WoYiGuis BLoG
Watch XSS_Attacks _-_ Cross_Site_Scripting_Exploits_and_Defense _ (Syngress-2007) this book, it is estimated that many Daniel has read, ah, on the computer has not been read, time is not much, when you have time, you can flip several pages and add them in English. Today, we have seen more than 150 pages. Well, stick to it.
First, let's talk about this Bypassing XSS Length Limitations. The method mentioned in this article is quite good. I checked the html manual and the location can use three attributes:
<Script> eval (location. hash. substr (1) </script>
<Script> eval (location. search. substr (1) </script>
<Script> eval (location. href. substr (52,60) </script>
The third method needs to calculate the value based on the situation. If you search for the string position in localtion. href and then process it, the url length will be increased. The specific value is the shortest. The above are the ideas of cainiao.