hacktricks/pentesting-web/xss-cross-site-scripting/sniff-leak.md

2.9 KiB

Sniff Leak

{% hint style="success" %} Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)

Support HackTricks
{% endhint %}

Leak script content by converting it to UTF16

Hii andiko inavuja maandiko/plain kwa sababu hakuna kichwa X-Content-Type-Options: nosniff kwa kuongeza wahusika wachache wa mwanzo ambao watafanya javascript ifikirie kwamba maudhui yako katika UTF-16 ili script isivunjike.

Leak script content by treating it as an ICO

Andiko linalofuata linavuja maudhui ya script kwa kuipakia kana kwamba ilikuwa picha ya ICO kwa kufikia parameter width.

{% hint style="success" %} Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)

Support HackTricks
{% endhint %}