@garethheyes I just figured out that you define undefined properties for unsandboxed names in object literals to make `a in b` work :D
no, as far as I can see, it works properly. well, except that e.g. `'XMLHttpRequest' in window` is true, but that's not a vuln
-
-
it's just that I wondered for quite some time why you define those properties with undefined values
-
for in loops, since the properites are rewritten I need supply the non-rewritten form
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.