XSS Fragmentation Attacks
October 25th, 2006 by noam, Filed under: Commentary, Full Disclosure, Web
A newly released paper shows how a fragmentation attack can be used to cause web site that don’t filter out content too strictly to include arbitrary javascript which in turn can be used to cause a cross site scripting vulnerability. One such web site is of course MySpace.com.
The concept basically stems from the idea that if the web site looks for tags when it filters out content, then using broken tag content will render the filtering mechanism useless.
You can read more about this in the following link.




Pingback: Tramadol online ehop.