3 ms·
I believe Chrome shows the original source because when you View Source, it requests the page again. This complicates debugging Ajax requests (and also Get and
by HNatWORK 15y ago
I believe Chrome shows the original source because when you View Source, it requests the page again. This complicates debugging Ajax requests (and also Get and Post requests).
Firefox and IE show the "current" source, which is liable to be replaced as shown by dave1010uk.
Type the following into the Chrome Dev Tools console, then the Firebug console:
testBool = true;
document.write('');
typeof testBool;
Chrome shows boolean, firefox shows undefined.
- cmelbye 15y agoI think that's correct about Chrome. If you want to see the "current" source, the Web Inspector is the way to go.
- JoachimSchipper 15y agoNote that re-downloading the source prevents this attack, but does not mean that the source you are looking at is what the page is actually running - just make the web server leave out the reference to evil.js the second time an IP address requests the page...
- knotty66 15y agoI wondered if there is anything different about the second (view source) request that could be detected and a different response provided - but I don't think so after a quick look with WireShark.
- sesqu 15y agoWell, you could set up a temporary client blacklist based on cookies or IP addresses.
- Tsagadai 15y agoIf you right click in Chrome for 'inspect element' you also get disappearing source code.
- nightpool 15y agoThe Firefox plugin Web Developer let's you set an option (View source in tab) that makes it work like the Chrome view source.