Quantcast
Channel: Files from Michal Zalewski ≈ Packet Storm
Viewing all articles
Browse latest Browse all 25

JavaScript Switcharoo Proof Of Concept 2

$
0
0
Firefox and Opera allow you to omit MIME type in data: URLs, possibly put random garbage into that section, and still get a valid HTML document. This is a natural extension of how the Content-Type header is handled in HTTP, but probably makes little or no sense here. With the use of Unicode homographs, you can create fairly believable URLs especially in Firefox.

Viewing all articles
Browse latest Browse all 25

Trending Articles