Feed

Holy IFRAME Batman!

Posted on April 3rd, 2008 in News by dglosser

Holy IFRAME Batman! I always wanted to say that ;)

My Christmas List:

I wish that browsers would
a)ignore all iframes not from a different domain than the base domain.
b)ignore any obfuscated javascript (or at least the stuff which seems malicious–if that’s possible)

I wish that all web crawlers (such as google) would:
a) not index any sites which contain obfuscated javascript (or at least the stuff which seems malicious–if that’s possible)
b) not index (or place a warning) on any site which contains an iframe calling content from a different domain.

I wish that all web servers would:
- have an option to ignore any IFRAME statements when displaying back to the browser. So even if a site was hacked and an iframe injected into the code the web server would simply ignore it and not even send it to the end-user’s browser…

There’s just way to much maliciousness with iframes and way too much obfuscated javascript out there….. Iframes are evil. I found someone who agrees with me.

Comments are closed.