By manipulating the GIF headers, one can create a bi-format file which is valid both as a GIF image and JavaScript code. This could allow one to upload an image, then reference it from an html script tag as a local resource, potentially bypassing certain security restrictions.
This entry was posted in Whatever and tagged from-ifttt, gif, hacks, images, JavaScript, Security, webdev. Bookmark the permalink.