[Greasemonkey] Safe to access variables from unsafeWindow?

Henrik Nyh henrik at nyh.se
Wed Sep 6 23:27:14 EDT 2006


Hullo,

Accessing a page's functions from unsafeWindow is supposedly not safe, 
because code could travel up the call stack into the monkey; but are 
there any known security issues with accessing _variables_ from 
unsafeWindow?

I'm asking because Flickr as well as DeviantArt expose a lot of 
delicious metadata in JavaScript variables.

Thanks,
-- 
Henrik Nyh
http://henrik.nyh.se/blog


More information about the Greasemonkey mailing list