Post Reply 
<object>...: Toggle Flash 09.07.04 (ccw! !nn) [jd sd] (d.2 l.2)
May. 24, 2010, 09:18 PM (This post was last modified: May. 24, 2010 09:19 PM by sidki3003.)
Post: #5
RE: <object>...: Toggle Flash 09.07.04 (ccw! !nn) [jd sd] (d.2 l.2)
Yes, it has to be a double backslash. The respective line in the original filter is:
Code:
|$TST(script=*)($TST(\1=\")$SET(1=\\x22)|$TST(\1=\')$SET(1=\\x27))
Wonder what went wrong here...

And yep, \x22 and \x27 are supposed to stand for double quote and single quote, respectively. Hex representation has shown to be more robust on injection than the escaped notation.
Add Thank You Quote this message in a reply
Post Reply 


Messages In This Thread
RE: <object>...: Toggle Flash 09.07.04 (ccw! !nn) [jd sd] (d.2 l.2) - sidki3003 - May. 24, 2010 09:18 PM

Forum Jump: