My Node.js app, or, a simple explanation of asynchronicity and non-blocking IO
maryrosecook.com
maryrosecook.com
After discovering that there's no XSS protection what so ever, the fun really started. I'm still sorry about that location.href='http://microsoft.com, but using a browser with JS disabled, we managed to find out how the script posts the message and were able to fix it that way.
Of course, then the "funny" people began crashing browsers using various methods.
That's when my coworker and I came up with the idea of fixing the hole by patching window.updateMessage, so everyone who was on the site when we were doing that was protected against further attempts at crashing browsers.
Now if we could have XSS protection built-in, this could really be so much fun. The "discussions" going on before the exploiting started all around were really funny.
I'll be keeping an eye on the site during the afternoon. Only three restarts in three hours! Woo.
I just checked and made sure it is still working as it is suppose to (Firefox + Safari). Ill try Chrome as well.