Comment on page
Sniff Leak
- Do you work in a cybersecurity company? Do you want to see your company advertised in HackTricks? or do you want to have access to the latest version of the PEASS or download HackTricks in PDF? Check the SUBSCRIPTION PLANS!
This writeup leaks a text/plain because there is no
X-Content-Type-Options: nosniff
header by adding some initial characters that will make javascript think that the content is in UTF-16 so th script doesn't breaks.The next writeup leaks the script content by loading it as if it was an ICO image accessing the
width
parameter.- Do you work in a cybersecurity company? Do you want to see your company advertised in HackTricks? or do you want to have access to the latest version of the PEASS or download HackTricks in PDF? Check the SUBSCRIPTION PLANS!
Last modified 3mo ago