Ranter
Join devRant
Do all the things like
++ or -- rants, post your own rants, comment on others' rants and build your customized dev avatar
Sign Up
Pipeless API
From the creators of devRant, Pipeless lets you power real-time personalized recommendations and activity feeds using a simple API
Learn More
Comments
-
A popup that warns the users about the security implications? Or something fun like a rainbow background indeed
-
They're probably doing fairly basic stripping of html if they don't catch iframes. See if you can get a script to load in an obscure way ;)
-
If they block only <script>, could you use <img>'s onload attribute to, for example turn the page background into nyan cat gifs?
Related Rants

What only relying on JavaScript for HTML form input validation looks like
Yeah no
Hey, have you ever wanted to punch a developer 8611 times before?
I have found a website that allows HTML in comments. They blocked <script>, but not <iframe>. I can just load a script from my personal website using it. What should i do?
(something innocent)
undefined
html
iframe
hack
security hole