JS Injection Security Risks

The cluster focuses on security concerns over techniques that inject JavaScript into websites or other tabs without consent, likened to shady ISP behavior, and discussions of mitigations including NoScript, CSP, ad blockers, and blocking scripts from sites like Google.

📉 Falling 0.4x Security
5,515
Comments
20
Years Active
5
Top Authors
#5863
Topic ID

Activity Over Time

2007
6
2008
41
2009
86
2010
182
2011
239
2012
243
2013
367
2014
267
2015
325
2016
372
2017
335
2018
424
2019
495
2020
400
2021
410
2022
390
2023
327
2024
289
2025
305
2026
12

Keywords

NoScript JS youtube.com github.io slideshare.net DNS URI darkpatterns.org CAD google.com javascript js reload flash html page content verbatim code browser

Sample Comments

DarthNebo Aug 11, 2022 View on HN

This is nuts, injecting code without website consent, pretty much like shady-ISP behaviour!

staunch Apr 17, 2014 View on HN

Don't X-Frame-Options and frame-busting Javascript break this idea?

kevin_thibedeau Jun 12, 2023 View on HN

NoScript usually bypasses this behavior. Especially when the content is delivered but hidden with JS DOM manipulation.

unilynx Mar 6, 2022 View on HN

those kind of tricks are already blocked by browsers, as the article explains

datguyfromAT Dec 10, 2021 View on HN

couldn't this be a major security issue since you could integrate your own js to any url on the domain?

38 Sep 1, 2023 View on HN

yeah sadly that seems to be the case. they are using 1st party inline scripts, so even blockers with dynamic filtering rules are unlikely to catch this.

invig Jun 20, 2011 View on HN

Security implications? Now your browser will execute JavaScript from sites you didn't even visit. Awesome.

user17843 Jun 19, 2019 View on HN

How useful is blocking third party scripts and frames against this?

Hamuko Oct 13, 2019 View on HN

Haven't browsers already done changes to combat that?

einpoklum Sep 27, 2021 View on HN

Can't you just prevent most scripts on google.com from running, for this mangling not to happen?