Javascript protocol fuzz results
Published: Mon, 30 Jun 2008 11:32:06 GMT
Updated: Sat, 22 Mar 2025 15:38:10 GMT
Well it seems that Firefox 2.0.0.14 has provided the most interesting results with my protocol fuzzer.
<pre lang="html"> Char: 56320, link: jav�ascript: Char: 56321, link: jav�ascript: Char: 56322, link: jav�ascript: Char: 56323, link: jav�ascript: Char: 56324, link: jav�ascript: Char: 56325, link: jav�ascript: ,, ,, ,, ,, </pre>All the way to:-
<pre lang="html"> char: 57343, link: jav�ascript: </pre>and hex entities but with a semi-colon:-
<pre lang="html"> From: Char: 56320, link: jav�ascript: To: Char: 57343, link: jav�ascript: </pre>It means code like this works in Firefox 2.0.0.14:-
<pre lang="html"> [test](jav�ascript:al�ert%281%29) </pre>More oddities were found but nothing as interesting as the above.
The ever changing XML file can be found here which stores the vectors by platform and browser versions:-
Update...
Opera strangeness too...
<pre lang="html"> Char:2048,Link:javascriptࠀ: Char:2304,Link:javascriptऀ: Char:3328,Link:javascriptഀ: Char:3840,Link:javascriptༀ: Char:4096,Link:javascriptက: Char:4256,Link:javascriptႠ: Char:4352,Link:javascriptᄀ: Char:4608,Link:javascriptሀ: Char:4864,Link:javascriptጀ: Plus nbsp is allowed here:- Char:160,Link: javascript: </pre>There are more, higher ones too :)