Re: A perfect DOM sandbox

On 15 February 2011 07:54, Boris Zbarsky <> wrote:

> On 2/15/11 2:40 AM, wrote:
>>     if(navigator.userAgent.match(/Firefox/))
>>         ifr.setAttribute("src","/xss.php?csp&plain_text");
> What's the point of that?

He sets the url to a script which has CSP enabled to provide same origin

     try {
>         ifr.contentDocument.documentElement.innerHTML=src;

Given that you immediately do this?

I think you might be confused with sdc's naming conventions, "src" actually
refers to the source code supplied not the url of the iframe.

Received on Tuesday, 15 February 2011 10:06:42 UTC