How does Facebook disable Developer Tools?
stackoverflow.com
stackoverflow.com
I'd consider this a genuine security issue, and wouldn't be surprised if the dev console at least got moved behind a lot more 'here be dragons' warnings.
or hide it behind a turing-test-for-engineers ... 'solve the following code test to enable the dev console' ;)
Another place where you see this sort of thing: banks that try to prevent password managers from filling in your credentials (also I've seen a few recently that try to prevent you from pasting in your password).
There is a tradeoff there too: like this Facebook trick helping save some users, bank tricks probably help some users from accidentally saving their bank credentials on some public or shared computer, but it makes it really annoying (or not possible short of opening devtools and setting the input box's value manually) for those of us that want a unique and more-or-less random password for each site we visit.
It's neat for small changes as you don't have to write a whole extension just a simple script.
javascript:alert('hi ' + document.body.innerHTML);
If people can be tricked into executing code in the dev console, then why not this too?edit: Ooops, someone had already made a post to this effect. Sorry.
I speak from someone who teaches ruby and javascript. Javascript is in every browser and the console is a wonderful place to start. When I teach ruby (on Mac's) I have to start with, "well ok, now download xcode". It's really easy for someone to give up before getting everything working.
And "when I teach ruby", "well ok, now download xcode"... ok, Xcode is a 2.5GB download, but it is a one click download and install via App Store. And really? Xcode for Ruby? Are you really doing that?
Also instead of downloading the whole xcode you can download the xcode cli tools.
Mac OS X comes with Ruby already installed, and afaik you don't need a C compiler to learn standard ruby, you'd only need it for certain gems (which want to build native extensions).
Standard Ruby development generally involves both a Ruby version manager (rvm, rbenv, etc.) and the ability to install gems with native extensions.
The latest version of OS X comes with Ruby 2.0, which is hardly obsolete, and that or Ruby 1.8.7 (from earlier OS X) is totally fine for learning to use Ruby, which is how this thread started.
Claiming you need to start to learn by installing xCode or the tools is false - there is lots more to ruby than installing rvm, rails and sql gems etc. Beginners could go a long way without requiring non-native gems, and by the time they get to that stage, installing Ruby 2.0 should be a breeze, whatever route you choose.
Probably over 95% of mac users would never use the compiler, so I see why they left it out. Installing it is really very easy anyway, command line or with xcode.
xcode-select --install
on (Mavericks) Terminal.This has been called the "dancing monkeys problem". People can really be manipulated into doing anything in order to see the dancing monkeys (even if they couldn't be convinced to do those things for constructive purposes).
IMHO you just can't save people from themselves, might as well stop trying and making my life harder.
Never seen it called "dancing monkeys" - got a cite?
Here, to be honest, I vote for natural selection. Fight the scammers, and let the gullible be scammed until the society develops an immune response. It happens all the times, and I think that at least a part of the solution for Internet scam is to accelerate immune response development as much as possible.
Safari does this
Object.defineProperty(console, '_commandLineAPI',
{ get : function() { throw 'Nooo!' } })
But why isn't it enough?(which I have done, under another username)
Edit: I'm wrong. Need some sleep.
function escape(s) {
// Bonus level!
Object.defineProperty(console, 'foo',
{ get : function() { throw 'nooo!' } });
var code = 'with(window.console && console.foo || {}) {\n\t'+s+'\n}';
console.log(code);
try {
console.log(eval(code));
} catch (e) {
console.log(e);
}
}
The idea is, you need to craft `s`, such that `s` can execute arbitrary code without throwing 'nooo!'.
The interesting problem is, any access to `console.foo` with throw because the getter above is called. This includes the access inside the `with` statement. So the solution, if there is any, must
somehow cause mutation of state before the `with` even executes.Now, what brought me to the solution was this thought: "What in Javascript allows you to execute code before a given statement?" Upon framing it in this way, the solution became immediately clear: function declarations are automatically hoisted!
If you redefine `console` to be an object without the property 'foo', the `|| {}` part of the with predicate will instead be passed as the scope, and you have free reign to walk about the system.
So the solution is:
alert(1) } function console(){} {
Which produces the statement: with(window.console && console.foo || {}) {
alert(1) } function console(){} {
} function window(){alert(1)}window()
To those of you going for the code golf record, you can save a character in STRML's solution by redefining window instead. Furthermore, the last two braces can be omitted and whitespace removed for a total of 27 characters.It's the same as taking a bunch of code you have no idea how works, and paste it into CMD, then wondering why you just deleted C:/
:-)
It's the user password of an admin user. What other password can it possibly ask for? a global su password?
I hate the web