- XSSing Your Way to Shell
- http://www.slideshare.net/HansMichaelVarbaek/xssing-your-way-to-shell
- https://speakerdeck.com/varbaek/xssing-your-way-to-shell
- Python (vBSEO Exploit)
- Firefox (Confirmed)
- WordPress http://wordpress.org/
- Better WP Security http://www.exploit-db.com/wp-content/themes/exploit/applications/c6d6beb3c11bc58856e15218d512b851-better-wp-security.3.5.3.zip
- WPSEO https://yoast.com/wordpress/plugins/seo/
- WordPress: Contains
xss.js
used during the live demo. - vBulletin: Contains the newest version of the
vbseo.py
- Hans-Michael Varbaek
- MaXe / InterN0T
- It works!
- WordPress
xss.js
has re-usable functions!