Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
0 points
lostmsu
7mo ago
0 comments
Share
What's the hole? Neither appear to say.
undefined | Better HN
0 comments
default
newest
oldest
throwaway290
7mo ago
I guess that obfuscated JS in SVG runs? Then it downloads the script that does shady stuff
lostmsu
OP
7mo ago
That does not explain exactly what is wrong. The site could already run JS. It did not need SVG to do it.
throwaway290
7mo ago
Yeah I guess the original article is not clear on that. Other cases usually involved email but this is not
j
/
k
navigate · click thread line to collapse