Search found 3 matches

by .mario
Mon Jul 20, 2009 10:25 am
Forum: NoScript Development
Topic: JAR archive traversal vis SCRIPT src
Replies: 6
Views: 3997

Re: JAR archive traversal vis SCRIPT src

Awesome - thx :)
by .mario
Sun Jul 19, 2009 10:54 pm
Forum: NoScript Development
Topic: JAR archive traversal vis SCRIPT src
Replies: 6
Views: 3997

Re: JAR archive traversal vis SCRIPT src

Same behavior on "V. 1.9.6.2 - Your Friendly Web Cop"
by .mario
Sun Jul 19, 2009 10:50 pm
Forum: NoScript Development
Topic: JAR archive traversal vis SCRIPT src
Replies: 6
Views: 3997

JAR archive traversal vis SCRIPT src

Hi, I hope this is the right place - I did some testing with JAR files on remote locations and src attributes for script tags. Resulting in this example: <script src="jar://sites.google.com/site/jartest00mario/xss.jar!/attack2.js"></script> http://heideri.ch/jso/jar.html http://sites.googl...