English 中文(简体)
XSS on jsbin.com
原标题:

Anyone know if jsbin.com implements any protection for XSS or other javascript attacks?

I see jsbin links used fairly regularly on sites like this one and I can t find any indication from the site one way or another. If it does implement counter measures, what kinds of things does it block out. If not, I should probably be more careful about which links I choose to click.

最佳回答

I guess an unfriendly script could do a denial of service on jsbin by continually scripting a ‘save to public URL’ submission to clog the database up. And of course anyone could post a security hole exploit script which would infect people with old browsers and plugins; that might also get jsbin on Google s blocklist.

That s about all though... there are no user credentials to steal or nefarious things to do with people s accounts and privileges because there are no accounts or privileges.

I should probably be more careful about which links I choose to click.

Yes, that seems reasonable.

问题回答

暂无回答




相关问题
selected text in iframe

How to get a selected text inside a iframe. I my page i m having a iframe which is editable true. So how can i get the selected text in that iframe.

How to fire event handlers on the link using javascript

I would like to click a link in my page using javascript. I would like to Fire event handlers on the link without navigating. How can this be done? This has to work both in firefox and Internet ...

How to Add script codes before the </body> tag ASP.NET

Heres the problem, In Masterpage, the google analytics code were pasted before the end of body tag. In ASPX page, I need to generate a script (google addItem tracker) using codebehind ClientScript ...

Clipboard access using Javascript - sans Flash?

Is there a reliable way to access the client machine s clipboard using Javascript? I continue to run into permissions issues when attempting to do this. How does Google Docs do this? Do they use ...

javascript debugging question

I have a large javascript which I didn t write but I need to use it and I m slowely going trough it trying to figure out what does it do and how, I m using alert to print out what it does but now I ...

Parsing date like twitter

I ve made a little forum and I want parse the date on newest posts like twitter, you know "posted 40 minutes ago ","posted 1 hour ago"... What s the best way ? Thanx.

热门标签