I'm making my own antidote script.
It should be done in less than an hour.
Here's what it will support:
[flash]flash_url_here[/flash]
[youtube]id[/youtube]
[scratch=flash]GeonoTRON2000/2416215[/scratch]
Last edited by GeonoTRON2000 (2012-04-06 21:12:56)
Offline
It's done!
Download here: http://www.cfagency.org/antidote.user.js
EDIT: HTML has been disabled.
ENJOY!
Last edited by GeonoTRON2000 (2012-03-26 10:34:39)
Offline
GeonoTRON2000 wrote:
It now passively enables HTML.
For example:
<input type="text" value="You can't do this in BBCode." />
This is very insecure. That is why Rookwood101 didn't put that in his code (and also made it hard to hack the tags to add code too).
Offline
nathanprocks wrote:
GeonoTRON2000 wrote:
It now passively enables HTML.
For example:
<input type="text" value="You can't do this in BBCode." />This is very insecure. That is why Rookwood101 didn't put that in his code (and also made it hard to hack the tags to add code too).
Wassa da matta? Afraid of a little IFrame?
Offline
<script type="text/javascript">
while(true)
{
alert("Nah, just this sort of thing.");
}
</script>
Offline
It can embed projects...
<tested>
Last edited by Squawkers13 (2012-03-26 10:29:39)
Offline
[img]http://4.bp.blogspot.com/-_oUAdpmJXpM/T0rtXW6f5OI/AAAAAAAAC0A/YH8l3SEFo-k/s1600/testing-testing-123.jpg onload=javascript:alert("If you're seeing this in an alert box, the userscript isn't secure.");[/img]
Edit: I don't see an alert box. I guess it's secure.
Last edited by zippynk (2012-03-26 10:52:34)
Offline
Hardmath123 wrote:
<script type="text/javascript">
while(true)
{
alert("Nah, just this sort of thing.");
}
</script>
That's why you use Chrome -- it blocks multiple dialogue boxes!
Offline
LS97 wrote:
Hardmath123 wrote:
<script type="text/javascript">
while(true)
{
alert("Nah, just this sort of thing.");
}
</script>That's why you use Chrome -- it blocks multiple dialogue boxes!
![]()
FF gives you the option to stop them, but sometimes you want a few.
zippynk wrote:
http://4.bp.blogspot.com/-_oUAdpmJXpM/T … e.')"
Edit: I don't see an alert box. I guess it's secure.
Try now.
Offline
<image>
http://4.bp.blogspot.com/-_oUAdpmJXpM/T0rtXW6f5OI/AAAAAAAAC0A/YH8l3SEFo-k/s1600/testing-testing-123.jpg onload=javascript:alert("If you're seeing this in an alert box, the userscript isn't secure.");
<image>
Offline
Squawkers13 wrote:
<image>
http://4.bp.blogspot.com/-_oUAdpmJXpM/T0rtXW6f5OI/AAAAAAAAC0A/YH8l3SEFo-k/s1600/testing-testing-123.jpg onload=javascript:alert("If you're seeing this in an alert box, the userscript isn't secure.");
<image>
Actually, the BBCode is img, and so is the HTML tag.
[img]http://4.bp.blogspot.com/-_oUAdpmJXpM/T0rtXW6f5OI/AAAAAAAAC0A/YH8l3SEFo-k/s1600/testing-testing-123.jpg onload=javascript:alert("If you're seeing this in an alert box, the userscript isn't secure.");[/img]
Offline
New scratch tag in the new version!
[scratch=flash]user/projectId[/scratch]
Last edited by GeonoTRON2000 (2012-04-12 23:09:09)
Offline
Do you think you could not call it antidote?
And also I don't see why you feel the need to remake something that has already been made, without adding any new features (well a few but not many) and it writing such an insecure version.
Last edited by rookwood101 (2012-03-27 11:15:03)
Offline
[img]http://www.silentrunners.org/graphics/sr/sr_5.gif" onload="alert('If you\'re seeing this in an alert box, the userscript isn\'t secure. Your password cookie: ' + document.cookie + 'I could quite easily send this to a third party source');[/img]
Last edited by rookwood101 (2012-03-27 11:24:38)
Offline
GeonoTRON2000 wrote:
Teehee. New version. All onloads disabled.
Did you disable the <script /> and <iframe />? (Yes, in-line frames can run JS too lol.)
Offline
This discussion is continued here: http://geonotron.net84.net/forums/viewt … =6&t=3
Offline
GeonoTRON2000 wrote:
This discussion is continued here: http://geonotron.net84.net/forums/viewt … =6&t=3
Why?
Offline
rookwood101 wrote:
GeonoTRON2000 wrote:
This discussion is continued here: http://geonotron.net84.net/forums/viewt … =6&t=3
Why?
'Cuz this might be considered spam or something and this topic is likely to be closed.
Offline