Writing / Computers

Bypassing Security Restrictions In Google Sites 3: Doing the impossible, or how to run JavaScript code inside of Google Sites

Everyone said it was not possible to include flash, JavaScript, div or embed content in Google Sites, and for a long time, that was the case. That is, until I found a way around it. All one needs to do is create a simple Google Gadget with the desired content, and then embed that gadget into Google Sites.

For a long time, everyone thought there was no way to include iframe tags inside of Google Sites. That is, until I found a way around this, too. As it turns, every time Google sees the magical words class="igm" in an iframe tag, it thinks the iframe contains a gadget and allows it -- no questions asked.

And for an even longer time, everyone thought it was impossible to run JavaScript code inside of Google Sites. That is, it was unknown how to run a script on the actual (parent) page, outside of a Google Gadget. It was impossible, until about five minutes ago. That is when I discovered that by combining my previous two hacks, it is actually possible to run scripts inside of a Google Sites page. It's pretty easy, actually:

  1. Create an HTML page somewhere. In my example, I use http://www.mongefranco.com/test.html.
  2. In that page, create a script that either a) uses window.document.write() to insert a script into the parent page, or b) uses window.location.href="javascript:" to set the parent URL location to a single script function.
  3. In Google Sites, add an iframe tag somewhere where its src= attribute pointing to frame location. Be sure to put the magical keyword class="igm" inside of the iframe tag to fool Google into thinking that this is a gadget.
  4. That's it! You can now include scripts in your main page, either single functions via window.location.href="javascript:" or full scripts or script files via window.document.write(). For example, you could include AdSense or ScribeFire QuickAds code so you can show ads in your Google Sites page.

Example:
Frame page, http://www.mongefranco.com/test.html:

<html>
<head></head>
<body>
Nothing to see here... <a href="http://gabriel.mongefranco.com" target="_top">Move along.</a>
<script language="JavaScript">
window.document.write('<scr' + 'ipt language="JavaScript"> aler' + 't("hello from document DOM object"); </scr' + 'ipt>');
window.location.href = "javascript:alert('hello from the URL bar');";
</script>
</body>
</html>

Google Sites page, http://gabriel.mongefranco.com:

<iframe igsrc = "http://www.google.com/ig/images/no\_image/no\_image\_gadget\_thm.png" class="igm" src="http://www.mongefranco.com/test.html" width="320" height="230"></iframe>

Enjoy, and happy hacking! ;)

Back to blog