Experimenting with #Known an #Indieweb compliant publishing tool. Hopefully I'll be able to keep this space updated with my notes and even some longer posts in the future.
Peter Vágnerpublished this
This test embeds XSS within the hcard name and time field. Clicking on
the name or title should not raise an alert.
Does clicking me alert?, Jul 08 2016 on checkmention.appspot.com
Clicking this
should not cause an alert.
This div
should not alert.
Try clicking this link
and this too.
Mouse over this
should not cause an alert. This broken
http://
alert("XSS4");//
Neither should jAvascript:alert('test2').
Please look at the Owasp XSS prevention cheat sheet for more information.
Checkmention XSS test, Jul 08 2016 on checkmention.appspot.com
Congratulations! You've successfully handled a webmentioned note.
I guess that it's about time that we stop experimenting and try something new on https://
I love the way your site looks, though I'm not really the Jony Ive. How easy is it for someone to discover the real author of this note? Please also check that the links in this note have no rel="me" attribute on them.
Jonathan Ive, Jul 08 2016 on www.apple.com