Firefox and IE's "View source" can be spoofed to show anything
scriptjunkie.us
scriptjunkie.us
Firefox and IE show the "current" source, which is liable to be replaced as shown by dave1010uk.
Type the following into the Chrome Dev Tools console, then the Firebug console:
testBool = true;
document.write('');
typeof testBool;
Chrome shows boolean, firefox shows undefined.[1]: https://webcache.googleusercontent.com/search?q=cache:http:/...
It works in Firefox 6, not sure about any other browsers. If you want to see the actual source, disable JavaScript (or use Chrome or curl).
Ctrl/Cmd-u can also be used to view source in Firefox.
I think it's more a question of what do you expect to see when you "View Source". For example, I have messed around with document.write a lot and it's pretty obvious to me that, if I use view source then it's going to give me the source and any changes done to it my document.write/open/close. In this case since document.write is used after HTML parsing has been completed it replaces the whole page and thus makes view source rather pointless.
- To see the original source, hit ctrl-u before dismissing the alert.
- To see the "hybrid" source, hit ctrl-u after dismissing the alert. I always expected this to be idential to what the webserver sent, just syntax highlighted. (Though I haven't messed around with document.close before.)
- To see the generated source, hit ctrl-a, right click & "View Selection Source". This is different to the original/hybrid source as Firefox inserts html tags to make the page valid. My example had no html, head, title or body tags. This should reflect the current page DOM, as affected by any JavaScript.
It could be your browser blocking sequential alerts or some strange caching issue.
I'd have a more substantial comment, I hope, if the site was loading.
If anyone happens to load this elusive "View Source Spoof" page, please leave a nice detailed description for the rest of us.
Our minds can draw the pictures :)
https://webcache.googleusercontent.com/search?q=cache:http:/...
Server side user agent discrimination is a good point. One has have the option to send his or her own lies regarding that, though. There's always a a way to follow whatever script path to its various ends...
fetch http://jcs.org/tmp/nothing.html through curl:
jcs@air:~> curl -s http://jcs.org/tmp/nothing.html
there is really nothing here, i can promise you that.
but you just aren't seeing the content. jcs@air:~> curl -s http://jcs.org/tmp/nothing.html | vis
View source in Firefox. \^H\^H\^H\^H\^H\^H\^H\^H\^H\^H\^H[...] curl http://jcs.org/tmp/nothing.html | vim -The best way to access downloaded source is probably with JavaScript turned off.
I especially don't understand this part:
When you use document.write outside of a script tag embedded inline in
the page [...]
What is "outside of a script tag embedded inline in the page" supposed to mean? setTimeout(function() {
document.write('foo');
document.close();
}, 1);
[1] http://taskthere.com/viewsource/It will be effective at blocking the Flash-like HTML ads that are going to pop up soon as well. Unless they get really creative with CSS.