3 ms·
From looking at the JavaScript snippet that is provided, it looks like I can get around the validation by simply creating a cookie who's contents is "validated=
by aewens 8y ago
From looking at the JavaScript snippet that is provided, it looks like I can get around the validation by simply creating a cookie who's contents is "validated=yes" before the qeys script is loaded.
EDIT: The part of the snippet in question:
window.addEventListener('load', function(a){
document.cookie.indexOf('validated=')<0&&v();
});
- eat_veggies 8y agoI can confirm that this completely stops qeys from even sending a request on the page I'm testing it on. However, any client side protection can be bypassed, especially if your adversary has write access to the code you're trying to protect. Maybe as an additional protection, qeys should, say, 1 in 7 [0] times, send a request regardless of whether the cookie present. [0] https://en.wikipedia.org/wiki/Morris_worm https://en.wikipedia.org/wiki/Morris_worm
- frits1993 8y agoYou could indeed do that. I really like eat_veggies' suggestion, something I'll consider.