Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I just call alert('dada') from the console, and it tells me congratulation the site is buggy as well


The victim of your XSS attack will not use the console, so when creating a XSS attack it shouldn't require the use of the console to activate it.

I can break any website for myself by putting stuff in the console.


Kinda not within the spirit of the exercise don't you think.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: