Weve all known that the main problem of constructing XSS attacks is how to obfuscate malicious code. In the following paragraphs I will attempt to explain the concept of bypassing script filters with variable-width encodings, and disclose the applications of this concept to Hotmail and Yahoo! Mail web-based mail services.