"Oh, we didn't intend this to be used by anyone else!". Proceeds to publish the script publically, with terms that ensures that it's one of first links that come up when you google "torn elimination data". Proceeds to obfuscate code so that it's not apparent what it actually does. Creates multiple chat rooms to filter the messages that come through...
snooch: you can't block scripts that are browser side. If it's possible to display to a user, it's possible to create software that can read that same information. This particular exploit was done by providing a user script in a public forum which you install directly in your browser which then reads the torn page and for that reason can just extract the chat box and send it onward. The way they did it was a bit sneaky, as it purported to enhance the attack pages with better filtering / enhanced information per user - but had just a small disclaimer stating it was for "KW use only" - but it was easy to find on google. They also had intentionally obfuscated the code so that if you took just a small glance you couldnt actually see that it was readh the chat boxes...
"Oh, we didn't intend this to be used by anyone else!". Proceeds to publish the script publically, with terms that ensures that it's one of first links that come up when you google "torn elimination data". Proceeds to obfuscate code so that it's not apparent what it actually does. Creates multiple chat rooms to filter the messages that come through...