Can XSS attacks be executed from a linked stylesheet?

Possible duplicate:
Scripts on sites in CSS styles

I am considering creating my own CSS using related style sheets (NOT inline style tags). Is it possible to perform an XSS attack from a stylesheet?

thank

+5
source share
3 answers

In Internet Explorer , Firefox, and other browsers, it can embed JavaScript in CSS by providing a URL javascript:in a url()CSS statement .

, ( ) CSS. , XSS. , Delete Account " , 1000 $".

white-list (text-*, font-*, color, background ( , URL- )), , .

+3

. , , . , : after : before, .

, , , - .

0

these are old hacks, but they can work in an older browser, for example, you can put the javascript protocol in href attr.

http://ha.ckers.org/xss.html (style search)

0
source

All Articles