User: Password:
Subscribe / Log in / New account

Chrome reflective XSS protection

Chrome reflective XSS protection

Posted Nov 17, 2009 1:05 UTC (Tue) by jamesh (guest, #1159)
Parent article: Chrome reflective XSS protection

I wonder if this kind of XSS protection could be useful to an attacker as a way of disabling legitimate scripts on a site?

Pick a script that appears in the page, encode it into the request using a form parameter that the site ignores, and pass that URL to the victim. The browser would have no knowledge that the form parameter is being ignored, and just see that its contents have been repeated in the page.

(Log in to post comments)

Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds