29 October 2004

The case of the spoon

In the nascent years of Javascript, I cohorted to create something we called a spoon: a self-replicating non-interactive javascript. This was possible because of user editable unescaped HTML being printed to some online dynamic content.

In the case of a message board, for example, we would have javascript look at the user's address book and send itself to every user in it. The user would be oblivious, but it would DoS the server very quickly, as more users were exposed to it, and a cascade effect would result.

The term spoon was probably coined during the height of the Matrix fad.

0 Comments:

Post a Comment

<< Home