GUYS DO NOT CLICK ON THE “CLICK SOURCE” POST

oceanmaster:

soul-is-over:

it demonstrates an XSS attack, and can run arbitrary code. who knows what it can do with your tumblr.

you have been warned

While OP IS somewhat correct (it DOES open itself up to being a huge security risk if used maliciously), in this specific case it is a harmless prank.

javascript:d=document;s=d.createElement(‘style’);s.type=’text/css’;s.innerHTML=”.post{-webkit-transition: all 5s ease-in-out; -moz-transition: all 5s ease-in-out; -o-transition: all 5s ease-in-out;}.post:hover{-webkit-transform: rotate(1800deg) scale(1); -moz-transform: rotate(1800deg) scale(1); -o-transform: rotate(1800deg) scale(1);}”;d.getElementsByTagName(‘head’)[0].appendChild(s);

All this Javascript is doing, is adding a CSS3 animated transition to the page.

.post {
    -webkit-transition: all 5s ease-in-out;
    -moz-transition: all 5s ease-in-out;
    -o-transition: all 5s ease-in-out;
}

.post:hover {
    -webkit-transform: rotate(1800deg) scale(1);
    -moz-transform: rotate(1800deg) scale(1);
    -o-transform: rotate(1800deg) scale(1);
}

There is nothing inherently bad about this particular script. If you clicked it, you should have nothing to worry about  — At least not this time around.

That said, it IS possible that someone could edit the Javascript in the Content Source to do something malicious. Always take care in what you click.

Hello there! I’m the guy who created this post.

soul-is-over: you are correct, it is an XSS vulnerability, and generally speaking I myself will advise people not to click on such things without knowing beforehand what they do. However, I can also assure you that the code I wrote is completely safe. All it does is inject a stylesheet that does some funky proprietary CSS effects to each post box; nothing more happens.

Basically, what Oceanmaster said.

(Source: s0ul-is-over)

  1. kerogero reblogged this from skysscribbles
  2. draayder reblogged this from ouendanl and added:
    OH UH WHOOPS GUYS DON’T CLICK IT
  3. bunnyfan194 reblogged this from djavjr
  4. timesplicer reblogged this from sassy-gay-watson
  5. rinniecakes reblogged this from danielgirl15 and added:
    can trust my friends when they tell...I’d be screwed.
  6. itsgoodtohavefriends reblogged this from needadispenserhere
  7. andnothingbutthetruth reblogged this from chineseelectricbatman and added:
    OH FUCK SHIT i clicked it a couple times GOD DAMN IT
  8. detectivegeorge reblogged this from probabilityofpsychosis
  9. thenextdragonborn reblogged this from chineseelectricbatman and added:
    gonna… What is the click source
  10. chineseelectricbatman reblogged this from militarypenguin and added:
    If that’s true. Oops. I clicked it three times or so.
  11. lovelustpixiedust reblogged this from fuckred
  12. sketchylock reblogged this from edscutechibigirl and added:
    BEFORE THE OTHER POST? NOOOO-
  13. fairy-flossfair reblogged this from kannmuri
  14. kannmuri reblogged this from romanorgasm
  15. okiedokoro reblogged this from oceanmaster
  16. ribbonkind reblogged this from ascantha and added:
    ..well fuck. ;~; /deletes..
  17. louie-legs reblogged this from xieril
  18. 0xd05 reblogged this from thepeopleofd and added:
    it does nothing except rotating the posts dear tumblr time to learn javascript :D
  19. thepeopleofd reblogged this from ascantha
  20. castlesarecrumbling reblogged this from bellypebbles
  21. skysscribbles reblogged this from needadispenserhere and added:
    I… Has anyone suffered an attack from it? D: A LOT of people seemed...have clicked it…
  22. collababortion reblogged this from hamburgerjack
  23. bellypebbles reblogged this from yachumi
  24. youregonnaloseit reblogged this from pothead-the-porcupine and added:
    OMGOMG. I CLICKED IT ;-;. OMG! What should I do….
  25. pothead-the-porcupine reblogged this from yesgoodverygood
  26. brotoman liked this
  27. winbutlershair said: waht post
  28. pfwooshin liked this
  29. dyedgreyillusion reblogged this from the-ryuchan
  30. itakusexual reblogged this from tsunbasa
  31. akanasan reblogged this from tessiethecreep
  32. clash-at-demonhead reblogged this from tsunbasa
  33. geewhathappensnext liked this
  34. bloobakingpan reblogged this from ri-chii
  35. procrastinality liked this
  36. evayume reblogged this from invisibear
  37. mageofdicks reblogged this from mangothebear
  38. bellabot reblogged this from himapapa and added:
    wait i thought it was just gonna be something troll-y or scary what? what what WAHT what’s gonna happen what the hell no
  39. simounologue reblogged this from miyomo
  40. snowshoebombay reblogged this from edscutechibigirl and added:
    me .. yay my paranoia was good for something
  41. goddesswashu reblogged this from ponywithafez
  42. ibelonginnarnia liked this
  43. faeries-everywhere reblogged this from edscutechibigirl
  44. wtfvivian reblogged this from bri2uty
  45. fortuna-admoturus liked this
  46. farawayconnections reblogged this from whaoanon and added:
    Well shit too late now here’s hoping it’s just a guy having fun
  47. seifer-almasy reblogged this from cloudspanties
  48. dragoninatrenchcoat reblogged this from wholocked and added:
    I clicked on it and I think it was honestly okay, and meant no harm. However, I think it could have done harm if it...
  49. our-diobolikal-rapture liked this
  50. alienanthropologist reblogged this from mylifeasasassymannequin