Y
Hacker News
new
|
ask
|
show
|
jobs
by
hrrsn
4399 days ago
There are apparently easier ways, but I just chucked an alert(); in my Dropbox public folder, did an //dl.dropboxusercontent.com/u/14XXX/xss.js as they serve both http and https.