4 ms·
Since the site seems to be down, you can read the article (no images unfortunately) in Google's Cache[1]. [1]: https://webcache.googleusercontent.com/search?q=
by xorglorb 15y ago
Since the site seems to be down, you can read the article (no images unfortunately) in Google's Cache[1].
[1]: https://webcache.googleusercontent.com/search?q=cache:http://www.scriptjunkie.us/2011/09/original-source-forgery/&hl=en&strip=1 https://webcache.googleusercontent.com/search?q=cache:http:/...
- dave1010uk 15y agoI've recreated a simple proof of concept here: http://taskthere.com/viewsource/ http://taskthere.com/viewsource/ It works in Firefox 6, not sure about any other browsers. If you want to see the actual source, disable JavaScript (or use Chrome or curl).
- tspiteri 15y agoTo see the actual source in Firefox 6, I just viewed the source without dismissing the alert, there was no need to disable anything. The only thing is that with the alert, I couldn't right click on the page and click on "View Page Source", I had to use the menu item Tools: Web Developer: Page Source (or its keyboard shortcut).
- dave1010uk 15y agoI used an alert as a quick example. You could put any HTML or JS on the page (e.g. links for SEO value, iframes with PDF exploits, a bitcoin miner or a video of Rick Astley) and when someone views the source it looks like there's nothing malicious. Ctrl/Cmd-u can also be used to view source in Firefox.
- fgaaghf 15y agoIf you want to view the current HTML source in Firefox you can use Ctrl+A and then right-click > "View Selection Source". I think it's more a question of what do you expect to see when you "View Source". For example, I have messed around with document.write a lot and it's pretty obvious to me that, if I use view source then it's going to give me the source and any changes done to it my document.write/open/close. In this case since document.write is used after HTML parsing has been completed it replaces the whole page and thus makes view source rather pointless.
- dave1010uk 15y agoThis bug isn't showing the usual generated source but some kind of hybrid between original source and generated source. - To see the original source, hit ctrl-u before dismissing the alert. - To see the "hybrid" source, hit ctrl-u after dismissing the alert. I always expected this to be idential to what the webserver sent, just syntax highlighted. (Though I haven't messed around with document.close before.) - To see the generated source, hit ctrl-a, right click & "View Selection Source". This is different to the original/hybrid source as Firefox inserts html tags to make the page valid. My example had no html, head, title or body tags. This should reflect the current page DOM, as affected by any JavaScript.
- tspiteri 15y agoMy intention was to suggest an easy way to view the actual source. I think your example is actually better as an example as it is easy to see the source both before and after the function is called.
- Dobbs 15y agoIf I use pentadactyl's `gf` I get the source with the alert. If I right click I get the intended result.
- estel 15y agoPeculiar: in FF5 I don't see the alert, but do see it in view source.
- AndyKelley 15y agoWhen I refresh the page, I don't see the alert again. Did you even check any referrers, or just set a flag to only show the alert once?
- dave1010uk 15y agoNope, it's incredibly basic, just the HTML you see. I wrote the code on my phone and didn't have time to do anything like that. Here's the source: http://i.imgur.com/zV937.png http://i.imgur.com/zV937.png - it should work served as a local file too. It could be your browser blocking sequential alerts or some strange caching issue.