XSS (Cross Site Scripting) Cheatsheet, by RSnake

I found this very useful page for XSS (Cross Site Scripting). Many of you have asked for more specifics about how to force authority sites to link to your web sites.

The page, XSS (Cross Site Scripting) Cheatsheet: Esp: for filter evasion – by RSnake, covers hex encoding, IP Obfuscation, URL string evasion and more:

“This XSS still worries me, as it would be nearly impossible to stop this without blocking all active content:”

Fantastic work; thank you RSnake. If you ever want to write something on SEOblackhat.com, no need to hack it – you’re more than welcome to publish here any time you want.

Both comments and pings are currently closed.

One Response to “XSS (Cross Site Scripting) Cheatsheet, by RSnake”

  1. Ozh says:

    Nice list indeed. I’ve had some fun some months ago exploiting Flickr with XSS (harmless, and fixed since by admins)