4 ms·
<script id="test"> E = (function() { var F = function(x) { var secret = 42, key = 0xC0C0ACAFE; return x===
by columbo 13y ago
<script id="test">
E = (function() {
var F = function(x) {
var secret = 42, key = 0xC0C0ACAFE;
return x===key ? secret :0
};
return function G_F(x) {
console.log(document.getElementById("test").innerHTML.split("secret")[1].substr(3,2));
return F(x>>>0);
}
})();
E();
</script>
The above is very hacked together... does this break the security? Or am I misreading this?
- tlrobinson 13y agoI'm not sure, but I think if it's loaded from an external file there's no way to get at the text of script.
- fooyc 13y agoUsually the script would be remote (script src="..."), and the same origin policy would prevent you from getting its source in a similar way.
- columbo 13y agoAh! Ok that makes more sense then