@0x6D6172696F Well, depends - if there's a broken server-side XSS filter, you can probably use that to bypass the client-side one?
@0x6D6172696F Like if it strips <script>, you do <img onerror="alert<script>(1)" src=x>. should bypass chrome's filter afaik
12:32 PM - 14 Jul 2015
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.