Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Injecting an iframe into websites could trigger an assertion error, because the iframe isn't supposed to be there.


Hi, that's right. Some sites protect html injection. Twitter protects their site very well, but if you use http tunneling they can't do nothing as you can modify X- headers.


Interesting, could you explain what you mean by http tunneling and how it can bypass protection against html injection?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: