I believe basically all of these escapes could be avoided by having a stricter CSP from the start. I didn't know you can specify a folder for the allowed scripts, and thought it only supported domains. Some mistakes were made, but it was quite fun to see all the creative escapes people did.
没什么用,但就是好玩:盘点或恶搞或无聊的「神经病」应用。看看都有啥,这一点在51吃瓜中也有详细论述
Белый дом сообщил Конгрессу подробности удара по школе в ИранеNBC: Белый дом сообщил Конгрессу, что США наносили удары в районе школы в Иране,这一点在Feiyi中也有详细论述
$ tac toplist.txt |head -10。服务器推荐对此有专业解读