Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Guess what..

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > General IT Discussion

Guess what..
Reply
 
Thread Tools
Old 27-01-2011, 12:09   #1
Dai
Inactive
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 77
Services: 50Mb, TV & Phone
Posts: 3,673
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Guess what..

Anyone care to guess what this does?


($=[$=[]][(__=!$+$)[_=-~-~-~$]+({}+$)[_/_]+
($$=($_=!''+$)[_/_]+$_[+$])])()[__[_/_]+__
[_+~$]+$_[_]+$$](_/_)


googling will reveal all ... how many web forums that attempt to strip
out javascript from posts would strip it out?
Dai is offline   Reply With Quote
Advertisement
Old 27-01-2011, 22:57   #2
Matth
Inactive
 
Join Date: Mar 2004
Services: BB:M, TV:XL, Phone:M, Loyalty
Posts: 2,516
Matth has reached the bronze age
Matth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze ageMatth has reached the bronze age
Re: Guess what..

Alarming, IE8 detected an XSS attempt
See also
http://utf-8.jp/public/jjencode.html
Matth is offline   Reply With Quote
Old 27-01-2011, 23:43   #3
budwieser
cf.mega poster
 
budwieser's Avatar
 
Join Date: Jan 2004
Location: Cambridgeshire
Age: 64
Posts: 4,232
budwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny star
budwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny star
Re: Guess what..

Quote:
Originally Posted by DaiNasty View Post
Anyone care to guess what this does?


($=[$=[]][(__=!$+$)[_=-~-~-~$]+({}+$)[_/_]+
($$=($_=!''+$)[_/_]+$_[+$])])()[__[_/_]+__
[_+~$]+$_[_]+$$](_/_)


googling will reveal all ... how many web forums that attempt to strip
out javascript from posts would strip it out?
Is it the script for an ASCI Porn film? Needs a couple more ( . )( . ) in it mate.
budwieser is offline   Reply With Quote
Old 28-01-2011, 22:31   #4
Dai
Inactive
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 77
Services: 50Mb, TV & Phone
Posts: 3,673
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Guess what..

Quote:
Originally Posted by Matth View Post
Alarming, IE8 detected an XSS attempt
See also
http://utf-8.jp/public/jjencode.html
I'm reliably informed thusly:

What it does very cleverly is dissect individual letters from the
runtime string constants like "object", "false" and "true", then
concatenate them back together to make a string representation of the
code it wants to execute, which it can do because javascript is a
dynamic language ...

All that demo code does is build the equivalent of

window["alert"](1)

but without containing any alphanumerics itself, with similar techniques
and by making use of additional string constants (you could get hold of
"null", "number", "string", "undefined" and "array" easily) you could
grab 18 out of the 26 letters to play with

abcdefg_ij_lmno__rstu___y_

with suitable cunning, you could start to patch together a sizeable
fraction of whatever code you really wanted to inject, all without
looking like recognisable code.

Or something..
Dai is offline   Reply With Quote
Old 28-01-2011, 23:18   #5
Maggy
The Invisible Woman
Cable Forum Mod
 
Maggy's Avatar
 
Join Date: Jun 2003
Location: between Portsmouth and Southampton.
Age: 73
Services: VM XL TV,50 MB VM BB,VM landline, Tivo
Posts: 40,365
Maggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden aura
Maggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden auraMaggy has a golden aura
Re: Guess what..

__________________
Hell is empty and all the devils are here. Shakespeare..
Maggy is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 20:22.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum