5 ms·
This is why I love NoScript. Viewed it no problems and easily saw what you were doing. Pretty clever trick, thank you.
by Flam 15y ago
This is why I love NoScript. Viewed it no problems and easily saw what you were doing. Pretty clever trick, thank you.
- sedev 15y agoNoScript is the new antivirus, really.
- JoshTriplett 15y agoNo, NoScript acts more like a whitelist of executables permitted to run, with all others banned. Browser sandboxes themselves are the new antivirus. Or alternatively, NoScript is the new lynx. The problem shown in this example needs fixing in the browser, not by gutting the browser. This example just shows that "view source" should probably make it easier to get at the DOM-generated source. ("View Selection Source" or anything that shows the current DOM will work.)
- dfc 15y agoNoScript + RequestPolicy is awesome. RequestPolicy adds the "missing feature" in my opinion: context aware script loading.
- Zarel 15y agoI recently learned about a similar trick that gets around NoScript: http://citeomatic.com/_asdf.html http://citeomatic.com/_asdf.html (This one only works in Firefox and Opera, not Chrome, sadly)
- thinkalone 15y agoThat one's fun - I thought it was going to be more complicated and never considered the method you used :)
- Or1on 15y agoVery cool. With httpfox I got html:after { padding-left: 5px; content: 'Can you view my source from Firefox or Opera?'; } Edit: It's also possible to view the source with Firefox JSview, Web Developer addons and curl.
- dhx 15y agoNice trick. Spoiler: HTTP/1.1 200 OK Date: Mon, 19 Mar 2012 08:49:27 GMT Server: Apache Link: <_asdf.css>;rel="stylesheet";type="text/css";media="all" Content-Length: 0 Connection: close Content-Type: text/html; charset=UTF-8