4 ms·
Loading all of jQuery seems a little bit excessive when the only thing they're using is the $.ajax function. http://youmightnotneedjquery.com/#request http://yo
by rmchugh 12y ago
Loading all of jQuery seems a little bit excessive when the only thing they're using is the $.ajax function. http://youmightnotneedjquery.com/#request http://youmightnotneedjquery.com/#request
- interdrift 12y agoOn which side are you ._.
- tomjen3 12y agoEngineers don't care what side anybody is on, as long as the tech works.
- hobs 12y agoReally? We knew the world would not be the same. A few people laughed, a few people cried, most people were silent. I remembered the line from the Hindu scripture, the Bhagavad-Gita... "Now, I am become Death, the destroyer of worlds." Any engineer worth his salt absolutely understands the consequences of their actions on the world. Sometimes they understand a bit too late.
- throwaway7767 12y ago> Engineers don't care what side anybody is on, as long as the tech works. Good engineers do care. Don't mistake "being an engineer" with "being apathetic".
- blar 12y agoIt's excessive if your goal is _solely_ to execute a repeating AJAX request. But, if I'm understanding the attack correctly, this script is injected _in place of_ jQuery requested from Baidu's CDN. If you want the affected sites to appear normal, so the users whose browsers you are highjacking will contribute to the DDOS for the longest possible period, then you want to ensure that jQuery does indeed load. The OP further clarifies why jQuery is injected _twice_: seems the injection is occurring only for 1% of requests. So it appears the code is looking to see if it has triggered the injection itself, and fires another request if needed.