3 ms·
> Custom JS on your subdomains is a bad idea What is the difference between allowing users to put custom JS on a subdomain, vs. someone just opening up the dev
by tablatom 14y ago
> Custom JS on your subdomains is a bad idea
What is the difference between allowing users to put custom JS on a subdomain, vs. someone just opening up the developer console and running whatever JS they like? Does JS loaded from the server have different privileges to JS entered at the console?
- deleted 14y ago[deleted]
- homakov 14y agono difference. but running XSS in console is shooting your leg
- asafh 14y agoThe difference is, I can put custom JS on my Github page and send you a link, when you open it you run code I authored. Developer console is just me running code, and is also on any arbitrary domain on any site.
- tablatom 14y agoMy understanding of this article was that he pulled off the hack entirely by himself, without having to get someone to visit his page. Maybe I misunderstood.
- underwater 14y agoWhat you're referring to is a self-XSS. They were a lot more common back when you could run JavaScript from the address bar. These days if you try and paste JavaScript to your address bar (try it with: javascript:alert(1);) then the browsers try and stop you. Firefox just won't execute any JavaScript, even if you've manually typed it. IE and Chrome strip the "javascript:" prefix (but Chrome is vunerable if you type "j" and paste the remainder). More info here: https://www.facebook.com/photo.php?v=956977232793 https://www.facebook.com/photo.php?v=956977232793