<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Javascript on AppVuln</title>
    <link>https://appvuln.com/blog/tags/javascript/</link>
    <description>Recent content in Javascript on AppVuln</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    <lastBuildDate>Sun, 23 Jul 2017 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://appvuln.com/blog/tags/javascript/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>XSS Tricky: Function Hoisting</title>
      <link>https://appvuln.com/blog/xss-tricky-function-hoisting/</link>
      <pubDate>Sun, 23 Jul 2017 00:00:00 +0000</pubDate>
      <guid>https://appvuln.com/blog/xss-tricky-function-hoisting/</guid>
      <description>&lt;p&gt;Another day, another hunt for XSS. A simplified version of the target code:&lt;/p&gt;&#xA;&lt;pre&gt;&lt;code&gt;&amp;lt;script&amp;gt;&#xA;func().val(&#39;&amp;lt;?php echo htmlspecialchars($input, ENT_COMPAT, &#39;UTF-8&#39;); ?&amp;gt;&#39;);&#xA;&amp;lt;/script&amp;gt;&#xA;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;A user-supplied &lt;code&gt;$input&lt;/code&gt; is echoed into a JavaScript context after having HTML entities encoded. We can&amp;rsquo;t inject additional script tags due to the HTML encoding. So we&amp;rsquo;ll stick with JavaScript and try to inject a payload:&lt;/p&gt;&#xA;&lt;pre&gt;&lt;code&gt;&#39;); alert(1); //&#xA;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;We use &lt;code&gt;&#39;);&lt;/code&gt; to close out the &lt;code&gt;val()&lt;/code&gt; call with an empty string. Next comes our payload. Finally, &lt;code&gt;//&lt;/code&gt; comments out any remaining characters from the original code. We end up with:&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS Tricky: innerText&#39;s HTML Decoding</title>
      <link>https://appvuln.com/blog/xss-tricky-innertexts-html-decoding/</link>
      <pubDate>Sun, 26 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://appvuln.com/blog/xss-tricky-innertexts-html-decoding/</guid>
      <description>&lt;p&gt;XSS is in the air, everywhere I look around. A simplified version of the code:&lt;/p&gt;&#xA;&lt;pre&gt;&lt;code&gt;&amp;lt;div id=&amp;quot;foo&amp;quot;&amp;gt;&#xA;&amp;lt;?php echo htmlspecialchars($input, ENT_QUOTES, &#39;UTF-8&#39;); ?&amp;gt;&#xA;&amp;lt;/div&amp;gt;&#xA;&#xA;&amp;lt;script&amp;gt;&#xA;var bar = document.getElementById(&#39;foo&#39;);&#xA;var text = bar.innerText;&#xA;bar.innerHTML = &#39;&amp;lt;b&amp;gt;&#39; + text + &#39;&amp;lt;/b&amp;gt;&#39;;&#xA;&amp;lt;/script&amp;gt;&#xA;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;So our user-supplied &lt;code&gt;$input&lt;/code&gt; is echoed after having HTML entities encoded. Then its DOM element is read with &lt;code&gt;innerText&lt;/code&gt;. This property returns only the text from a DOM element. Next, some decorative tags are added to the text and the whole thing is written back as markup, using &lt;code&gt;innerHTML&lt;/code&gt;. Although there&amp;rsquo;s usually little reason to do this in JavaScript, our original input is encoded, so it doesn&amp;rsquo;t appear to be vulnerable to XSS.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
