🎉 Giveaway Alert! 🎉
Hello everyone, I’m giving away 10 students passes for @bsidesahmedabad.
Just comment below why you wanna attend the event and like the tweet.
Good luck.
🎉 Giveaway Alert! 🎉
Hello everyone, I’m giving away 10 students passes for @bsidesahmedabad.
Just comment below why you wanna attend the event and like the tweet.
Good luck.
@0xMstar@krishnsec@zseano@Tur24Tur You can try encoded html entity in between
jav%26Tab%3bscript://google.com/%0dalert(1)
(	 —> %26Tab%3b)
Only if the above value is reflecting on href link.
or try %0c in between the javascript protocol.
@carbonmanx@zseano The element "style" will trigger the above event handler as the content-visibility has been as auto. Using double quotes and adding "style element will trigger above XSS.
If you see a site with " _layout/*" endpoints or in source code, then it runs on Microsoft SharePoint.
Here is the API endpoint list that you can still test:
https://t.co/yyToGbDmaN
It's a complete list but you can still check out Microsoft sharepoint documentation.