Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
Snetry
82 days ago
|
parent
|
context
|
favorite
| on:
XSS –> RCE in Screeps, a programming game on Steam
the issue isn't that a user can be convinced into running `console.log(“<script>hackMe()</script>”)` but that `console.log(creep.name)` may execute hackMe() without you expecting it.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: