JavaScript is dangerous! Why? How are websites vulnerable to it? Find out about bug-bounties from Tom Scott.

More from Tom Scott: and

This video was filmed and edited by Sean Riley.

Computerphile is a sister project to Brady Haran’s Numberphile. See the full list of Brady’s video projects at:

  1. I would also tell a bit about other ways javascript can get into your page like ads and etc

  3. Well explained, but he didn't specify any concrete technique for executive such an attack (possibly intentional).
    Though, explains the mechanics well enough that one could figure it out. ☺️

  5. Oooooorrrr, you can command JavaScript to create web upload form and upload a php file with your filemanager shell and you can modify, add, or delete contents on the pages! 😁

  7. But how can you influence the web page of others by just modifying script on the page you were sent ? You can modify whatever you want, but when another person will send a request to the site, it will send them back the original page, without any of the modification you applied. Am I wrong ?

