4 ms·
Yeah was curious about this as well.
by hnguy4 10y ago
Yeah was curious about this as well.
- bitexploder 10y agoIn truth they were likely exploiting a vulnerability in MethBot. Similar to XSS only server side. The legality of this, if my suspicion is correct is highly dubious, so they kept the details low key. I imagine somewhere in MethBots virtual DOM emulation they got sloppy and ran code (JS) from the server. Using metaprogramming plus some output they could predict they could use runtime reflection and inspect server side JS object.