Web Hack List

Other nomination

Top-Level Universal XSS

Internet Explorer's PlainHostName rule maps any dotless hostname to the Local Intranet Zone, so sites served at a bare TLD such as http://ac/ load with reduced origin checks and no XSS filter. An XSS on such a host therefore becomes universal XSS able to read cross-domain responses. A working proof of concept reads reddit.com response headers.

Record

Researcher
superevr
Published by
Superevr

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of superevr, first published at the original source. Preserved copies are kept so the citation survives its host.