Post Reply 
Andrew's Security Filter(s) v5.62 (May 10, 2009)
Jun. 17, 2008, 11:48 AM
Post: #54
RE: Andrew's Security Filter(s) v5.56 (June 15, 2008)
Kye-U Wrote:EDIT: Found a 484-byte long <script> tag here; increased the byte-limit in my test filter from 256 to 512

Yeah, 256 is too small.

Oddysey Wrote:Don't forget that in some cases, the "<script...." you see in a page's source code didn't necessarily arrive in that form
...snip...
<document.write "<scr" + "ipt>"...... etc.>

In order for the code example you cited to work, the outer html script tag must work.
If you disable the html script tags, nothing in the script will work.

Oddysey Wrote:Mike, is this what you meant by the tag sometimes being encoded?

I was thinking of the String.fromCharCode() and String.charCodeAt() javascript methods.
Although trying to text match variations of your example can also be a real pain.

z12
Add Thank You Quote this message in a reply
Post Reply 


Messages In This Thread
RE: Andrew's Security Filter(s) - Guest - Aug. 02, 2007, 10:23 AM
RE: Andrew's Security Filter(s) - usr - Aug. 02, 2007, 11:05 AM
RE: Andrew's Security Filter(s) - Kye-U - Aug. 02, 2007, 02:01 PM
RE: Andrew's Security Filter(s) - usr - Aug. 02, 2007, 02:07 PM
RE: Andrew's Security Filter(s) - Oddysey - Aug. 02, 2007, 06:33 PM
RE: Andrew's Security Filter(s) - usr - Aug. 02, 2007, 09:11 PM
RE: Andrew's Security Filter(s) - Kye-U - Aug. 02, 2007, 10:43 PM
RE: Andrew's Security Filter(s) - usr - Aug. 02, 2007, 11:53 PM
RE: Andrew's Security Filter(s) - Kye-U - Aug. 04, 2007, 04:26 AM
RE: Andrew's Security Filter(s) - usr - Aug. 04, 2007, 10:21 AM
RE: Andrew's Security Filter(s) - Kye-U - Oct. 22, 2007, 05:15 AM
RE: Andrew's Security Filter(s) - usr - Nov. 02, 2007, 08:40 PM
RE: Andrew's Security Filter(s) v3 (Nov. 11, 2007) - Guest - Apr. 22, 2008, 12:01 PM
RE: Andrew's Security Filter(s) v5.56 (June 15, 2008) - z12 - Jun. 17, 2008 11:48 AM

Forum Jump: