Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

Basic 27


ellipsis's Avatar
...
0 -1

I successfully got empty tags and tried encoding the tags as html entities and to no avail because the output textbox doesn't decode the encoded chars.

Can I PM someone with what I have? I've already went through the OWASP filter evasion cheat sheet for help.


Mordak's Avatar
Evil Sorcerer
4,025 18

Your making it to complex !!! Pm me if you want.


tnk04's Avatar
Member
0 0

I'm not entirely certain it's actually working, you know, unless I'm missing something, too. I can get it to display the "injection", though it's obviously been through htmlentities()… I don't remember ever having to bypass that, but then again, it was a hell of a long time ago.


korg's Avatar
Admin from hell
0 0

it's working fine. Again try something simple to inject.