TXT Record XSS
who.is
TXT Record XSS
1–10 of 236 posts
Re: TXT Record XSS
#2Re: TXT Record XSS
#3Never trust user input.
Edit: See http://www.dnswatch.info/dns/dnslookup?la=en&host=jamiehanki... for the actual code.
Re: TXT Record XSS
#4http://dig.whois.com.au/dig.php?dom=jamiehankins.co.uk&type=...
http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins....
Re: TXT Record XSS
#5Re: TXT Record XSS
#6Clever. I didn't get it at first. Never trust user input. Edit: See http://www.dnswatch.info/dns/dnslookup?la=en&host=jamiehanki... for the actual code.
Never trust any input. I think this is a case where people assume that is isn't pure user input because is would have already been parsed/checked/verified.
"Oh, its in the DNS system so it must be safe" is worse then "well, it came from our database so it should be fine". Don't even trust something coming out of your own database. You never know what various input checking bugs might have accidentally let in over time.
Re: TXT Record XSS
#7Firefox needs to show the 'play' icon for the audio tag.
Re: TXT Record XSS
#8Re: TXT Record XSS
#9So uh. This works on a few websites. A couple I've found http://dig.whois.com.au/dig.php?dom=jamiehankins.co.uk&type=... http://mxtoolbox.com/SuperTool.aspx?action=txt:jamiehankins....
Re: TXT Record XSS
#10How does this work?