| OLD | NEW |
| (Empty) |
| 1 CONSOLE MESSAGE: Blocked a frame with origin "http://127.0.0.1:8000" from access
ing a frame with origin "http://localhost:8000". Protocols, domains, and ports m
ust match. | |
| 2 CONSOLE MESSAGE: line 1: TypeError: 'undefined' is not an object (evaluating 'ta
rget.document.body') | |
| 3 This page opens a window to "", injects malicious code, and then navigates its o
pener to the victim. The opened window then tries to scripts its opener after re
loading itself as a javascript URL. | |
| 4 Code injected into window: | |
| 5 <script>window.location = 'javascript:\'<script>function write(target, message)
{ target.document.body.innerHTML = message; }setTimeout(function() {write(window
.opener, \\\'FAIL: XSS was allowed.\\\');}, 100);setTimeout(function() {write(wi
ndow.opener.top.frames[1], \\\'SUCCESS: Window remained in original SecurityOrig
in.\\\');}, 200);setTimeout(function() { if (window.testRunner) testRunner.globa
lFlag = true; }, 300);<\\\/script>\''</script> | |
| 6 | |
| 7 | |
| 8 -------- | |
| 9 Frame: '<!--framePath //<!--frame0-->-->' | |
| 10 -------- | |
| 11 This page doesn't do anything special (except signal that it has finished loadin
g). | |
| 12 | |
| 13 -------- | |
| 14 Frame: '<!--framePath //<!--frame1-->-->' | |
| 15 -------- | |
| 16 SUCCESS: Window remained in original SecurityOrigin. | |
| OLD | NEW |