
Labels

Comments

@lifangzheng
Copy link

lifangzheng commented May 12, 2017

<object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTs8L3NjcmlwdD4=">
直接在浏览器弹了,应该也算对吧

@haozi
Copy link
Owner

haozi commented Nov 19, 2017

不能算合格,新开的 context,与原页面是独立的上下文,受同源限制,危害小很多。

拦截脚本没能捕获到这个 alert,原因见源码
https://github.com/haozi/xss-demo/blob/master/src/data/sandbox.raw#L10

@haozi haozi closed this as completed Nov 19, 2017
@haozi haozi reopened this Nov 19, 2017
@haozi haozi added the wontfix label Nov 19, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants