Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Basic 27


ellipsis's Avatar
...
0 -1

I successfully got empty tags and tried encoding the tags as html entities and to no avail because the output textbox doesn't decode the encoded chars.

Can I PM someone with what I have? I've already went through the OWASP filter evasion cheat sheet for help.


Mordak's Avatar
Evil Sorcerer
4,025 19

Your making it to complex !!! Pm me if you want.


tnk04's Avatar
Member
0 0

I'm not entirely certain it's actually working, you know, unless I'm missing something, too. I can get it to display the "injection", though it's obviously been through htmlentities()… I don't remember ever having to bypass that, but then again, it was a hell of a long time ago.


korg's Avatar
Admin from hell
0 0

it's working fine. Again try something simple to inject.