[WEB SECURITY] XSS filter Bypass

John Wilander john.wilander at owasp.org
Tue May 29 11:59:03 EDT 2012

Have you tried <%73cript and <%53cript, i.e. URL encoding of 's' and 'S'?

Tried various encodings of '<' so you don't trigger the filter at all?


My music http://www.johnwilander.com
Twitter https://twitter.com/johnwilander
CV or Résumé http://johnwilander.se

24 maj 2012 kl. 12:16 skrev Appsec User <pentestguy.cs at gmail.com>:

> Hi,
> I am probing for XSS in an application. Application has a filter which
> triggers if I put anything after less than sign '<' except space, %
> and >. So application accepts < character but only allows space, % and
>> after it. So e.g < script(note space in b/w) is allowed but <script
> will be rejected(no space). I have tested for various encoding also
> <%00script is allowed but it puts space between < and script and
> browser does not treat it as mark up. I cannot probe for javascript
> events as Payloads are reflecting in HTML context not in javascript
> context. Any suggestions how can I by-pass this filter.
> _______________________________________________
> The Web Security Mailing List
> WebSecurity RSS Feed
> http://www.webappsec.org/rss/websecurity.rss
> Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA
> WASC on Twitter
> http://twitter.com/wascupdates
> websecurity at lists.webappsec.org
> http://lists.webappsec.org/mailman/listinfo/websecurity_lists.webappsec.org

More information about the websecurity mailing list