Chinaunix首页 | 论坛 | 博客
  • 博客访问: 1198914
  • 博文数量: 272
  • 博客积分: 3899
  • 博客等级: 中校
  • 技术积分: 4734
  • 用 户 组: 普通用户
  • 注册时间: 2012-06-15 14:53
文章分类

全部博文(272)

文章存档

2012年(272)

分类: 网络与安全

2012-06-27 10:58:04

老外发现的一个firefox功能

.cgisecurity.com/2010/03/random-firefox-url-handling.html

我在我的firefox 3.6上测试通过

以下是转载:


About a year ago I discovered this by accident and hadn't seen it published anywhere so thought it was worth mentioning. If you enter the following into the firefox URL bar it will follow them to

[]

[http://]

[].cnn.com

Etc...

You can also substitute [] for {} or " and it will also work (I haven't bothered enumerating/posting each one, but you get the idea). Now if you hyperlink using the following link it will follow them.

Maybe someone will find this useful in some way :) 


在我看来这几个特性是很有用的。一些IDS的规则又需要更新了,不在这里深入讨论~~ 

浏览器自己整的一些功能,总是会给IDS规则带来各种麻烦

比如上次我提到的IE %5c的问题也是如此。

阅读(1124) | 评论(0) | 转发(0) |
0

上一篇:Firefox 3.6 crash

下一篇:Dojo 的DOM based XSS

给主人留下些什么吧!~~