A litte hint:
Don't use style="width:0px;height:0px;border:0px;" only, because if the page has something like this in it's CSS:
iframe {
padding:100px;
}
then the following code or text after the iframe will have a large space between itself and the text before the iframe.
style="display:none" works fine and is more than enough ;)
ckore Wrote:
-------------------------------------------------------
> A litte hint:
> Don't use style="width:0px;height:0px;border:0px;"
> only, because if the page has something like this
> in it's CSS:
>
> iframe {
> padding:100px;
> }
> then the following code or text after the iframe
> will have a large space between itself and the
> text before the iframe.
> style="display:none" works fine and is more than
> enough ;)
Well if you're creating the page yourself like the idea was then that isn't really an issue.
Edited 1 time(s). Last edit at 01/19/2007 12:24PM by hasse.
So it does the xss script and then goes to google...but it seems like it just goes to google and forgets about the iframe. When I remove the google redirection it works though so I'm confused :P
----------------------------------
Just use script tags.
<script>document.write('<iframe src="xssscript.php" style="width:0px;height:0px;border:0px"></iframe>')</script>
<script>
location.href="http://www.google.com"
</script>
why did you guys help this kid.. he has no clue how to code, and just copied and pasted your replies. this is where gareth's codetcha comes in handy..... (btw replying to this due to current post on neopets.. god i haven't seen that "game" in over 8-9 years. can't believe it's still going strong)
I never took part in such faggotry, but it's no longer simply a game, fragge. They've expanded their empire, and now have commercials on television, digital pocket games, and stuffed creatures for sale.
Awesome AnDrEw - That's The Sound Of Your Brain Crackin'
http://www.awesomeandrew.net/