Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
A popup that warns the users about the security implications? Or something fun like a rainbow background indeed
-
They're probably doing fairly basic stripping of html if they don't catch iframes. See if you can get a script to load in an obscure way ;)
-
If they block only <script>, could you use <img>'s onload attribute to, for example turn the page background into nyan cat gifs?
Related Rants
I have found a website that allows HTML in comments. They blocked <script>, but not <iframe>. I can just load a script from my personal website using it. What should i do?
(something innocent)
undefined
html
iframe
hack
security hole