3 ms·
Why the attacker will run the content loaded as an script instead of just dumping what they get? Edit: I think is the dataType: "script" part. From jquery docs
by jfroma 12y ago
Why the attacker will run the content loaded as an script instead of just dumping what they get?
Edit: I think is the dataType: "script" part. From jquery docs:
> "script": Evaluates the response as JavaScript and returns it as plain text.
- mckoss 12y agoThe JavaScript used is very amateurish with many outmoded features, poorly optimized. I couldn't believe they were loading jquery, for example. This looks to be the work of a script kiddie rather then a superpower's cyber warriors.
- slang800 12y agoOr a script kiddie working for a superpower.
- zagnut8088 12y agoI agree - but it might just be deflection. The Chinese could use the same argument to assert they bore no responsibility. Besides - everybody has jquery cached. Why create an ajax from scratch and add to the weight of the crap they are injecting into the script? For quick and dirty I like it. Its not exactly long term or really destructive - but its kind of a cute and clever attack. Github's response to pop an alert was priceless. Sure it probably annoyed the hell out of millions of Chinese people - and their government will probably claim Github attacked them --- but the truth will out... maybe. Totalitarian regimes are shady as hell.
- dandelany 12y agoThey have no choice. If they used an AJAX call it could be blocked by (lack of) ACAO headers. The only way to hit a remote URL that cannot be blocked is by adding a <script href="//github..." /> tag to the URL, which means the client has no choice but to run the contents.