3 ms·
Sidenote: does anyone know why all these cancer scripts use this approach of using an initial Javascript payload to create a `script` tag, instead of just being
by Rjevski 8y ago
Sidenote: does anyone know why all these cancer scripts use this approach of using an initial Javascript payload to create a `script` tag, instead of just being a `script` tag directly?
- m3talsmith 8y agoOne thing I can think of is trying to avoid caching.
- toyg 8y agoProbably to dictate precisely when they get loaded, rather than relying on browser behaviour.
- etaioinshrdlu 8y agoA injected script element was last I checked the only way to send a piece of data to a remote server on a third party domain without a preflight OPTIONS request. Less round trips. Less bandwidth. For more reading look here:http://dev.housetrip.com/2014/04/17/unleash-your-ajax-requests-with-cors/ http://dev.housetrip.com/2014/04/17/unleash-your-ajax-reques... But in general here's what is wanted. - No OPTIONS request - Third party domain. - withCredentials - pass cookies in the request. The best option in this case is actually a injected async script element. Source: worked in ad tech a few years ago. Looked into all the possible options, this came up least bad, and explained why it was so popular.
- lancefisher 8y agoThat's right. Check out JSONP for more info: https://en.wikipedia.org/wiki/JSONP https://en.wikipedia.org/wiki/JSONP This was really common before CORS.
- Vinnl 8y ago> The best option in this case is actually a injected async script element. I thought dynamically injected script elements were async by default? https://developer.mozilla.org/en-US/docs/Web/API/HTMLScriptElement#Dynamically_importing_scripts https://developer.mozilla.org/en-US/docs/Web/API/HTMLScriptE...
- ceejayoz 8y agoA direct script tag loads synchronously. This technique does not. In modern browser you can just do <script async>.
- batiste 8y agoEdit: I answered completely off base. Misunderstood the question. My hunch on the original question: Maybe some system only allow injected JS? Wordpress anyone? Not quite sure. Yes, I learned it not so long ago in fact and I am a bit ashamed of it. Try to save this into a HTML file: <html> <body> <script> let someJSON = {"hello": "</script><script>alert('powned')</script>"} </script> If you execute just the JavaScript in your browser console: perfectly fine, valid JS. Now open the HTML file in a browser: powned. This the because the browser has a HTML parsing phase, and only after JS is executed. When <script> is parsed, then the HTML parser is looking for the next </script>. It doesn't matter if the </script> happened to be inside the context of a JavaScript string. At this point the browser doesn't know about JS.