Search K
Appearance
Appearance
Other ways to support HackTricks:
This writeup leaks a text/plain because there is no X-Content-Type-Options: nosniff
header by adding some initial characters that will make javascript think that the content is in UTF-16 so th script doesn't breaks.
The next writeup leaks the script content by loading it as if it was an ICO image accessing the width
parameter.
Other ways to support HackTricks: