The Spanner logo
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    • Home
    • Blog
      • Blog home
      • RSS
    • Login
    The Spanner logo

    The Spanner
    Web security blog

    Made by Gareth Heyes
    Follow me on Twitter: @garethheyes

    Javascript for hackers!

    Hackvertor logo
    Shazzer logo
    My Github account
    Recent posts
    Introducing Feedworm: A Privacy-First RSS Reader That Lives in DevToolsSpeedy RSVP extensionAutoVaderHackvertor history and tag finderShadow Repeater v1.2.3 releaseBurp Hackvertor v2.1.24 releaseHacking roomsXSSing TypeErrors in SafarivalueOf: Another way to get thisMaking the Unexploitable Exploitable with X-Mixed-Replace on FirefoxThe curious case of the evt parameterCSS-Only Tic Tac Toe ChallengeRewriting relative urls with the base tag in SafariBypassing DOMPurify with mXSSNew IE mutation vectorHow I smashed MentalJSMentalJS DOM bypassAnother XSS auditor bypassXSS Auditor bypassBypassing the IE XSS filterUnbreakable filterMentalJS bypassesmXSSJava SerializationBypassing the XSS filter using function reassignmentRPOSandboxed jQueryX-Domain scroll detection on IE using focusEpic fail IEnew operatorDecoding complex non-alphanumeric JavaScriptHacking FirefoxDOM ClobberingBypassing XSS AuditorThe evolution of codeNon-Alpha PHP in 6-7 charsetTweetable PHP-Non AlphaMentalJS for PHPOpera x domain with video tutorialSandboxing and parsing jQuery in 100ms

    Epic fail IE

    By Gareth Heyes (@hackvertor)

    Published 12 years 6 months ago • Last updated March 22, 2025 • ⏱️ < 1 min read

    ← Back to articles

    gaz: omg more epic fail in IE :D

    larry: huh? :D

    gaz: what is "&#x0000041;" in IE compat?

    larry: hm A?

    gaz: no

    larry: ?

    gaz: lol ?

    larry: NUL ?

    gaz: &#x0000041; --> ? &#x000041; --> A

    larry: ah! out of bounds I get it

    gaz: what is this in IE compat: &#x41

    larry: :-h A?

    gaz: no lol &#x41 --> &#x41

    larry: #!$% me! :D why??

    gaz: hahahhaha what is &#x41 in standards?

    larry: A ?

    gaz: yeah haha

    larry: weeee

    gaz: how messed up is that? :D

    larry: entirely as usual :)

    ← Back to articles