This is a read-only archive of the old Scratch 1.x Forums.
Try searching the current Scratch discussion forums.

#1 2009-07-21 23:35:50

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

XSS Text

I have lately been testing the scratch website for XSS vulnerabilities, and am happy to announce that as of yet none have arisen. If I think of anything else, I will test it and tell you how it went. Below are the posts which I used to test it.
What I did:
> Tested for parsing of HTML tags. Did so by replacing the < and > symbols with their entity codes.
> Tested for multiple embedded tag parsing.
> Tested Image tag with valid URL
> Tried to exploit IE vulnerability for scripts in src attribute
> Continued above using charactercodes and breaks
> More testing revealed that img tags are just displayed as code if not enclosing a valid url.
> Tried hiding code into 'valid' urls. None worked.
> Deduced that connection protocol must be present to be classed as a valid url.
> Deduced that ampersands proceeded by a hash are parsed as entity code prefixes
> So far, The scratch website is safe!

Last edited by billyedward (2009-07-22 04:27:05)


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#2 2009-07-21 23:38:29

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

<b>TEST</b>


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#3 2009-07-21 23:43:17

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

<str<str<str<str<str<str<str<str<str<strike>ike>ike>ike>ike>ike>ike>ike>ike>ike>XSS test</str</str</str</str</str</str</str</str</str</strike>ike>ike>ike>ike>ike>ike>ike>ike>ike>


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#4 2009-07-21 23:45:03

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

http://streak.t35.com/Pictures/big%20logo.gif


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#5 2009-07-21 23:48:12

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]javascript:alert('XSS attack')[/img]
^ Malicious image src code


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#6 2009-07-21 23:51:38

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]java script:alert('XSS attack')[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#7 2009-07-21 23:52:43

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]java&nbsp;script:alert('XSS attack')[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#8 2009-07-21 23:54:11

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]javAscript:alert('XSS attack')[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#9 2009-07-21 23:55:48

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]alert('XSS attack')[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#10 2009-07-21 23:57:32

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]javascript[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#11 2009-07-21 23:59:01

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]java script[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#12 2009-07-22 00:00:28

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]aRandomWord[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#13 2009-07-22 00:02:09

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

http://www.aValidURL.com/blah.bmp


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#14 2009-07-22 00:03:36

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

http://ttt.com/anHTMLpage.htm


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#15 2009-07-22 00:04:46

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

http://google.com


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#16 2009-07-22 00:05:56

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]<!--http://ttt.com/sss.bmp-->[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#17 2009-07-22 00:07:00

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

http://ttt.com/sss.bmp&lt;!--http://ttt.com/sss.bmp--&gt;


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#18 2009-07-22 00:08:34

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]<!--http://ttt.com/sss.bmp-->http://ttt.com/sss.bmp[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#19 2009-07-22 00:10:13

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

http://ttt.com/sss.bmp&quot;


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#20 2009-07-22 00:16:58

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

http://ttt.com/alert('pi')


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#21 2009-07-22 00:18:04

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

http://ttt.com/javascript:alert('pi')


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#22 2009-07-22 00:20:48

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]javascript://pi.com[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#23 2009-07-22 00:24:24

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]javascript.com[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#24 2009-07-22 00:27:02

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]streak.t35.com/Pictures/big%20logo.gif[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

#25 2009-07-22 00:31:12

billyedward
Scratcher
Registered: 2008-01-03
Posts: 500+

Re: XSS Text

[img]streak.t35.com:80/Pictures/big%20logo.gif[/img]


"I'd love to change the world, but they haven't released the source code yet."
Check out the latest version of Streak --> http://billy.scienceontheweb.net/Streak

Offline

 

Board footer