logoalt Hacker News

rainonmoonlast Friday at 2:30 AM2 repliesview on HN

Except discord.com doesn't execute JavaScript, the user's browser does. These are meaningful distinctions that delineate the impact. You aren't "discord.com" if you target someone with an XSS exploit, you've only run a script in a user's session. Whether you can actually do anything with that script or not decides whether you can take over the account or not.


Replies

llmslave2last Friday at 2:46 AM

Everybody knows that XSS is a client side exploit, you're acting naive by pretending like we're claiming it gives access to a server and ignoring the fact that having control of the client gives you de facto control of whatever account is logged into the client.

show 1 reply
rvnxlast Friday at 3:01 AM

Yes, I agree, it’s a cool discovery though