A fact from Self-XSS appeared on Wikipedia's
Main Page in the
Did you know column on 5 October 2014 (
check views). The text of the entry was as follows:
|
This article is rated Start-class on Wikipedia's
content assessment scale. It is of interest to the following WikiProjects: | |||||||||||||||||||
|
The article says "Facebook now displays a warning message when users open the Web developer console...". I thought that the "Web developer console" was a part of the browser software, not something specific to any website. How can Facebook (or any other website) detect when you open it? 86.161.61.32 ( talk) 13:08, 5 October 2014 (UTC)
The article suggests the web console, but I think the term is used for XSS where the user is the only one affected by content which is returned only to them. Or where the user is complicit in some way in inserting the code.
An example would be by using a malicious helpful copy button that puts the payload into the copy and paste buffer. When the user then pastes that into a vulnerable field.
SimonWaters ( talk) 08:38, 22 August 2018 (UTC)
A fact from Self-XSS appeared on Wikipedia's
Main Page in the
Did you know column on 5 October 2014 (
check views). The text of the entry was as follows:
|
This article is rated Start-class on Wikipedia's
content assessment scale. It is of interest to the following WikiProjects: | |||||||||||||||||||
|
The article says "Facebook now displays a warning message when users open the Web developer console...". I thought that the "Web developer console" was a part of the browser software, not something specific to any website. How can Facebook (or any other website) detect when you open it? 86.161.61.32 ( talk) 13:08, 5 October 2014 (UTC)
The article suggests the web console, but I think the term is used for XSS where the user is the only one affected by content which is returned only to them. Or where the user is complicit in some way in inserting the code.
An example would be by using a malicious helpful copy button that puts the payload into the copy and paste buffer. When the user then pastes that into a vulnerable field.
SimonWaters ( talk) 08:38, 22 August 2018 (UTC)