Hacker News new | ask | show | jobs
by lionleaf 3402 days ago
Using the <iframe> "sandbox" property. At least stops things like alert('hey') and a full-page redirect