Email or username:

Password:

Forgot your password?
XSS~1.BUN :blobhaj_hearttrans:

Put ๏ฟฝ in random text fields so that developers are always wondering if they screwed up parsing somewhere.

43 comments
Erica Briony.

@xssfox for a brief moment I thought I should have it as part of my legal name

12 Lilith it/its๐’€ญ๐’ˆน๐’ ๐’Šฉ

@steadilyebbing @xssfox we're gonna change our legal name to Lilith Erica Freya ๐’‚—๐’ƒถ๐’ŒŒ๐’€ญ๐’ˆพ <unknown last name>

Colin

@xssfox STICK TO CROSS SITE SCRIPTING YOU MONSTER

DELETED

@xssfox thoughts on instead creating chaos with ๏ฟผ ?

Alastair McBain :unverified:

@secoops @xssfox How do those get into posts?

I imagine it's a copy-and-paste thing but no idea.

I don't know why they don't get filtered out when the user hits post.

DELETED

@asmcbain @xssfox

I'm guessing given it's just a unicode character, it's considered a valid character and no different to the other fun ones like: โ˜  โœ– โ˜ข โ˜ฃ

.:/ DiSCATTe \:.

@xssfox don't forget to urlurlurlurlencodeencodeencodeencode for data resiliency http%2525253A%2525252F%2525252Fdiscatte.github.io

Alastair McBain :unverified:

@discatte @xssfox I had a job posting that septuple escaped '(' and ')' from the job title to create the URL slug.

I had to file it, and my state's firewall decided it was malicious and blocked me from adding it to my list. ๐Ÿ˜…

Simon (a ๐Ÿฎ in ๐Ÿ‡ณ๐Ÿ‡ฟ)

@xssfox Don't worry, I wonder if I screwed up something either way.

via unreachable

@xssfox I like showing people's projects to my friend Josรƒยฉ (null) [object Object]

groxx

@xssfox I occasionally end my emails with a J, just to screw with people that I know will notice

embix

@xssfox @lisamelton and sprinkle in some zalgo text, while youโ€™re at it

Menno

@xssfox
Ooh! Elon, are you listening?
Someone came up with a new name for your next kid.

Torben

@xssfox One can still improve "Put ๏ฟฝ in random text fields" - in text fields or labels that always have the same text, put ๏ฟฝ into random places, different ones each time.
Parsing errors suck but intermittent, seemingly random parsing errors from same input drive devs insane! Muhaha.

8941dc91-867e-4412-afd5-4698d32477be

@xssfox
Always try to keep the ๏ฟฝ at the beginning or end of your string

Michael Westergaard
As the saying goes: life is a battle between developers trying to develop idiot-proof software and the universe trying to produce bigger idiots. This is a lovely new front of this very real and important conflict.
Dreit

@xssfox Lorem ipsum dolor sit amet, consectetur adipisici elit, sed eiusmod tempor incidunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquid ex ea commodi consequat. Quis aute iure reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint obcaecat cupiditat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Taya Nielsen

@xssfox ๐Ÿ˜๐Ÿ˜๐Ÿ˜๐Ÿ˜๐Ÿ˜

Kyle Brown

@xssfox I just assume you copied something from word and your smart quotes got messed up

Alix

@xssfox That's straight up evil. I love it.

Go Up