Hacker News new | ask | show | jobs
by JamieH 4292 days ago
The TXT record isn't being sanitized so it just echos out the script tag which then loads the JS file.