cookiefun! ?xss=undefined//vascr Goal: alert(document.cookie) // extract the PHPSESSID, FF3.6 - 4 only!

Results available here!

Oh - and it's more tricky than it looks...and that's not even my fault
The shorter the better, challenge ends when shortest way was found

Valid submissions (send me the cookie data!) will be listed by me in this very document
  1. Jonas Magazinius & machaira9 - 27 characters (05.05.2011 and 08.05.2011)
  2. base64 - 32 characters (08.05.2011 10:56)
  3. Tristan Larouanne - 39 characters (10.08.2011 11:43)
  4. Gareth Heyes - 40 characters (06.05.2011 15:50)
  5. Mauro Gentile - 44 characters (06.05.2011 16:38)
  6. Phil Purviance - 51 characters (05.05.2011 0:51)
  7. Joey Tyson - 57 characters (09.05.2011 19:24)
  8. Erlend Oftedal - 65 characters (10.05.2011 13:38)
  9. Rishi Narang - 68 characters (09.05.2011 9:41)
  10. Kyle Osborn - 73 characters (05.05.2011 20:20)
  11. Norman Hippert & Nils-Helge Garli Hegvik - 82 characters (09.05.2011 17:50, 10.05.2011 13:17)
  12. Torgeir Thoresen - 83 characters (06.05.2011 9:06)
  13. Taz - 83 characters (06.05.2011 16:50)
  14. Neal Poole - 126 characters (07.05.2011 8:49)
  15. Niko Thome - 249 characters (06.06.2011 8:04)
  16. Stefano Di Paola - 277 characters (05.05.2011 13:37)
Oh and... <script>window.name='payload()' is considered to be a bit lame :)