Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Blind XSS is a thing.

not my fault you haphazardly inserted <whatever I crafted> into an HTML field in some browser at some point in the future.

DNS records, facebook statuses, titles of apps on the playstore, Wifi SSIDs, BIO's on obscure forums, names of children, recipe ingredients, your TV's network nick name...anything that can hold the input of a user, that a scraper or content mechanism will eventually naively come across...

eventually it will get added to the DOM of some unknownst messenger, and I will receive a ping, letting me know that someone, somewhere, somewhen, sniffed my digital fart.



> ...anything that can hold the input of a user, that a scraper or content mechanism will eventually naively come across

Good way to put it, and I'm going to share this.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: