4 ms·
My favorite thing about VBScript is how long it stayed around in IE. If it was IE6, ok, you could forgive it. But in a limited form it was there until IE10. IE
by billyhoffman 6y ago
My favorite thing about VBScript is how long it stayed around in IE. If it was IE6, ok, you could forgive it. But in a limited form it was there until IE10. IE8 and IE9 would try and be "smart" and would figure out text was VBScript and execute it, even without a "lang" attribute. In fact, I used VBScript in some XSS attacks because it often evaded security filters due to how different the syntax was from JavaScript. It was also case insensitive, which helped it survive mutations on the input.
VBScript and other proprietary web nonsense the browser makers put into HTML/JS/CSS during the browser wars (looking at you HTML+TIME) created a ton of remotely accessible and poorly implemented surface to attack.
- TedDoesntTalk 6y agoDo you mean the TIME tag/element in html? What are the vulnerabilities with it? Asking out of genuine curiosity...